Massive $308 Million Crypto Heist Linked To LinkedIn Job Scam

An FBI report reveals a $308 million Bitcoin theft linked to a LinkedIn job scam by North Korean hackers, highlighting the growing threat of cybercrime in the cryptocurrency sector.

A recent FBI report has unveiled a sophisticated cyber heist that resulted in the theft of $308 million in Bitcoin from the Japan-based cryptocurrency firm DMM. The attack, attributed to North Korean cyber actors, began with a deceptive LinkedIn job recruitment scheme that exploited social engineering tactics.

Key Takeaways

  • North Korean hackers, known as TraderTraitor, executed a $308 million Bitcoin theft from DMM.
  • The attack initiated through a LinkedIn scam targeting an employee at Ginco, a cryptocurrency wallet provider.
  • The hackers used a malicious Python script disguised as a coding test to gain access to sensitive systems.
  • The incident highlights the growing trend of cybercriminals leveraging professional networking platforms for attacks.

The Attack Unfolds

The FBI's investigation revealed that the cybercriminal group TraderTraitor, operating under various aliases, orchestrated the attack in late March 2024. They targeted an employee at Ginco, a company that provided essential wallet management services to DMM. The attackers posed as recruiters on LinkedIn, establishing a seemingly legitimate connection with their target.

The critical breach occurred when the attackers sent a malicious URL disguised as a coding test. The unsuspecting employee executed the script, which compromised their system and allowed the hackers to gain unauthorized access to Ginco's internal communications.

Technical Execution of the Heist

By mid-May 2024, the TraderTraitor group had successfully infiltrated Ginco's systems. They exploited session cookies to impersonate the compromised employee, enabling them to monitor and manipulate legitimate transaction requests.

The heist culminated in late May when the hackers intercepted a transaction request from a DMM employee. They altered the transaction parameters, resulting in the unauthorized transfer of 4,502.9 Bitcoin, valued at approximately $308 million at the time.

International Cooperation in Investigation

The scale of this theft has prompted a coordinated response from international law enforcement agencies. The FBI is collaborating with Japan's National Police Agency and the Department of Defense Cyber Crime Center to track the stolen funds and identify the attack patterns used by TraderTraitor.

This incident underscores the ongoing threat posed by North Korean cyber actors, who are increasingly using sophisticated methods to fund their regime through cryptocurrency theft. Law enforcement officials emphasize that these attacks are part of a broader strategy to circumvent international sanctions.

Impact on the Crypto Industry

The fallout from this incident has been significant for DMM, which has announced plans to cease operations following the theft. The broader cryptocurrency industry has also felt the impact, with losses from hacks and fraud totaling approximately $1.5 billion in 2024, a 17% decrease from the previous year. Notable incidents include the $235 million hack of India's WazirX.

Despite the decline in overall losses, the DMM breach highlights the persistent vulnerabilities within the crypto sector, particularly regarding social engineering attacks that exploit human trust.

Conclusion

The $308 million theft linked to a LinkedIn job scam serves as a stark reminder of the evolving tactics employed by cybercriminals. As the cryptocurrency landscape continues to grow, so too does the need for enhanced security measures and awareness to protect against such sophisticated attacks. The collaboration between international law enforcement agencies is crucial in combating these threats and safeguarding the integrity of the crypto industry.

Sources

[ newsletter ]
Stay ahead of Web3 threats—subscribe to our newsletter for the latest in blockchain security insights and updates.

Thank you! Your submission has been received!

Oops! Something went wrong. Please try again.

[ More Posts ]

Trust Score API: Wallet and Contract Risk
18.10.2025
[ Featured ]

Trust Score API: Wallet and Contract Risk

Explore the Trust Score API for comprehensive wallet and smart contract risk assessment. Enhance Web3 security with dynamic, AI-powered insights.
Read article
Proof of Audit On-Chain: Verifiable Badge
18.10.2025
[ Featured ]

Proof of Audit On-Chain: Verifiable Badge

Explore Veritas, an AI-powered smart contract auditing system. Get verifiable proof of audit on-chain with immutable badges for enhanced security and transparency.
Read article
Demystifying MPC Wallets: A Comprehensive Guide to Multi-Party Computation Security
18.10.2025
[ Featured ]

Demystifying MPC Wallets: A Comprehensive Guide to Multi-Party Computation Security

Explore MPC wallets: a comprehensive guide to multi-party computation security, advantages over multisig, and real-world applications. Learn about MPC technology.
Read article