Skip to content
NetarxImpact Database
Fake Job Offer / Recruitment LureNo AI reportedConfirmed

LinkedIn recruiter lure at wallet vendor Ginco led to $308M DMM Bitcoin theft

DMM Bitcoin, via wallet software vendor Ginco · Cryptocurrency · Japan · May 2024

Funds lost
$308,000,000
Money actually taken from, or wired out by, the victim.
4,502.9 BTC, valued at approximately $308 million in the joint FBI/DC3/NPA advisory; Japanese reporting at the time cited roughly $305 million. DMM Bitcoin subsequently wound down, transferring assets to SBI VC Trade.

What happened

Japanese exchange DMM Bitcoin lost 4,502.9 BTC, about $308 million, in late May 2024. A joint advisory from the FBI, DoD Cyber Crime Center and Japan's National Police Agency traced the intrusion to March 2024, when a North Korean operative posing as a recruiter on LinkedIn contacted an employee of Ginco, the wallet software vendor DMM relied on. The theft was attributed to the TraderTraitor cluster.

How the deception worked

The recruiter pretext delivered a malicious Python script hosted on GitHub, framed as a pre-employment coding assessment. The Ginco employee copied the script into their own GitHub account to work on it, which handed the attacker access to session cookie data. Using those session cookies the attacker impersonated the employee and compromised Ginco's unencrypted internal communications system. From there they waited: in late May a DMM Bitcoin employee submitted a legitimate transaction request through Ginco's system, and the attacker altered it in flight so that the withdrawal, which carried valid authorisation from DMM's side, sent 4,502.9 BTC to attacker-controlled addresses.

AI involvement · No AI reported

No AI involvement was reported in the joint FBI, DC3 and NPA advisory.

The control that would have caught it· our reading, not a claim from the sources

Take-home coding tasks must be isolated from corporate identity and never touched by an account with production session access, and transaction requests should be verified against an independent channel between exchange and custody vendor before signing.

Sources (2)

  1. FBI, DC3, and NPA Identification of North Korean Cyber Actors, Tracked as TraderTraitor, Responsible for Theft of $308 Million USD from Bitcoin.DMM.com
    Federal Bureau of Investigation·fbi.govOpen ↗
  2. FBI reveals North Korea used LinkedIn to steal $305 million from Japan's DMM Bitcoin
    CryptoSlate·cryptoslate.comOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.