Case file · DMM BITCOIN 2024

How DMM Bitcoin was hacked: a fake recruiter, a vendor and $308 million

Published 2026-09-29 · 5 min read · Missing control: Device-bound sessions for vendor staff

A $308 million bitcoin theft from a Japanese exchange started with a job offer sent to someone who did not even work for the exchange that lost the money.[1][2] This case file covers how a fake recruiter's coding test led to 4,502.9 bitcoin leaving DMM Bitcoin, why the exchange closed months later, and the one control that would have made the stolen access far less useful.

What happened

DMM Bitcoin was a Tokyo cryptocurrency exchange. Like many exchanges, it relied on an outside company for the software that managed its crypto wallets: Ginco, a Tokyo wallet provider.[3]

In late March 2024, someone posing as a recruiter on LinkedIn contacted a Ginco employee and offered a job, with a pre-employment test hosted on GitHub. The test contained malicious code, and running it compromised the employee's computer.[1][2] Nothing visible happened for weeks.

From mid-May, the attackers used session information taken from that computer to pose as the employee inside Ginco's internal communication system. In May, according to the FBI, they likely used that position to tamper with a legitimate transaction request made by a DMM Bitcoin employee.[1] On May 31, 2024, 4,502.9 bitcoin left the exchange, then worth about $308 million, or 48.2 billion yen.[3][4]

DMM Bitcoin froze new accounts, withdrawals and some trading. On December 24, 2024, the FBI, the U.S. Defense Department's Cyber Crime Center and Japan's National Police Agency publicly attributed the theft to North Korea.[1][3]

How they got in

This was not a break-in through the exchange's front door. It came through a supplier, and through a person rather than a server.

Fake job offers work because they give a reason to run unfamiliar code. A coding test is supposed to be downloaded and run, so the usual warning signs look like normal steps in a hiring process. The FBI says running the test's code is what compromised the employee's computer.[1][2]

The next step matters most. When you log in to a web service, it gives your browser a session token, a small file that says you have already proven who you are. Anyone who copies that token can often reuse it from another machine without a password or a second login code. The FBI says the attackers used this kind of session data to impersonate the Ginco employee.[1][2] Once they were trusted inside the vendor's systems, they were close enough to the exchange's payment process to change where a real transfer went.

What it cost

The exchange covered its customers' losses by raising about 55 billion yen in loans and other funding in June 2024.[3][5] In September 2024, Japan's Financial Services Agency issued a business improvement order, finding serious problems with how the company managed system risk, including a lack of independent checks and security duties concentrated in a small group.[3]

On December 2, 2024, DMM Bitcoin announced it would close and move its customer accounts and assets to SBI VC Trade, part of the SBI financial group, with the transfer expected to finish around March 2025.[3][5] The Japanese police described the group behind the theft, which U.S. agencies track as TraderTraitor, as part of North Korea's military intelligence apparatus.[4] No one has been arrested.

The missing control

The missing control: device-bound sessions for vendor staff, so that a login token only works on the approved device it was issued to, together with an independent check before a transfer goes out.

The attackers did not need the employee's password. They needed something the employee's browser already held. If Ginco's systems had tied each session to a known, company-managed device, a token copied off that computer would have been useless anywhere else. The attackers would have had to keep working from the one infected machine, where their activity was more likely to be noticed. And because the damage came from a changed transaction, a second person confirming the destination before funds moved would have been a separate chance to stop it. Japan's regulator later faulted the exchange for weak independent checks.[3]

What to do in your business

Watch the case
A fake job test that cost DMM Bitcoin $308 millionDrops 2026-11-13
Close the same gap

Check your business for this control

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

More identity and access cases

Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.

Sources
  1. BleepingComputer: FBI links North Korean hackers to $308 million crypto heist
  2. Infosecurity Magazine: US and Japan blame North Korea for $308m crypto heist
  3. The Record: Japanese crypto service DMM Bitcoin shuts down after $300 million hack
  4. Nippon.com (Jiji Press): N. Korean hacker group stole assets from DMM Bitcoin, NPA says
  5. The Block: Japanese exchange DMM Bitcoin to shut down, transfer assets to SBI Group unit after $300 million hack