How a fake job test drained 4,502 bitcoin from DMM Bitcoin
In December 2024 the FBI, Japan's police and a Pentagon cyber unit traced the year's largest crypto theft — about $305 million — to North Korea's TraderTraitor crew.
DMM Bitcoin, a Tokyo-based exchange, lost 4,502.9 bitcoin — worth about $305 million by its own accounting, or $308 million per the FBI — in a single unauthorized transfer in late May 2024. It was the largest cryptocurrency theft recorded anywhere that year. Months passed before three governments named who did it.
In December 2024 the FBI, Japan's National Police Agency and the U.S. Defense Department's Cyber Crime Center jointly blamed a North Korean unit tracked as TraderTraitor, an arm of the Lazarus Group, The Record reported. The stolen coins, the agencies said, "ultimately moved to TraderTraitor-controlled wallets."
A malicious 'pre-employment test'
The intrusion did not begin at DMM. In March 2024 the attackers posed as a recruiter and approached an employee of Ginco, a Japanese wallet-software firm, sending a link to a malicious Python script hosted on GitHub as a supposed hiring exercise, per The Hacker News's account of the joint statement.
The employee copied that code to a personal GitHub account, and the attackers rode the access into Ginco's wallet-management system. By mid-May, the agencies said, they "used this access to manipulate a legitimate transaction request by a DMM employee" — converting a routine movement into a 4,502.9 BTC payout to the thieves.
The exchange did not survive
DMM Bitcoin's parent pledged to protect customers, but the wound proved fatal. On Dec. 2, 2024 the exchange said it would wind down and hand its accounts and assets to SBI VC Trade in March 2025, per CoinDesk; withdrawals and spot-buy orders had already been frozen for months.
The shape of this attack — compromise a vendor, then ride that trust into the real target — repeats across 2024's largest thefts. A few durable lessons:
- Treat an unsolicited 'recruiter' coding test as hostile — running a stranger's script is running their malware.
- The weakest signing key may sit at a supplier, not the exchange; custody is only as strong as every vendor with access.
- Social engineering, not broken cryptography, undoes most large exchanges — train the people who approve transfers.
- Withdrawal allow-lists and cold storage cap how much any single tampered request can move.
For customers the takeaway is blunt: an exchange that holds your keys can be brought down by a phishing message sent to a company you have never heard of. Self-custody shifts that risk onto you — a different trade-off, not an escape from it.
— Sources: [The Record](https://therecord.media/fbi-largest-crypto-hack-2024-tradertraitor) · [The Hacker News](https://thehackernews.com/2024/12/north-korean-hackers-pull-off-308m.html) · [CoinDesk](https://www.coindesk.com/business/2024/12/02/japanese-crypto-exchange-dmm-bitcoin-to-shut-down-after-305-m-hack)
NOT FINANCIAL ADVICE · VERIFY EVERYTHING