Skip to content
Yieldo

DMM Bitcoin

$305.0M
Funds stolen
$305.0M
Funds returned
31 May 2024
Date of incident
Technique
Phishing
Classification
Social Engineering
Target type
CEX
Affected chains
Bitcoin
Source
No public source link

On May 31, 2024, Japanese cryptocurrency exchange DMM Bitcoin disclosed the loss of 4,502.9 BTC — about $305 million at the time — from one of its hot wallets. In December 2024, the FBI, the U.S. Department of Defense Cyber Crime Center (DC3), and Japan's National Police Agency jointly attributed the theft to TraderTraitor, a North Korea-linked hacking cluster also tracked as Jade Sleet and UNC4899 (CryptoSlate; FBI). It stands as the largest theft ever attributed to North Korean state-linked actors.

How the attack worked

The intrusion did not start at DMM Bitcoin itself. According to the joint investigation, in March 2024 an attacker posed as a recruiter on LinkedIn and approached an employee of Ginco, a Japanese wallet-software vendor whose infrastructure DMM Bitcoin relied on. The "recruiter" sent a coding assignment: a Python script hosted on GitHub, framed as a pre-employment test. Running it exfiltrated the employee's session-authentication cookies. With those cookies, the attacker impersonated the employee inside Ginco's internal communication system and, by late May, intercepted and altered a legitimate transaction request that a DMM Bitcoin employee had already initiated — redirecting it to attacker-controlled addresses.

That distinguishes this case from most "private key compromised" incidents in this database: no key was brute-forced, phished directly, or extracted from a leaked seed. The attacker instead hijacked a trusted session inside a third-party vendor and rode it into a transaction that was, from the signing system's point of view, indistinguishable from a routine internal transfer.

What happened next

DMM Bitcoin immediately suspended withdrawals and spot trading. To make customers whole, the exchange committed to repurchasing an equivalent amount of BTC on the open market, funded through a series of loans and capital injections from DMM Group companies — including a ¥5 billion loan on June 3, roughly ¥48 billion by June 7, and a further ¥2 billion subordinated loan on June 10 (Cryptopolitan). None of the stolen 4,502.9 BTC was ever recovered or clawed back from the attackers — the compensation came entirely from parent-company capital, not from tracing the funds. In December 2024, DMM Bitcoin announced it would exit the crypto exchange business altogether, transferring all customer accounts and assets to SBI VC Trade, a subsidiary of SBI Holdings; the migration completed by March 2025 (CoinDesk). No arrests followed; state-linked actors operating from North Korea are effectively outside the reach of law enforcement.

What this means

  • Vendor risk is exchange risk. DMM Bitcoin's own systems were not the entry point — a wallet-software vendor's employee was. Any exchange outsourcing wallet or signing infrastructure inherits that vendor's attack surface, including its staff's susceptibility to social engineering.
  • Hardware wallets and multisig don't stop session hijacking. Key custody controls guard against key extraction, not against an attacker who rides a stolen, authenticated session into a transaction that looks legitimate to every downstream check.
  • Fake recruiter outreach on LinkedIn is a recurring North Korea-linked lure across multiple 2023–2024 incidents. Employees with any access to wallet infrastructure or deployment pipelines are higher-value targets than their job titles suggest.
  • User compensation is not fund recovery. DMM's customers were repaid in full, but that came from the parent company's balance sheet, not from the stolen BTC — a distinction that matters when judging whether an exchange's post-incident response actually reduces the attacker's payoff.

On-chain DeFi carries smart-contract risk. Keep core funds on a regulated exchange.