Crypto history
DMM Bitcoin, 2024: a recruitment lure reached a custody workflow
The official attribution follows a fake coding test through session impersonation to a manipulated transaction request.
Research articles and reference entries are published in English. Navigation is available in seven languages.
In this article
The published sequence
In its 23 December 2024 statement, the FBI and partner agencies attributed the DMM Bitcoin theft to North Korean TraderTraitor activity. They described a fake recruiter approaching an employee at wallet-software provider Ginco in March, using a malicious Python coding test. The employee had access to the wallet-management system.
A session became the route into operations
The agencies said stolen session information later enabled impersonation inside Ginco's communications system. They assessed that this access was likely used to manipulate a legitimate DMM transaction request. The theft involved 4,502.9 BTC, valued at about $308 million at the time. The word 'likely' belongs to the published account and should not be silently converted into certainty.
What this adds to the phishing record
The valuable boundary was not only a seed phrase. Recruitment infrastructure, an employee session and an operational approval channel became connected. This case explains why reviewing custody requires following the process that creates a transaction request, not just counting signatures at its final step.