Recommended Free Tools
On May 31, 2024, Japanese cryptocurrency exchange DMM Bitcoin disclosed that 4,502.9 BTC held for customers had been transferred out without authorization. The bitcoin was valued at about ¥48.2 billion, or roughly $305 million at the time. In December, the FBI, the U.S. Department of Defense Cyber Crime Center and Japan’s National Police Agency attributed the theft to North Korean cyber actors associated with TraderTraitor, describing a chain that began with a fake recruiter targeting an employee of wallet-software company Ginco.
DMM said it would replace the bitcoin and guarantee customer holdings. That commitment is not the same as independently verified proof that every customer’s repayment was completed. The incident was called the eighth-largest crypto theft at the time; that is a historical ranking from 2024, not a current all-time position.
What was stolen from DMM Bitcoin?
The reported loss was 4,502.9 bitcoin, assets DMM Bitcoin held for customers. Japanese financial authorities cited a value of approximately ¥48.2 billion. Contemporary reporting put the value at about $305 million, while the FBI later described it as approximately $308 million at the time of the attack. These dollar figures are estimates tied to different valuation points; the bitcoin quantity is the more stable measure. Japan’s Financial Services Agency (FSA) and the FBI’s later account report the respective figures.
DMM initially called the event an “unauthorized leakage.” News coverage commonly calls it a hack or theft, while Japanese regulatory documents describe crypto assets being illegally transmitted outside the company. These terms refer to the unauthorized outflow; they do not mean the Bitcoin network itself was shown to have been compromised. The Japan Virtual and Crypto assets Exchange Association also reported the 4,502.9 BTC figure and DMM’s customer guarantee statement.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware match#1 Best Overall
- Effortlessly build your crypto portfolio via the all in one Ledger Wallet app: buy, sell, send, receive, swap, stake and more across popular blockchains. 15,000+ coins & tokens in a single dashboard. Keep a close eye on the market. Compare service providers. Track performance. Get timely alerts. Build your portfolio with confidence.
- Effortlessly build your crypto portfolio via the all in one Ledger Wallet app: buy, sell, send, receive, swap, stake and more across popular blockchains. 15,000+ coins & tokens in a single dashboard. Keep a close eye on the market. Compare service providers. Track performance. Get timely alerts. Build your portfolio with confidence.
- Enjoy Bluetooth connectivity, iOS access, and hours of battery use with this mobile-first, secure backup signer. Freedom you can depend on.
- Genuine Check: confirm your signer is authentic during setup with the Ledger Wallet app.
- Protect your signer: keep it in mint condition at all times with a bespoke Pod or Case to avoid scratches and everyday wear and tear.
When did the attack happen?
May 31, 2024, is the date DMM publicly disclosed the outflow. A later Japanese regulatory summary refers to the illegal transmission on May 13. The public sources therefore use different dates for the event; the available accounts do not establish a definitive explanation for the discrepancy. The FBI’s December reconstruction describes an attack sequence that began well before DMM’s announcement.
- Late March 2024: A person posing as a recruiter contacted a Ginco employee through LinkedIn and sent a malicious Python script disguised as a pre-employment coding test, according to the FBI.
- After mid-May: The attacker used session-cookie information to impersonate the employee and access Ginco’s unencrypted communications system.
- Late May: The FBI said the attacker likely manipulated a legitimate transaction request made by a DMM employee.
- May 31: DMM publicly disclosed that 4,502.9 BTC had left its wallets without authorization.
- June 4: The FSA said DMM had reported a policy to compensate customers for the full amount and required the company to report on the causes and its compensation policy. The FSA’s press-conference record summarizes the response.
- September 26: The Kanto Local Finance Bureau issued a business-improvement order following an inspection. The FSA’s weekly review summarizes the action.
- December 23: The FBI, DC3 and Japan’s NPA publicly attributed the theft to North Korean actors associated with TraderTraitor.
How did the attackers get in?
The FBI’s public account describes a social-engineering and access-compromise chain involving Ginco, a Japanese enterprise cryptocurrency-wallet software company. It does not provide a complete technical reconstruction of every system or signing step, so details described as likely should not be treated as certain.
- A threat actor impersonated a recruiter on LinkedIn and contacted a Ginco employee.
- The employee received a GitHub link to a malicious Python script presented as a coding or pre-employment test. The employee copied the code to a personal GitHub page and was compromised.
- Later, the attacker used session-cookie information to impersonate the employee and access Ginco’s unencrypted communications system.
