CryptoReal
CASE FILE — May 31, 2024

Japan's DMM Bitcoin Drains $304 Million in Bitcoin From a Hot Wallet

A Japan-based centralized cryptocurrency exchange, DMM Bitcoin, was exploited for more than $304 million worth of Bitcoin, making the incident the largest crypto hack since December 2022 and one of the biggest thefts the industry has recorded.

The first sign of trouble came from Whale Alert, which flagged a transfer of 4,502 BTC moving from an unidentified wallet to another unidentified wallet. DMM confirmed soon afterward that the coins had been illicitly removed from one of its wallets.

The exchange has offered little in the way of technical explanation, saying only that it is investigating the incident and rolling out additional protections to prevent a repeat. It maintains that all customer BTC deposits remain fully backed, but has temporarily suspended spot-market buy orders, the opening of new leveraged positions, and new account sign-ups while the investigation continues.

The breach ranks as the third-largest cryptocurrency theft in Japan's history, behind the 2018 Coincheck hack, which saw more than $530 million in XEM stolen. Japan is also where the Mt. Gox exchange collapsed in 2014, an episode that ultimately involved over 809,000 BTC lost across six separate breaches during the exchange's lifetime.

Recovered or not, a theft of this size all but guarantees DMM a place on Rekt's leaderboard of the industry's worst hacks.

According to DMM's own account, the exchange first detected the leak around 1:30 PM Japan Standard Time, when 4,502.9 BTC left its hot wallet. The company posted an update on its official website, though it had stayed quiet on Twitter/X up to that point.

Security firm Beosin outlined two possible explanations for how the attacker pulled this off:

  • A conventional exchange-side compromise, in which either DMM's signature service was breached or a multi-sig private key was obtained. The attacker would then have used a receiving address resembling one from DMM's genuine transaction history, letting the transfer slip past detection systems.

  • An address-spoofing scheme, where whoever authorized the transfer checked only the first five and last two characters of the destination address, allowing a lookalike address controlled by the attacker to receive the funds instead of the intended recipient.

On-chain trail:

The transaction associated with the attack: 975ec405ac9dc9fa5ab8009d94d6a1fe31dff8a8127ea90d023104e52754e4d7

The address that received the stolen funds: 1B6rJRfjTXwEy36SCs5zofGMmdv2kdZw7P

From there, the Bitcoin was spread across ten further addresses:

bc1qegcazuxnp5wxxxamdqvjv345fpve6656vpjln4

Sums referenced in this case file

bc1qgcv2j80009apvjekph40wagwutfu6l3gcm2fw0

bc1q2u9m2eqy8glvrjeqr5sceqngpad6dnxrtyxlf3

bc1q2tu4dxyvnaquar96mj99yqjanfzgg3fv4gzytd

bc1q7p3atj3v95k4pd7qxnnqlhjwu843ty2hqn9gy0

bc1qr4vnu4f4tl3gwfxt6a5hgt6vuusgsd0j2cnz74

bc1q3ur23g02rq5w0x6y8vek3xradjgs080nzksfje

bc1qrtltlc7zjzj3knde2tqjt7tl2p5l2keh4l2uka

bc1qx6jpnnfjrfcx9ehhdmj7qqyzpyd8pek00trrq7

bc1q7pdecv2raf3x84unxlv9ghtpjfpwlam6dx27xd

To help identify whoever carried out the theft, Arkham Intelligence launched a bounty program. Payouts are tied to identifying a KYC'd exchange deposit connected to the stolen funds, unmasking the exploiter's identity, or contributing to a successful recovery effort.

With the stolen coins being tracked closely on-chain, it remains an open question whether blockchain forensics combined with the bounty incentive will lead to the attacker's identification and the return of the $304 million.

Whatever else it becomes, the DMM breach reinforces a familiar lesson: custody matters, and centralized storage carries centralized risk. DMM has said it intends to make affected customers whole, though replacing that volume of Bitcoin will not be simple or cheap.

The Arkham bounty program could yet help recover funds or expose those responsible, and on-chain investigators have cracked comparable cases before. Even so, with the stolen coins already scattered across multiple addresses, following the trail further may prove to be a long and complicated task. Whether the bounty and blockchain analysis together are enough to resolve the case before it cements itself as one of 2024's largest crypto losses remains to be seen.

The precise cause of the breach — address spoofing, a compromised private key, or something else entirely, including the possibility of an inside job — has not been confirmed. Separately, the practice of holding such a large sum in a hot wallet rather than cold storage has drawn criticism as an avoidable risk.

Whether those responsible are ever identified, or simply disappear into crypto's long list of unsolved thefts with $304 million to show for it, is still unknown.

DMM Bitcoin
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.