US and Japanese law enforcement say North Korean hackers were responsible for stealing 4,502.9 bitcoin, worth $308M, from Japanese exchange DMM in May 2024
The $308 million hack of Japanese crypto exchange DMM in May was the work of North Korean hackers, the U.S. and Japanese law enforcement agencies said Monday.
CoinDeskSheldon Reback
Context & Ripple Effects
DMM first disclosed the loss of 4,502.9 bitcoin as an unauthorized outflow, then outlined a plan to replace the bitcoin and make customers whole through a roughly $321M funding plan. The new attribution turns an exchange-specific incident into a formally identified cross-border cybercrime case.
U.S. and Japanese authorities now publicly assign responsibility for the DMM theft to North Korean hackers, giving the case a defined alleged perpetrator rather than an unresolved exchange breach.
The attribution reinforces the significance of DMM’s prior customer-remediation effort and subsequent exit from the market, rather than treating the loss as an isolated operational failure.
Second-order effects
Japanese exchanges and their customers are likely to view custody, wallet-access controls, and incident-response capacity as competitive and continuity risks, particularly after DMM’s planned asset transfer to SBI VC Trade.
If major thefts continue to force remediation and market exits, crypto-exchange competition may increasingly favor firms with stronger operational resilience and the capacity to absorb customer losses.
State-linked crypto theft is becoming a persistent geopolitical-security issue for digital-asset markets, linking exchange security failures to international law-enforcement and national-security responses.
The trend: Crypto theft is shifting from a firm-level security problem toward a cross-border financial-security issue as state-linked actors target exchanges and breaches reshape market participation.
The FBI and international partners are reporting a North Korean crypto theft from a Japan-based company. After an initial compromise with social engineering techniques, the cyber actors used TraderTraitor malware to steal cryptocurrency worth $308 million: https://www.fbi.gov/...…
??? > After mid-May 2024, TraderTraitor actors exploited session cookie information to impersonate the compromised employee and successfully gained access to Ginco's unencrypted communications system.
DPRK's trading career is...uh....going.....🙈 tbh if i was the dude managing Hyperliquid's 4 validators (or those fucking ghetto ass binaries on gh) I would be shitting my pants right now. Hyperliquid dudes dont seem worried at all though so im sure its fine. 🫠 [image]
Hyperliquid Labs: We are aware of reports circulating regarding activity by supposed DPRK addresses. There has been no DPRK exploit - or any exploit for that matter - of Hyperliquid. All user funds are accounted for. Hyperliquid Labs takes opsec seriously. No vulnerabilities have
I can't speak much on the security of the actual Hyperliquid validators, but I am somewhat familiar with how the HL USDC bridge and Arbitrum work. Right now there's $2.3B of USDC in the HL bridge contract deployed on Arbitrum. Most of the functions in this bridge contract are
Next question is: how many North Korean programmers does Hyperliquid employ, knowingly or not. Time to take a closer look at those company devs you've never met in person who claim to live in Singapore or Thailand.
Imagine being a VC amid the Hyperliquid / DPRK / Tay fallout and deciding yeah, I could just not say anything... or I could randomly chime in with this and not bring any receipts💀💀💀 [image]
my best attempt at a tldr on this North Korea / Hyperliquid stuff: An industry veteran white hacker made a tweet saying they think Hyperliquid should chat with them bc North Korea is trading on their platform and trying to find a way to exploit it (they do this on lots of
OK, so in case you didn't get it and are raging at Tay in the comments: 1. North Korea doesn't trade on Hyperliquid. If they are getting liquidated on HL, it means they are testing a potential vulnerability. 2. Yes she works at Metamask, which is irrelevant. Hope this helps.