How DMM Bitcoin was hacked: a fake recruiter, a vendor and $308 million
A $308 million bitcoin theft from a Japanese exchange started with a job offer sent to someone who did not even work for the exchange that lost the money.[1][2] This case file covers how a fake recruiter's coding test led to 4,502.9 bitcoin leaving DMM Bitcoin, why the exchange closed months later, and the one control that would have made the stolen access far less useful.
What happened
DMM Bitcoin was a Tokyo cryptocurrency exchange. Like many exchanges, it relied on an outside company for the software that managed its crypto wallets: Ginco, a Tokyo wallet provider.[3]
In late March 2024, someone posing as a recruiter on LinkedIn contacted a Ginco employee and offered a job, with a pre-employment test hosted on GitHub. The test contained malicious code, and running it compromised the employee's computer.[1][2] Nothing visible happened for weeks.
From mid-May, the attackers used session information taken from that computer to pose as the employee inside Ginco's internal communication system. In May, according to the FBI, they likely used that position to tamper with a legitimate transaction request made by a DMM Bitcoin employee.[1] On May 31, 2024, 4,502.9 bitcoin left the exchange, then worth about $308 million, or 48.2 billion yen.[3][4]
DMM Bitcoin froze new accounts, withdrawals and some trading. On December 24, 2024, the FBI, the U.S. Defense Department's Cyber Crime Center and Japan's National Police Agency publicly attributed the theft to North Korea.[1][3]
How they got in
This was not a break-in through the exchange's front door. It came through a supplier, and through a person rather than a server.
Fake job offers work because they give a reason to run unfamiliar code. A coding test is supposed to be downloaded and run, so the usual warning signs look like normal steps in a hiring process. The FBI says running the test's code is what compromised the employee's computer.[1][2]
The next step matters most. When you log in to a web service, it gives your browser a session token, a small file that says you have already proven who you are. Anyone who copies that token can often reuse it from another machine without a password or a second login code. The FBI says the attackers used this kind of session data to impersonate the Ginco employee.[1][2] Once they were trusted inside the vendor's systems, they were close enough to the exchange's payment process to change where a real transfer went.
What it cost
The exchange covered its customers' losses by raising about 55 billion yen in loans and other funding in June 2024.[3][5] In September 2024, Japan's Financial Services Agency issued a business improvement order, finding serious problems with how the company managed system risk, including a lack of independent checks and security duties concentrated in a small group.[3]
On December 2, 2024, DMM Bitcoin announced it would close and move its customer accounts and assets to SBI VC Trade, part of the SBI financial group, with the transfer expected to finish around March 2025.[3][5] The Japanese police described the group behind the theft, which U.S. agencies track as TraderTraitor, as part of North Korea's military intelligence apparatus.[4] No one has been arrested.
The missing control
The missing control: device-bound sessions for vendor staff, so that a login token only works on the approved device it was issued to, together with an independent check before a transfer goes out.
The attackers did not need the employee's password. They needed something the employee's browser already held. If Ginco's systems had tied each session to a known, company-managed device, a token copied off that computer would have been useless anywhere else. The attackers would have had to keep working from the one infected machine, where their activity was more likely to be noticed. And because the damage came from a changed transaction, a second person confirming the destination before funds moved would have been a separate chance to stop it. Japan's regulator later faulted the exchange for weak independent checks.[3]
What to do in your business
- Keep work off personal devices. Staff and contractors who can touch payments or customer data should do that work only on company-managed computers, not the laptop they use for job hunting.
- Turn on device checks and short sessions. In Microsoft 365, Google Workspace or your banking portal, require approved devices where offered, shorten how long logins last, and sign everyone out after a suspected compromise.
- Ask your vendors the same questions. If a supplier runs part of your money flow, ask how they protect staff logins and devices, and put the answer in the contract.
- Confirm every payment change out of band. Before money goes to a new or changed account, call a known number, not one in the message, and get a second person to approve it.
- Warn staff about job-offer tests. Tell employees that nobody should run a recruiter's file or code on a work machine, and give them one person to report odd offers to.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- Guide: Employee offboarding checklist: how to cut off a former employee's access the same day
- Guide: How to verify callers before password resets, and protect your phone number from SIM swaps
- Guide: Which two-step login actually stops phishing, and how a small office rolls it out
- How the SEC's X account was hacked: a fake ID, a SIM swap and no MFA
- How the Colonial Pipeline hack happened: one unused VPN account and no MFA
- How the 2020 Twitter hack happened: a fake help desk call and an admin tool
- How the Mirai botnet knocked Twitter and Netflix offline with factory passwords
- How the Ronin bridge was hacked: a fake job offer and $600 million
- How Uber got hacked in 2022: a stolen password and one tired tap
- Every identity and access control
- All case files
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.
- BleepingComputer: FBI links North Korean hackers to $308 million crypto heist
- Infosecurity Magazine: US and Japan blame North Korea for $308m crypto heist
- The Record: Japanese crypto service DMM Bitcoin shuts down after $300 million hack
- Nippon.com (Jiji Press): N. Korean hacker group stole assets from DMM Bitcoin, NPA says
- The Block: Japanese exchange DMM Bitcoin to shut down, transfer assets to SBI Group unit after $300 million hack