/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

US and Japanese law enforcement say North Korean hackers were responsible for stealing 4,502.9 bitcoin, worth $308M, from Japanese exchange DMM in May 2024

The $308 million hack of Japanese crypto exchange DMM in May was the work of North Korean hackers, the U.S. and Japanese law enforcement agencies said Monday.

CoinDesk Sheldon Reback

Context & Ripple Effects

DMM first disclosed the loss of 4,502.9 bitcoin as an unauthorized outflow, then outlined a plan to replace the bitcoin and make customers whole through a roughly $321M funding plan. The new attribution turns an exchange-specific incident into a formally identified cross-border cybercrime case.

The breach’s business consequences were already substantial: DMM Bitcoin later opted to close and transfer accounts and assets to SBI VC Trade. It also fits the broader record of large North Korean-linked crypto thefts affecting Japanese businesses cited in related coverage.

First-order effects

  • U.S. and Japanese authorities now publicly assign responsibility for the DMM theft to North Korean hackers, giving the case a defined alleged perpetrator rather than an unresolved exchange breach.
  • The attribution reinforces the significance of DMM’s prior customer-remediation effort and subsequent exit from the market, rather than treating the loss as an isolated operational failure.

Second-order effects

  • Japanese exchanges and their customers are likely to view custody, wallet-access controls, and incident-response capacity as competitive and continuity risks, particularly after DMM’s planned asset transfer to SBI VC Trade.
  • The case adds a concrete Japanese example to allied reporting that North Korean-backed groups conducted major crypto thefts in 2024, supporting closer cross-border investigative coordination around stolen crypto flows.

Third-order effects

  • If major thefts continue to force remediation and market exits, crypto-exchange competition may increasingly favor firms with stronger operational resilience and the capacity to absorb customer losses.
  • State-linked crypto theft is becoming a persistent geopolitical-security issue for digital-asset markets, linking exchange security failures to international law-enforcement and national-security responses.

The trend: Crypto theft is shifting from a firm-level security problem toward a cross-border financial-security issue as state-linked actors target exchanges and breaches reshape market participation.

Discussion

  • @fbi @fbi on x
    The FBI and international partners are reporting a North Korean crypto theft from a Japan-based company. After an initial compromise with social engineering techniques, the cyber actors used TraderTraitor malware to steal cryptocurrency worth $308 million: https://www.fbi.gov/...…
  • @tayvano_ Tay on x
    holidays? what holidays? 👀 https://www.fbi.gov/...
  • @cheenanet Cheena on x
    ??? > After mid-May 2024, TraderTraitor actors exploited session cookie information to impersonate the compromised employee and successfully gained access to Ginco's unencrypted communications system.
  • @tayvano_ Tay on x
    DPRK's trading career is...uh....going.....🙈 tbh if i was the dude managing Hyperliquid's 4 validators (or those fucking ghetto ass binaries on gh) I would be shitting my pants right now. Hyperliquid dudes dont seem worried at all though so im sure its fine. 🫠 [image]
  • @wublockchain Wu Blockchain on x
    Hyperliquid Labs: We are aware of reports circulating regarding activity by supposed DPRK addresses. There has been no DPRK exploit - or any exploit for that matter - of Hyperliquid. All user funds are accounted for. Hyperliquid Labs takes opsec seriously. No vulnerabilities have
  • @0xcygaar @0xcygaar on x
    I can't speak much on the security of the actual Hyperliquid validators, but I am somewhat familiar with how the HL USDC bridge and Arbitrum work. Right now there's $2.3B of USDC in the HL bridge contract deployed on Arbitrum. Most of the functions in this bridge contract are
  • @safetyth1rd @safetyth1rd on x
    secured by four validators, being probed by Lazarus Ignoring security issues Hyper liquid
  • @stoicsavage @stoicsavage on x
    can everyone calm the fuck down now hyperliquid [image]
  • @0xfoobar @0xfoobar on x
    [image]
  • @silvermanjacob Jacob Silverman on x
    Next question is: how many North Korean programmers does Hyperliquid employ, knowingly or not. Time to take a closer look at those company devs you've never met in person who claim to live in Singapore or Thailand.
  • @jillrgunter Jill Gunter on x
    Imagine being a VC amid the Hyperliquid / DPRK / Tay fallout and deciding yeah, I could just not say anything... or I could randomly chime in with this and not bring any receipts💀💀💀 [image]
  • @zeneca @zeneca on x
    my best attempt at a tldr on this North Korea / Hyperliquid stuff: An industry veteran white hacker made a tweet saying they think Hyperliquid should chat with them bc North Korea is trading on their platform and trying to find a way to exploit it (they do this on lots of
  • @evgenygaevoy @evgenygaevoy on x
    I know Tay can be rough around the edges when it comes to communication style, but you don't mess with indicators like this
  • @tusharjain_ Tushar Jain on x
    Imagine how OFAC will react to a no KYC centralized exchange with North Korean activity (4 closed source validators = centralized)
  • @poorguard @poorguard on x
    OK, so in case you didn't get it and are raging at Tay in the comments: 1. North Korea doesn't trade on Hyperliquid. If they are getting liquidated on HL, it means they are testing a potential vulnerability. 2. Yes she works at Metamask, which is irrelevant. Hope this helps.
  • @blknoiz06 @blknoiz06 on x
    hyperliquid [image]