DMM Bitcoin, a Japanese centralized cryptocurrency exchange, was the target of a sophisticated hack in May 2024. This incident marked the eighth-largest crypto heist of all time and the most significant since December 2022.
The hack was first identified when a large-scale transfer of 4,502.9 BTC, valued at over $308 million, was detected moving from one unknown Bitcoin wallet to another. Initially, the nature of this transfer was unclear — whether it was a whale moving assets or a security breach. However, the situation became more concerning when the stolen Bitcoin was distributed to multiple addresses, complicating efforts to track and recover the funds.
This hack is particularly notable in the context of Japanese crypto history. It follows major incidents like the 2018 Coincheck hack, where over $530 million worth of XEM was stolen, and the infamous Mt. Gox collapse in 2014, which saw over 809,000 BTC stolen across multiple hacks.
DMM Bitcoin quickly acknowledged the breach, confirming that the exchange had been hacked. The company took immediate steps to investigate the incident, prevent further unauthorized access, and reassure customers that their deposits were secure. As a precaution, certain services were temporarily frozen, including withdrawals and new account openings, to contain the damage and facilitate the investigation.
In response to the hack, DMM Bitcoin announced plans to secure funds for procuring the stolen bitcoin with financial support from its parent company, DMM Group. By June 3, the exchange had borrowed 5 billion yen ($32 million) and planned additional funding of 48 billion yen ($307.6 million) by June 7, followed by 2 billion yen ($12.8 million) on June 10, totalling $352.4 million. DMM Bitcoin aims to replace the stolen bitcoin without impacting the market and continues to investigate the incident, apologizing for the inconvenience caused to its customers.
Despite these efforts, DMM Bitcoin did not provide detailed information about the root cause of the hack. Several potential vulnerabilities could have been exploited by the attackers, including:
Exposed Private Keys: Private keys are crucial for securing blockchain accounts. If a hot wallet's key was compromised, either through an insider threat or external breach, attackers could easily transfer funds to their wallets.
As one can see from the attack transaction, multisig 2 of 3 was used in this case, so the hacker needed to compromise 2 private keys. This happens but is quite rare or the signature service of DMM Bitcoin can be hacked.Address Poisoning: By seeding a user’s transaction history with lookalike addresses, attackers could trick users into sending funds to the wrong address. In this case, users send funds to the latest address from the transaction history.
However, this method is less likely, because the hacker address was new and it didn't send any transactions before the attack transaction.
Arkham Intel has launched a bounty program to help identify the perpetrators. The guidelines for the bounty include identifying a KYC (Know Your Customer) centralized exchange deposit, revealing the exploiter's identity, and successful recovery of the funds.
With the stolen Bitcoin transactions being closely monitored, blockchain forensics and the bounty program might lead to the hacker’s unmasking and potential recovery of the $304 million. However, the task is daunting, given the sophisticated measures typically employed to launder such significant sums.
The DMM Bitcoin hack underscores the critical need for robust security practices to protect high-value cryptocurrency accounts. Key security measures that can help prevent similar incidents include:
Employee Training: Ensuring that all employees are trained in the latest cybersecurity practices can help mitigate the risk of insider threats and social engineering attacks, which seems like the most possible vector of the attack.
While the root cause of the DMM Bitcoin hack remains unclear, the current status of the stolen funds offers valuable insights. Shortly after the hack, many crypto investigation companies noted that the stolen BTC was divided among ten new crypto wallets and has remained there since. This transparency is a unique feature of blockchain technology, anyone can view these addresses and monitor future movements of the funds.
The global community is now watching to see how the hacker might attempt to launder the stolen Bitcoin. Typically, criminals use various services, such as mixers, to obfuscate the origin of their funds. However, today's advanced cryptocurrency investigation tools and techniques can often trace these funds even after they pass through mixing services.
Interestingly, the hacker has not yet begun moving the stolen BTC to launder them, likely due to the immediate reporting of the hack. Prompt reporting of crypto crimes can accelerate investigations and increase the chances of recovering stolen assets. At Gftd Japan, we emphasize the importance of swift reporting to our clients, as it significantly enhances the success rate of crypto investigations.
Blockchain investigations are powerful tools for recovering stolen funds and preventing future hacks. Knowing that their actions can be traced may deter potential hackers from attempting such crimes. Gftd Japan provides comprehensive crypto investigation services for victims of hacks and scams. If you need our assistance, please contact us and read more about our crypto investigations service.
The DMM Bitcoin hack serves as a stark reminder of the ongoing risks faced by cryptocurrency exchanges and the critical need for robust security measures. By implementing advanced security practices and continuously monitoring and improving their systems, exchanges can better protect their cryptocurrency and maintain the trust of their users. For organizations seeking to enhance their cybersecurity measures, consulting with experts like Gftd Japan can provide the necessary tools and strategies to safeguard digital assets effectively. We can also investigate crypto hacks and help recover stolen cryptocurrency. If your organization needs assistance in strengthening its cybersecurity framework, contact Gftd Japan. Book a call with us today to secure your digital assets.