DMM Bitcoin
- Technique
- Phishing
- Classification
- Social Engineering
- Target type
- CEX
- Affected chains
- Bitcoin
- Source
- No public source link
On May 31, 2024, Japanese cryptocurrency exchange DMM Bitcoin disclosed the loss of 4,502.9 BTC — about $305 million at the time — from one of its hot wallets. In December 2024, the FBI, the U.S. Department of Defense Cyber Crime Center (DC3), and Japan's National Police Agency jointly attributed the theft to TraderTraitor, a North Korea-linked hacking cluster also tracked as Jade Sleet and UNC4899 (CryptoSlate; FBI). It stands as the largest theft ever attributed to North Korean state-linked actors.
How the attack worked
The intrusion did not start at DMM Bitcoin itself. According to the joint investigation, in March 2024 an attacker posed as a recruiter on LinkedIn and approached an employee of Ginco, a Japanese wallet-software vendor whose infrastructure DMM Bitcoin relied on. The "recruiter" sent a coding assignment: a Python script hosted on GitHub, framed as a pre-employment test. Running it exfiltrated the employee's session-authentication cookies. With those cookies, the attacker impersonated the employee inside Ginco's internal communication system and, by late May, intercepted and altered a legitimate transaction request that a DMM Bitcoin employee had already initiated — redirecting it to attacker-controlled addresses.
That distinguishes this case from most "private key compromised" incidents in this database: no key was brute-forced, phished directly, or extracted from a leaked seed. The attacker instead hijacked a trusted session inside a third-party vendor and rode it into a transaction that was, from the signing system's point of view, indistinguishable from a routine internal transfer.
What happened next
DMM Bitcoin immediately suspended withdrawals and spot trading. To make customers whole, the exchange committed to repurchasing an equivalent amount of BTC on the open market, funded through a series of loans and capital injections from DMM Group companies — including a ¥5 billion loan on June 3, roughly ¥48 billion by June 7, and a further ¥2 billion subordinated loan on June 10 (Cryptopolitan). None of the stolen 4,502.9 BTC was ever recovered or clawed back from the attackers — the compensation came entirely from parent-company capital, not from tracing the funds. In December 2024, DMM Bitcoin announced it would exit the crypto exchange business altogether, transferring all customer accounts and assets to SBI VC Trade, a subsidiary of SBI Holdings; the migration completed by March 2025 (CoinDesk). No arrests followed; state-linked actors operating from North Korea are effectively outside the reach of law enforcement.
What this means
- Vendor risk is exchange risk. DMM Bitcoin's own systems were not the entry point — a wallet-software vendor's employee was. Any exchange outsourcing wallet or signing infrastructure inherits that vendor's attack surface, including its staff's susceptibility to social engineering.
- Hardware wallets and multisig don't stop session hijacking. Key custody controls guard against key extraction, not against an attacker who rides a stolen, authenticated session into a transaction that looks legitimate to every downstream check.
- Fake recruiter outreach on LinkedIn is a recurring North Korea-linked lure across multiple 2023–2024 incidents. Employees with any access to wallet infrastructure or deployment pipelines are higher-value targets than their job titles suggest.
- User compensation is not fund recovery. DMM's customers were repaid in full, but that came from the parent company's balance sheet, not from the stolen BTC — a distinction that matters when judging whether an exchange's post-incident response actually reduces the attacker's payoff.
Sources
- FBI reveals North Korea used LinkedIn to steal $305 million from Japan's DMM Bitcoin — CryptoSlate ↗
- Japanese Crypto Exchange DMM Bitcoin to Shut Down After $305M Hack — CoinDesk ↗
- DMM Bitcoin to raise over $300M for BTC buyback to compensate victims — Cryptopolitan ↗
- FBI, DC3, and NPA Identification of North Korean Cyber Actors, Tracked as TraderTraitor, Responsible for Theft of $308 Million USD from Bitcoin.DMM.com — FBI (U.S. Federal Bureau of Investigation) ↗
Sources checked 07.08.2026
On-chain DeFi carries smart-contract risk. Keep core funds on a regulated exchange.