Japan Lost 4,502 Bitcoin in a Day and the Exchange Never Recovered
The largest crypto theft of 2024 took 4,502.9 Bitcoin from a Japanese exchange in a single afternoon. The FBI later attributed it to North Korea. DMM Bitcoin announced it was shutting down seven months after.

On May 31, 2024, DMM Bitcoin lost 4,502.9 Bitcoin. At the time that was about $305 million, and it made this the largest crypto theft of the year by a comfortable margin.
DMM Bitcoin was not a fringe operation. It was a licensed Japanese exchange, part of the DMM.com group, operating in the jurisdiction that had rebuilt its entire regulatory framework around not letting this happen again after Mt. Gox in 2014 and Coincheck in 2018. Japan's Financial Services Agency had spent six years tightening custody rules, cold storage requirements and operational audits specifically so that a Japanese exchange would not wake up short several hundred million dollars. It happened anyway.
The mechanism was never fully detailed publicly. The consistent assessment across security firms is a compromised private key, with some analysts also raising address poisoning as a contributing vector. What is not disputed is the scale or the destination: the Bitcoin moved out in bulk and was routed through CoinJoin, a Bitcoin mixing technique that breaks the link between inputs and outputs and makes conventional chain analysis substantially harder.
In December 2024, the FBI, Japan's National Police Agency and partner agencies formally attributed the theft to North Korean actors, specifically the group tracked as TraderTraitor, which sits within the broader Lazarus umbrella. The named mechanism was social engineering: an approach to an employee at a company connected to DMM's infrastructure rather than a direct assault on the exchange itself. That pattern will be familiar to anyone who read the Ronin Bridge entry, where a fake LinkedIn job offer and a poisoned PDF cost Axie Infinity $625 million.
DMM's initial response was better than most. The company said it would make users whole and would do it by borrowing against its parent group's resources to buy back an equivalent amount of Bitcoin rather than passing the loss to customers. That is a serious commitment and it was, at least in intent, honoured. What it could not do was fix the underlying position. An exchange that has just handed 4,502 Bitcoin to a state-sponsored hacking unit has a customer trust problem no balance sheet fixes.
In December 2024, DMM Bitcoin announced it was winding down. Customer accounts and custodial assets would transfer to SBI VC Trade, part of the SBI Group, with the migration targeted for March 2025. The exchange had operated since 2018 and was closing seven months after the theft.
Nobody was arrested. Nothing was recovered. Attribution to a state actor is, in practical terms, the end of the road for asset recovery: there is no jurisdiction to sue, no defendant to extradite, and no realistic prospect that Pyongyang returns anything. What the attribution provides is intelligence value and sanctions leverage, not restitution.
The uncomfortable framing is that Japan's regulatory regime is genuinely among the strictest in the world, built deliberately in response to two prior catastrophes, and it did not prevent this one. Custody rules govern how an exchange stores keys. They do not govern whether an employee at a connected company opens the wrong file.
The Aftermath
DMM Bitcoin committed to making customers whole, backed by its parent group rather than passing losses to users, and by most accounts honoured that. It could not restore confidence in the business. In December 2024 the exchange announced it would wind down, with accounts and custodial assets transferring to SBI VC Trade by March 2025. No arrests have been made and none are realistic: the FBI and Japan's NPA attributed the theft to North Korea's TraderTraitor unit, which places recovery beyond the reach of any court. The stolen Bitcoin, laundered through CoinJoin, has not been recovered.
COMMENTS