- The attacker likely manipulated a legitimate transaction request from a DMM employee.
- The resulting transaction sent 4,502.9 BTC to wallets controlled by the attackers.
This was not simply a case of an attacker breaking Bitcoin’s protocol. The government account points instead to compromise and manipulation around people, communications and transaction operations. It also places a third-party wallet-software provider in the attack chain, rather than describing a direct intrusion into DMM alone.
Rank #2
- Proven security at scale: Over 9 years and millions of cards issued with no known remote hacks, while military‑grade EAL6+ security keeps your private keys locked inside the chip. Your cryptocurrencies stay strongly protected from online attackers.
- Tap once to manage your entire crypto wallet across 90 blockchains - no USB cables or Bluetooth, no batteries, no setup. Access 14,100+ coins & tokens, DeFi, NFTs, and staking instantly from your phone
- Smart backup: Use your second Tangem Wallet as your Backup keys with end‑to‑end encryption; no more papers, pictures. If one card is lost, the remaining can still restore full access, with an optional seed phrase available for advanced users.
- Engineered to last up to 25 years: Waterproof (IP69K), shockproof and tested for extreme temperatures from −25°C to 50°C. A durable cold wallet with long‑term protection and independently audited security.
- Trusted by 6 million users worldwide - buy, sell, swap, stake, and spend cryptocurrency directly. The secure offline storage wallet designed for how people actually use crypto wallets
Who did authorities blame?
The FBI, DC3 and Japan’s National Police Agency attributed the theft to North Korean cyber actors associated with TraderTraitor. The activity is also tracked under names including Jade Sleet, UNC4899 and Slow Pisces. The agencies’ attribution is an investigative finding, not a public criminal conviction naming the individuals who carried out the theft. It does not establish that every operation using one of these threat labels was conducted by the same people. The joint government announcement gives the attribution and attack details.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Was this a cold-wallet hack?
A corporate filing later described the stolen customer assets as held in cold wallets. Cold storage can keep private keys away from some internet-connected systems, but the label does not establish that every part of a custody operation is offline or immune to compromise. Transaction requests, communications, employee sessions, wallet-management systems and approval workflows can remain relevant to how an asset is moved.
The public accounts establish the unauthorized transfer and describe the Ginco-related compromise, but they do not document every wallet-control or signing mechanism. It is therefore more precise to say that customer bitcoin was stolen through a compromised operational chain than to claim that an offline private key was directly extracted. The SEC-filed corporate disclosure uses the cold-wallet characterization.
Rank #3
- All your digital assets in one place. You can manage thousands of crypto including Bitcoin, Ethereum, Solana, Tether and more.
- Defend your identity against hackers: secure your online accounts with passwordless, hardware backed, 2FA logins for all your favorite apps and websites.
- Connectivity: USB-C cable connection only. No Bluetooth.Compatible with the Ledger Wallet crypto app, both desktop (Windows, macOS, Linux) and mobile (Android only). Not compatible with iOS.
- Protect your digital assets with the industry's best security: keep your private keys offline in your private signer, battle-tested by the Donjon's white hat hackers, CC EAL 6+ certified Secure Element, constantly updated Ledger OS.
- Effortlessly build your crypto portfolio via the all in one Ledger Wallet app: buy, sell, send, receive, swap, stake and more across popular blockchains. 15,000+ coins & tokens in a single dashboard. Keep a close eye on the market. Compare service providers. Track performance. Get timely alerts. Build your portfolio with confidence.
Were DMM Bitcoin customers reimbursed?
DMM said it would procure replacement bitcoin with support from group companies and guarantee all bitcoin entrusted by users. The FSA confirmed that DMM had reported a policy to compensate the full amount and required the company to report on its response. Those statements show a commitment and regulatory oversight; the cited public records do not independently verify the final timetable, payment method or completion of every customer payment.
A compensation guarantee should not be confused with deposit insurance or with the ability to reverse a confirmed Bitcoin transaction. The terms of any remedy depend on the company’s implementation; the sources cited here do not establish whether every customer received bitcoin, yen or another form of compensation.
What did Japanese regulators find?
On September 26, 2024, the Kanto Local Finance Bureau issued DMM Bitcoin a business-improvement order after an inspection. The regulator’s concerns extended beyond the fact of the theft to the company’s governance and information-system risk controls.
