The FBI and Japan's National Police Agency have confirmed that North Korean hackers are behind the theft of $308 million worth of crypto from the DMM Bitcoin exchange. The attack took place in May 2024.

“ The theft is related to activity by the TraderTraitor, which is also tracked as Jade Sleet, UNC4899 and Slow Pisces group ,” the agencies said . “ TraderTraitor hackers often resort to social engineering attacks that target multiple employees of the same company at the same time .”
It is worth noting that DMM Bitcoin ceased operations earlier this month.
North Korean hackers TraderTraitor have been linked to attacks in the Web3 and typically trick victims into downloading crypto apps that contain malware and allow the theft of cryptocurrencies. The group has been active since at least 2020.
See also: 2024: $2.2 billion worth of crypto stolen – North Koreans primarily responsible
In recent years, North Korean hackers have carried out various social engineering attacks, using employment and recruitment bait. Hackers approach potential targets under the guise of collaborating on a GitHub project, which then leads to the deployment of malicious npm packages.
The group, however, is perhaps best known for infiltrating and gaining unauthorized access to systems JumpCloudlast year.
As for the DMM Bitcoin breach, the attack began with a contact with an employee of a Japanese cryptocurrency wallet software company called Ginco. In March 2024, North Korean hackers approached the employee posing as a recruiter. They sent him a URL to a malicious Python script hosted on GitHub. This was part of an alleged pre-hire test.
The victim, who had access to Ginco's wallet management system, was compromised after copying Python code to his personal GitHub page.
See also: Radiant Capital: North Korean hackers stole $50 million worth of crypto
The North Korean hackers moved to the next phase of the attack in mid-May 2024, when they exploited session cookie information to impersonate the compromised employee, gaining access to Ginco's unencrypted communications system
“In late May 2024, the attackers likely used this access to manipulate a legitimate transaction request from a DMM Bitcoin employee, resulting in the loss of 4,502.9 BTC, worth $308 million at the time of the attack,” authorities said. “The stolen funds were ultimately transferred to wallets controlled by the TraderTraitor hackers.”
The revelation comes shortly after Chainalysis attributed the DMM Bitcoin breach to North Korean hackers, stating that the attackers exploited vulnerabilities in the infrastructure to make the unauthorized withdrawals.

According to the company, the hackers used the CoinJoin and then transferred a portion of the funds (via a series of bridging services) to HuiOne Guarantee, an online marketplace affiliated with the HuiOne Group, which has previously been accused of facilitating cybercrime.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: North Korean hackers Sapphire Sleet have stolen $10 million worth of crypto.
The North Korean crypto theft has significant implications for the global economy. First, the theft creates uncertainty and loss of confidence in the cryptocurrency market. Investors and users are concerned about the safety of their funds and the possibility of becoming victims of cyberattacks.
Additionally, the theft of crypto by North Korean hackers could have a negative impact on the development and security of cryptocurrencies in general. cyberattacks expose weaknesses in security systems and can cause market turmoil. The loss of public trust can negatively affect the value of cryptocurrencies.
Finally, these attacks could have geopolitical implications. North Korea is using stolen cryptocurrencies to fund its nuclear weapons and missile programs. This could threaten regional security and provoke reactions from other countries.
Source: thehackernews.com
