Summary
DMM Bitcoin was a licensed Japanese cryptocurrency exchange operated by DMM Group (DMM.com) that launched in January 2018. In May 2024 it suffered the eighth-largest crypto theft in history when North Korean state-sponsored hackers attributed to the TraderTraitor subgroup of Lazarus Group stole 4,502.9 BTC (approximately $305–308 million USD) through a sophisticated supply-chain attack targeting Ginco, a third-party wallet management provider. Following the hack, Japan's Financial Services Agency issued a business improvement order, the exchange restricted operations, and in December 2024 announced full closure with all customer assets transferred to SBI VC Trade by March 2025.
Connected Entities
1 entities- + 1 more
Timeline(11 events)
2018-01-10
DMM Bitcoin launches trading platform under DMM Group, offering spot and leverage trading in Japan.
2024-03-01
TraderTraitor operative posing as a LinkedIn recruiter contacts a Ginco employee and delivers a malicious Python script disguised as a pre-employment coding challenge.
2024-05-01
Attackers exploit harvested session cookies to impersonate the compromised Ginco employee and access Ginco's unencrypted internal communications system.
2024-05-31
4,502.9 BTC (approximately $305–308 million) is illegally transferred from DMM Bitcoin wallets via manipulation of a legitimate DMM employee transaction request. DMM Bitcoin publicly confirms the breach.
2024-07-12
Tether blacklists a Tron wallet address linked to the laundering chain, freezing approximately $28–30 million in USDT connected to Huione Guarantee.
2024-07-15
ZachXBT publicly reports over $35 million from the DMM Bitcoin hack has been laundered through Huione Guarantee in Cambodia, identifying Lazarus Group laundering signatures.
2024-09-01
Japan's FSA (Kanto Local Finance Bureau) issues a formal business improvement order against DMM Bitcoin under Article 63-16 of the Payment Services Act, citing concentrated authority in operations and security as a systemic failure.
2024-10-28
FSA deadline for DMM Bitcoin to submit a business improvement plan with specific measures and implementation timeline.
2024-12-02
DMM Bitcoin announces it will cease all operations and transfer all customer accounts and assets to SBI VC Trade by March 2025.
2024-12-23
The FBI, U.S. DC3, and Japan's NPA issue a joint public statement formally attributing the DMM Bitcoin theft to North Korean cyber actors operating as TraderTraitor (also tracked as Jade Sleet, UNC4899, Slow Pisces).
2025-03-08
SBI VC Trade completes transfer of all DMM Bitcoin customer accounts and assets. DMM Bitcoin ceases operations entirely.
Decision Log
- hash: F29fy7nNV4JZn65Z2m125pawnpLtLJdBZTcywavsW2K8
- hash: 9z7Cq5Fi2M17dbEga7grbgCvmB1v7wcEtgC5nbhoJm3p
- hash: CPMKAgcjJtjhtVxN5LiX2DNGXF6qxEumTU13nohgszwp
This investigation is cryptographically anchored to the Solana blockchain and source URLs are archived via the Internet Archive.
model: claude-sonnet-4-6
generated: 5/4/2026, 2:54:32 AM
last updated: 6/15/2026, 7:29:59 PM
avoid.net — verified advice for a post-truth world