Research details
Context
When 4,503 BTC disappeared from DMM Bitcoin's cold wallet in May 2024, the public record offered limited detail. OneInfinity's R&D team traced the on-chain evidence to reconstruct what likely happened, and found a pattern of address manipulation and operational negligence that a standard security audit would have flagged.
Key takeaways
- The exploited wallet used a two-of-three multi-signature scheme. Only two compromised or negligent signers were needed to authorise the transfer of 4,503 BTC. The on-chain evidence shows the transaction went through the standard signing flow, not around it.
- The attacker's address shared the first four and last two characters with DMM Bitcoin's operational hot wallet. This is consistent with address poisoning, a technique designed to exploit visual verification during routine approvals. A signer checking only the beginning and end of the address would see a match.
- DMM Bitcoin’s security practices relied on visual checking during cold-to-hot wallet transfers. Secure address whitelisting with cryptographic verification, transaction thresholds with automated alerts, and independent confirmation channels would have disrupted this attack at multiple points. OneInfinity’s underwriting process identifies exactly these gaps.
Contributors
- Rex ZhangOneInfinity
- OneInfinity R&D teamOneInfinity
Related Research

Bybit Incident Research
How a supply-chain compromise bypassed multi-signature controls in the largest crypto theft in history, and what custody operations can learn from it.
Read the analysis
Recent Centralized Platform Hack Tactics & Mitigation
Mapping the attack tactics behind over $2 billion in centralized platform losses and the layered controls that can disrupt them.
Read the analysis
A Risk Classification Framework for Decentralized Finance Protocols
Classifying the technical, economic, operational and infrastructure risks of DeFi protocols - giving insurers a consistent basis for comparing exposures.
Read the reportInterested in working together?
Our team is expanding research across Web3, Cybersecurity, and AI.

