DeFi Intel

DMM Bitcoin Hack and Shutdown (May 31, 2024)

Date
2024-05-31
Loss
$305M (4,502.9 BTC)
Category
Exchange hack (key/transaction compromise)
Attack vector
TraderTraitor (Lazarus) social-engineering of a wallet-software-vendor employee, then manipulation of a legitimate DMM transaction request
Attribution
TraderTraitor / Lazarus / DPRK (jointly confirmed by FBI, DC3 and Japan's National Police Agency in December 2024)

Overview

On May 31, 2024, the Japanese cryptocurrency exchange DMM Bitcoin disclosed that approximately 4,502.9 BTC, worth about $305 million at the time, had been drained from its wallets in what it described as an unauthorized leak of Bitcoin. The theft was, at the moment it occurred, the largest crypto hack of 2024 and one of the largest exchange thefts in history, and it ultimately proved fatal to the company: after more than six months of frozen withdrawals, an apology and a struggle to backfill the hole, DMM Bitcoin announced in early December 2024 that it would wind down operations and transfer customer accounts and assets to SBI VC Trade, a subsidiary of the SBI financial group, with the migration completed in March 2025. In December 2024 the U.S. FBI, the Department of Defense Cyber Crime Center (DC3) and Japan's National Police Agency issued a joint advisory formally attributing the theft to TraderTraitor, the FBI's designation for the Lazarus subgroup that has specialized in crypto theft, the same threat cluster later tied to the 2025 Bybit compromise. The advisory described a now-familiar Lazarus playbook: rather than breaking the exchange's cryptography directly, the attackers socially engineered an employee at Ginco, a Japanese wallet-software company whose infrastructure DMM relied on, using a fake pre-employment recruitment lure, then leveraged that foothold to manipulate a legitimate transaction request and redirect 4,502.9 BTC to attacker-controlled addresses. The funds were laundered through mixers, the Cambodian Huione marketplace and cross-chain bridges including THORChain. DMM Bitcoin is the clearest 2024 case study in supply-chain-plus-social-engineering exchange compromise, and in how a single catastrophic loss can end an otherwise functioning exchange even when customers are made whole.

Timeline of events

On May 31, 2024, DMM Bitcoin posted a notice acknowledging an unauthorized leak of Bitcoin from its wallets and immediately suspended a range of services, including new account openings, spot buy orders, withdrawals of crypto, and certain leveraged-trading functions, to contain the situation. The leak itself occurred on May 30; on-chain analysts including those at Elliptic and the broader investigator community quickly identified the loss as 4,502.9 BTC, worth roughly $305 million at prevailing prices. DMM Bitcoin, backed by the large Japanese DMM.com group, publicly committed to fully guaranteeing the customer Bitcoin that had been lost, stating it would procure the equivalent amount of BTC with support from group companies, an unusually strong solvency backstop that distinguished the incident from collapses in which customers bear the loss. Over the following weeks DMM raised capital and acquired BTC to cover the shortfall while withdrawals remained constrained, an extended period of impaired service that the company repeatedly apologized for. The prolonged restrictions, the difficulty of operating a leveraged-trading business while backfilling a nine-figure hole, and the reputational damage proved too much: on December 2, 2024, DMM Bitcoin announced it would cease operations and transfer customer accounts and assets to SBI VC Trade, with the handover completed by around March 2025. Separately, on December 23-24, 2024, the FBI, DC3 and Japan's NPA published their joint attribution to TraderTraitor.

Attack mechanism

The joint FBI/DC3/NPA advisory laid out a mechanism that is characteristic of TraderTraitor and the broader Lazarus apparatus, and which makes the DMM theft a supply-chain compromise as much as an exchange hack. In late March 2024 a TraderTraitor operator, posing as a recruiter on LinkedIn, contacted an employee of Ginco, a Japan-based enterprise wallet-software company whose systems were used in DMM Bitcoin's custody workflow. The lure was a fake pre-employment coding test, a malicious script hosted on a code-sharing site, that the target was asked to complete; running it gave the attackers a foothold on the employee's machine. Using that access, the attackers are assessed to have impersonated the compromised employee and, by mid-May, gained access to Ginco's unencrypted communications systems. With that position, when a legitimate DMM Bitcoin transaction request flowed through the relevant systems in late May, the attackers manipulated it, substituting attacker-controlled destination details, and caused 4,502.9 BTC to be sent to addresses they controlled. Crucially, this is not a smart-contract bug or a brute-forced private key; it is the exploitation of the human-and-vendor layer that surrounds the signing of transactions, the same class of failure that would later define the Bybit cold-wallet compromise, in which a trusted piece of the signing pipeline is subverted so that what the exchange intends to do and what actually executes on-chain diverge.

