Digital Assets

DMM Bitcoin May 2024 Incident Analysis

Reconstructing the probable attack behind DMM Bitcoin’s $305 million loss through on-chain forensic evidence.

Published June 2024

Share:

Research details

Context

When 4,503 BTC disappeared from DMM Bitcoin's cold wallet in May 2024, the public record offered limited detail. OneInfinity's R&D team traced the on-chain evidence to reconstruct what likely happened, and found a pattern of address manipulation and operational negligence that a standard security audit would have flagged.

Key takeaways

  1. The exploited wallet used a two-of-three multi-signature scheme. Only two compromised or negligent signers were needed to authorise the transfer of 4,503 BTC. The on-chain evidence shows the transaction went through the standard signing flow, not around it.
  2. The attacker's address shared the first four and last two characters with DMM Bitcoin's operational hot wallet. This is consistent with address poisoning, a technique designed to exploit visual verification during routine approvals. A signer checking only the beginning and end of the address would see a match.
  3. DMM Bitcoin’s security practices relied on visual checking during cold-to-hot wallet transfers. Secure address whitelisting with cryptographic verification, transaction thresholds with automated alerts, and independent confirmation channels would have disrupted this attack at multiple points. OneInfinity’s underwriting process identifies exactly these gaps.

Contributors

  • Rex ZhangOneInfinity
  • OneInfinity R&D teamOneInfinity

Interested in working together?

Our team is expanding research across Web3, Cybersecurity, and AI.