HomeTech NewsInside the $305M DMM Crypto Hack by North Korea

Inside the $305M DMM Crypto Hack by North Korea

North Korean Hackers Strike Again

In May 2024, hackers linked to North Korea carried out a $305 million crypto theft from the Japanese exchange DMM. The haul involved more than 4,500 bitcoin and was described in the article’s source material as the biggest crypto hack. Japanese and U.S. law enforcement agencies, including the FBI and Department of Defense, confirmed the attack and linked it to a group known as TraderTraitor.

The case matters because it was not presented as a simple breach of an exchange’s public-facing systems. The attackers worked their way through a chain of trusted relationships: a recruiter’s message, a job-related coding task, a wallet company’s internal access, and ultimately a legitimate DMM transaction request. That is a far more uncomfortable threat model than a stolen password or an opportunistic exploit. It turns ordinary business workflow into the route into a financial system.

TraderTraitor is also known as Jade Sleet, UNC4899, and Slow Pisces. The multiple names reflect the way cybersecurity researchers and agencies track the same activity under different labeling systems. What matters for companies is the group’s method: it uses social engineering to persuade people to grant access themselves, often before a victim realizes there is anything suspicious to investigate.

From a LinkedIn Message to Exchange Access

The attack began with an employee at Ginco, a crypto wallet company. A North Korean operative posed as a recruiter on LinkedIn and sent the employee a malicious Python script as part of what appeared to be a pre-employment test. This is a useful reminder that recruitment outreach can be an especially effective disguise. Candidates expect to receive files, complete technical exercises, and interact with unfamiliar people. The normal signals that might raise concern in an unsolicited message can look routine in a hiring conversation.

The employee unknowingly uploaded the code to a personal GitHub account. That gave the attackers access to sensitive session cookies, which in turn enabled them to infiltrate Ginco’s communication systems. The technical details matter, but the broader failure is not uniquely technical. Session cookies can act as proof that a user has already authenticated. If attackers obtain them, they may be able to act within an existing session rather than defeat a login screen in the most obvious way.

This is why attacks built around identity and trust are so difficult to stop with a single security product. A company can invest heavily in perimeter controls and still be exposed when a worker is persuaded to run code, upload a file, or approve what appears to be a normal request. For firms handling crypto infrastructure, the lesson is not simply “train employees better.” It is to limit what any one compromised identity can reach, monitor unusual access, and treat code received through informal channels as a meaningful security event.

The intrusion also shows why service providers deserve the same scrutiny as exchanges themselves. Ginco was the entry point, while DMM was the eventual target. In a connected financial environment, security is shaped by vendors, custody arrangements, communications platforms, employee devices, and the paths through which transaction instructions move. The weakest point may sit outside the organization that ultimately loses the funds.

Related reading: How a $230M Bitcoin Theft Was Cracked by Blockchain Analysis, June 2, 2024 — SquaredTech.

How the Crypto Hack Happened

Once inside Ginco’s systems, the hackers waited months for the right opportunity. Patience is central to the seriousness of this incident. Access alone does not necessarily produce a theft; attackers still need to understand the environment, identify valuable processes, and avoid triggering alarms before they can turn an intrusion into a financial loss.

Using the stolen access, the group intercepted a legitimate transaction request from a DMM employee. That interception led to the theft of over 4,500 bitcoin and forced DMM to shut down operations. The distinction between a fraudulent request and an intercepted legitimate one is important. In the latter scenario, the process itself may look normal to the people carrying it out. The attacker is exploiting confidence in a workflow, not merely trying to break into it from outside.

For crypto businesses, this places a premium on transaction verification that does not rely on a single channel or a single authenticated session. Large transfers are not just accounting events; they are moments when an organization needs to ask whether the instruction is genuine, whether the destination has changed, and whether the people involved are seeing the same information. Those checks can feel burdensome during routine operations, but the alternative is allowing a carefully prepared intrusion to blend into ordinary activity.

TraderTraitor’s use of a pre-employment test as a hacking tool is particularly revealing. The malicious Python script was embedded in a process designed to assess technical ability and establish trust. That is clever not because Python itself is unusual, but because the attackers understood the context in which a target would be willing to handle code. Careful planning and trickery, rather than brute force alone, played a major role in this cybercrime.

Related reading: Two Miami Criminals Used Crypto Mixers and VPNs to Launder: $230M Bitcoin Theft, September 25, 2024 — SquaredTech.

The Bigger Picture for Crypto Crime

According to Chainalysis, North Korean hackers dominated crypto-related crimes in 2024. The Democratic People’s Republic of Korea (DPRK) was responsible for stealing $1.34 billion across 47 incidents that year alone, more than double the $660 million stolen last year. The $305 million DMM theft is therefore not an isolated headline. It sits within a larger pattern in which major thefts can be tied to organized actors using a repeatable mix of technical access and human deception.

That pattern creates a hard problem for the crypto industry. Blockchain transactions can offer visibility after funds move, but visibility does not prevent the initial loss. Exchanges, wallet providers, and their partners still have to protect the people and systems that authorize movement in the first place. Once an attacker has gained privileged access and can manipulate or intercept a transaction process, the speed of crypto transfers can leave little room for a second look.

The incident highlights the growing threat of cyber theft in crypto and the need for stronger security measures. The most practical response is layered: tighter controls on privileged access, careful treatment of external code and job-test files, separation between communication tools and transaction authority, and verification processes designed for high-value transfers. None of those measures is glamorous. They are the kind of operational discipline that becomes visible only when it is absent.

With North Korean groups leading the charge, 2024 was a tough year for the industry. Organizations worldwide must remain vigilant as cybercrime continues to grow. The DMM case is a warning against treating social engineering as a low-level nuisance. Here, a LinkedIn approach and a malicious script became the opening move in a theft measured in hundreds of millions of dollars.

Stay Updated: Tech NewsCrypto

Yasir Khursheed
Yasir Khursheedhttps://www.squaredtech.co/
Meet Yasir Khursheed, a VP Solutions expert in Digital Transformation, boosting revenue with tech innovations. A tech enthusiast driving digital success globally.
RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Most Popular