Rank #4
- UNPARALLELED SECURITY: Protect your assets with Trezor Safe 5's NDA-free EAL 6+ Secure Element, offering robust defense and complete transparency.
- EFFORTLESS NAVIGATION: Experience seamless crypto management with the vibrant color touchscreen, designed for intuitive and user-friendly interactions.
- ENHANCED USER EXPERIENCE: Enjoy tactile confirmation with Trezor Touch Haptic Engine, making each interaction precise and engaging.
- SUPPORTS 1000s OF COINS & TOKENS: Securely handle thousands of assets, including Bitcoin, Ethereum, and more, all in one wallet.
- EASY ASSET MANAGEMENT: Monitor and transact seamlessly with Trezor Suite, our user-friendly desktop and mobile app
- System-risk, development, operations and information-security responsibilities were concentrated among a limited number of people.
- The company lacked a system-management executive from the start of operations, according to the regulatory findings.
- Independent monitoring and checks and balances were weak.
- Information-system risk management and handling of crypto-asset outflow risk were inadequate.
The Kanto Local Finance Bureau’s detailed order describes the governance deficiencies and includes the May 13 date reference. The FSA’s administrative-action notice records the order. The action matters because it documents weaknesses in oversight and control, not only the loss itself.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Why was it called the eighth-largest crypto theft?
Contemporary reporting citing blockchain analytics firm Elliptic called the DMM incident the eighth-largest cryptocurrency theft on record at the time. TechCrunch’s May 31, 2024 report used that ranking alongside the approximately $305 million estimate. The rank is date-bound: later thefts, including the 2025 Bybit incident, were substantially larger, so “eighth-largest in history” should not be presented as the current all-time standing.
Rankings also depend on what is counted. A list of exchange hacks may differ from one that includes bridge exploits, protocol breaches, fraud, insider theft or losses tied to a company’s collapse. FTX, for example, involved allegations of fraud and misuse of customer funds alongside bankruptcy, rather than one clearly bounded wallet theft of the same kind. Dollar rankings can also shift with the valuation date and the assets included. Chainalysis’s 2025 Crypto Crime Report provides later context on crypto crime and North Korea-linked theft.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesBest Value
- Dual-chip architecture for maximum protection: The next-gen, fully auditable TROPIC01 chip works alongside a certified EAL6+ Secure Element—completely NDA-free—to deliver radically transparent, industry-leading defense against physical attacks.
- Quantum-ready security: Get protection against future threats with the first-ever hardware wallet designed with quantum-ready architecture.
- See every detail with confidence: Our largest high-resolution color touchscreen makes it easy to navigate your assets, review transactions and manage your coins with clarity.
- Wireless freedom with encrypted Bluetooth control: Manage, buy, swap and stake securely using Trezor Suite on desktop or mobile. Qi2-compatible wireless charging keeps your Trezor powered up. No cables required—security meets convenience.
- Works seamlessly with Android, iOS and desktop: Connect wirelessly or via USB-C to your phone or computer. Manage your crypto anywhere with our companion Trezor Suite app.
What the incident shows about exchange custody
Third-party providers add another control boundary
Using a specialist wallet-software provider can supply expertise and infrastructure an exchange would otherwise need to build. It also creates dependence on the provider’s employee security, session controls, communications and incident response. A vendor relationship therefore needs independent monitoring and a clear process for verifying transaction requests, not just contractual assurance.
People and sessions can be part of the attack surface
The alleged fake-recruiter approach illustrates how a malicious coding test can target an employee before any exchange transaction is involved. Session-cookie theft can then let an attacker act as a legitimate user without needing to guess a password at the moment of access. Practical controls include treating unsolicited recruiting tests and code links cautiously, protecting sessions, and verifying sensitive requests through a separate trusted channel.
Cold storage is one safeguard, not a complete security model
Keeping keys offline can reduce exposure, but custody also depends on how requests are created, reviewed, authorized and signed. Independent transaction checks, separation of duties, tightly limited privileges and monitoring for abnormal transfers address risks that the phrase “cold wallet” alone does not resolve.
Exchange custody and self-custody shift rather than erase risk
An exchange account places asset access and security controls with the exchange, which may provide customer support and a corporate remedy when something goes wrong. It also exposes customers to centralized systems, staff and vendors. Self-custody removes the exchange as custodian but makes the user responsible for safeguarding recovery phrases, devices and signing decisions; phishing, device compromise and irreversible mistakes remain risks. Neither approach makes loss impossible.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