Root cause analysis

The root cause sits at the intersection of third-party-vendor risk and the persistent effectiveness of recruitment-themed social engineering against crypto-adjacent engineers. First, DMM Bitcoin's custody and transaction workflow depended on a vendor, Ginco, whose own endpoint and communications security became the soft point of entry; a compromise of the vendor translated into a compromise of DMM's ability to safely authorize a transfer. Vendor and supply-chain dependencies expand an exchange's trust boundary far beyond its own perimeter, and they are frequently under-audited relative to the exchange's internal controls. Second, the initial foothold came from the by-now extensively documented Lazarus fake-recruiter playbook: a plausible job offer, a coding challenge that doubles as a malware delivery vehicle, and a target population, software engineers, with privileged access. Third, the transaction-authorization process lacked controls strong enough to prevent a manipulated request from being signed and broadcast; an out-of-band verification of destination addresses, hardware-enforced policy on withdrawal destinations, or independent confirmation of the transaction details could have caught the substitution. The deepest lesson is that for a high-value custodian the security of every dependency in the signing path, including third-party software vendors and the individual engineers who maintain them, is part of the custodian's own security posture, and an adversary that cannot break the cryptography will instead break the weakest human or vendor link feeding into it.

Initial response and recovery

DMM Bitcoin's immediate response prioritized customer protection over continuity of trading. It froze the affected services to prevent further loss, publicly disclosed the incident on May 31, and, most importantly, committed to fully cover the lost customer Bitcoin, stating it would procure 4,502.9 BTC equivalent with the financial support of its DMM.com group affiliates rather than passing the loss to depositors. This solvency backstop, a wealthy parent group able to absorb a $305M hole, meant that, unlike collapses such as Mt. Gox or FTX, DMM Bitcoin customers were not exposed to the theft. Over the subsequent weeks the company arranged the capital and BTC purchases needed to make good on that commitment while keeping withdrawals constrained. But covering the loss did not save the business: the combination of a frozen, impaired service for months, the operational and capital strain of replacing the stolen BTC, and the reputational damage led DMM to conclude that an orderly wind-down was preferable to continuing. The chosen path, transferring customer accounts and assets to SBI VC Trade, a regulated, well-capitalized SBI-group exchange, was designed to give customers a soft landing: their balances and accounts would migrate to a going concern rather than being trapped in a failed entity. The handover was carried out in early 2025.

Funds tracking and laundering

On-chain investigators tracked the stolen 4,502.9 BTC from the moment of the theft. The funds were broken up and moved through a laundering pipeline that, by the time of the December 2024 advisory and subsequent reporting, was understood to involve Bitcoin mixers, the Cambodia-based Huione Guarantee marketplace, which had become a major laundering venue for DPRK-linked actors, and cross-chain bridging, notably THORChain, used to convert Bitcoin into Ethereum and other assets to frustrate tracing and freezing. By mid-July 2024, ZachXBT and others had flagged the movement of tens of millions of dollars of the stolen funds, and Elliptic and other analytics firms published flow-of-funds analyses. The pattern, immediate fragmentation, routing through a jurisdictionally-permissive marketplace, and cross-chain hops in preference to sanctioned mixers alone, mirrors the Lazarus laundering methodology seen across the WazirX, Bybit and other DPRK thefts, and it underscores how the cross-chain liquidity layer has become the connective tissue of large-scale crypto laundering. The reuse of the same laundering infrastructure across incidents is itself part of what allows investigators to cluster wallets and attribute new thefts to the same operators.

Legal and regulatory aftermath

The headline legal development was the joint public attribution: in late December 2024 the FBI, the DoD Cyber Crime Center (DC3) and Japan's National Police Agency issued a coordinated advisory naming TraderTraitor, an FBI-designated Lazarus subgroup, as responsible for the $305M theft and detailing the Ginco-employee social-engineering vector. This kind of cross-border law-enforcement attribution serves to publicly document the methodology, warn other potential targets (especially software vendors and their engineers), and support sanctions and asset-freezing actions, even though the named operators sit in a non-extraditable jurisdiction and face no realistic prospect of arrest. Within Japan, the incident fell under the oversight of the Financial Services Agency (FSA), which regulates licensed crypto exchanges; the loss and subsequent wind-down reinforced regulatory attention to exchange custody, third-party-vendor risk and security controls. The choice to migrate customers to SBI VC Trade, itself an FSA-registered exchange, kept the resolution within the regulated perimeter and avoided a disorderly bankruptcy. More broadly, the DMM theft fed directly into the international policy conversation about DPRK crypto theft as a state-financing mechanism, the same conversation that the larger Bybit hack would intensify in 2025.

Industry implications and verdict

DMM Bitcoin is the definitive 2024 demonstration of three things. First, that the largest exchange thefts no longer come from breaking cryptography but from compromising the people and vendors in the transaction-authorization pipeline, the same lesson that the Bybit cold-wallet compromise would make even larger in 2025; the security of an exchange is the security of its weakest dependency, including third-party wallet-software vendors and the individual engineers who run them. Second, that the Lazarus fake-recruiter social-engineering playbook remains devastatingly effective against crypto-adjacent software engineers, and that defending against it requires treating recruitment-themed approaches and unsolicited coding tests as a live threat vector, with endpoint isolation, code-execution sandboxing and skepticism baked into engineering culture. Third, that a strong solvency backstop can protect customers from loss without protecting the business from failure: DMM made customers whole and still wound down, a reminder that operational continuity after a nine-figure theft is its own challenge distinct from solvency. For practitioners, the remediations are concrete: audit and constrain every third-party dependency in the signing path; enforce out-of-band, hardware-backed verification of withdrawal destinations so a manipulated transaction request cannot silently execute; and harden engineering teams against recruitment-lure malware. The verdict is that DMM Bitcoin belongs in the record as the bridge case between the bridge-and-contract hacks of 2021-2022 and the human-and-vendor-pipeline compromises that now define the largest thefts.

Recovery

Customers were fully protected: DMM committed to procure the equivalent 4,502.9 BTC with DMM.com group support, so no depositor bore the loss. Accounts and assets were migrated to SBI VC Trade by around March 2025. The stolen BTC itself was largely laundered; minimal direct recovery of the thieves' proceeds. The FBI/DC3/NPA published a joint attribution to TraderTraitor in December 2024.

Key lessons

  • An exchange's security is the security of its weakest dependency, including third-party wallet-software vendors and their individual engineers
  • The Lazarus fake-recruiter / coding-test malware lure is a live, recurring threat to crypto engineers; treat recruitment approaches and unsolicited code as hostile
  • Enforce out-of-band, hardware-backed verification of withdrawal destinations so a manipulated transaction request cannot silently execute
  • Solvency and continuity are distinct: making customers whole does not guarantee a business survives a nine-figure theft

Frequently asked questions

What happened in the DMM Bitcoin Hack and Shutdown?

On May 31, 2024, DMM Bitcoin lost 4,502.9 BTC (~$305M), the year's largest hack, after TraderTraitor (Lazarus) socially engineered an employee of wallet-software vendor Ginco with a fake coding test and used that access to manipulate a legitimate DMM transaction. The DMM.com group made customers whole, but the exchange wound down and migrated accounts to SBI VC Trade by March 2025. The FBI, DC3 and Japan's NPA jointly attributed it to TraderTraitor in December 2024. A supply-chain-plus-social-engineering compromise of the transaction-authorization pipeline, the same class of failure later magnified by Bybit.

How much was lost?

Approximately $305M (4,502.9 BTC) was lost on 2024-05-31.

How did the attack work?

TraderTraitor (Lazarus) social-engineering of a wallet-software-vendor employee, then manipulation of a legitimate DMM transaction request

Who was responsible?

TraderTraitor / Lazarus / DPRK (jointly confirmed by FBI, DC3 and Japan's National Police Agency in December 2024)

Were the funds recovered?

Customers were fully protected: DMM committed to procure the equivalent 4,502.9 BTC with DMM.com group support, so no depositor bore the loss. Accounts and assets were migrated to SBI VC Trade by around March 2025. The stolen BTC itself was largely laundered; minimal direct recovery of the thieves' proceeds. The FBI/DC3/NPA published a joint attribution to TraderTraitor in December 2024.

Related