On-chain investigator ZachXBT published findings on July 14, 2024, linking North Korea’s Lazarus Group to the devastating $305 million hack of Japanese crypto exchange DMM Bitcoin, which occurred in May 2024. The revelation came as the blockchain sleuth traced approximately $35 million in stolen funds being laundered through the Cambodia-based online marketplace Huione Guarantee, exposing a sophisticated multi-chain laundering operation that highlights the persistent threat posed by state-sponsored cybercriminal groups.
The Exploit Mechanics
The original hack targeted DMM Bitcoin on May 31, 2024, resulting in the theft of 4,502.9 BTC, valued at approximately 48 billion yen, or roughly $305 million at the time of the breach. The exchange confirmed the incident shortly after, suspending withdrawals and launching an internal investigation. DMM Bitcoin subsequently raised approximately $320 million to fully compensate affected users, underscoring the severity of the attack and the exchange’s commitment to making its customers whole.
According to ZachXBT’s analysis, the laundering process employed by the attackers follows a highly structured pattern consistent with Lazarus Group operations. The stolen Bitcoin is first deposited into a cryptocurrency mixer to obscure its origin. Once mixed, the funds are bridged from the Bitcoin network to Ethereum or Avalanche using cross-chain protocols including THORChain, Threshold, and the Avalanche Bridge. On these smart contract platforms, the Bitcoin is swapped for USDT, then bridged once more to the Tron network via SWFT, before finally being transferred to Huione Guarantee wallets.
Affected Systems
The investigation revealed that the laundering operation exploited multiple decentralized infrastructure components. Cross-chain bridges, particularly THORChain and Threshold, were used to move funds between blockchains without centralized intermediaries. The Tron network served as the final transit layer due to its low transaction fees and popularity for USDT transfers. Huione Guarantee, described by blockchain analytics firm Elliptic as having received over $11 billion in crypto since 2021 across wallets linked to its operations, functioned as the cash-out destination.
Stablecoin issuer Tether responded swiftly to the unfolding situation, blacklisting $29.6 million in USDT held in a Tron-based wallet connected to Huione Guarantee. Bitrace, a Web3 investigative tool provider, confirmed that the address was frozen because it assisted malicious actors in laundering funds from criminal activities, including fraud and crypto theft. The wallet had reportedly received approximately $14 million from the DMM Bitcoin hack within just three days.
The Mitigation Strategy
The DMM Bitcoin hack and its aftermath illustrate several important defensive strategies for cryptocurrency exchanges. First, the rapid response by Tether in freezing illicit USDT demonstrates the effectiveness of real-time on-chain monitoring and collaboration between blockchain analytics firms and stablecoin issuers. Second, the investigation by ZachXBT, a independent researcher, highlights the growing role of community-driven security efforts in the crypto ecosystem.
For exchanges specifically, the incident reinforces the critical importance of cold storage solutions for the majority of customer funds, multi-signature authorization requirements for large transfers, and real-time transaction monitoring systems capable of detecting unusual withdrawal patterns. DMM Bitcoin’s ability to compensate users through a $320 million fundraising effort also speaks to the value of maintaining adequate reserves and insurance mechanisms.
Lessons Learned
North Korean hacking groups, particularly Lazarus, have been responsible for over $1.3 billion in cryptocurrency theft throughout 2024 alone. Their methods continue to evolve, leveraging increasingly sophisticated cross-chain laundering techniques that take advantage of the decentralized finance ecosystem’s infrastructure. The use of Huione Guarantee, linked to Cambodia’s ruling Hun family through the Huione Group conglomerate, reveals how certain jurisdictions have become safe havens for processing stolen digital assets.
The crypto industry must strengthen cross-chain monitoring capabilities, develop better relationships with bridge operators to flag suspicious large-value transfers, and work more closely with regulators to identify and shut down laundering pipelines before stolen funds can be converted to fiat currency.
User Action Required
Individual cryptocurrency users should take this incident as a reminder to diversify their holdings across multiple platforms rather than keeping all funds on a single exchange. Hardware wallets remain the most secure option for long-term storage of significant cryptocurrency holdings. Users should also enable all available security features on their exchange accounts, including two-factor authentication, withdrawal whitelist restrictions, and anti-phishing codes. Staying informed about exchange security incidents and promptly moving funds when concerns arise can prevent losses from future exchange breaches.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Always conduct your own research before making any financial decisions.
zachxbt is doing more on-chain investigative work than most three letter agencies at this point. the huione guarantee tracing was meticulous
zachxbt traced 35M through huione but the remaining 270M is probably already converted to fiat through Macau casinos. that path is basically untraceable
More than probably. The junket route predates crypto entirely. The 2025 huione sanctions closed one door while the casino side stayed wide open.
4502.9 BTC stolen and DMM raised $320M to compensate users. Thats commitment most exchanges wouldnt match.
$35M through huione is just the tip. lazarus typically launders through 5-6 layers before it reaches anything traceable
5-6 layers is conservative. some of the wright chain analysis showed them going through 12+ hops before hitting huione
chain_sleuth_ 12+ hops is standard for Lazarus since the Ronin bridge. they learned from Harmony and Nomad tracing and added layers
chainhop_tracer_ 12+ hops is standard lazarus since the Ronin bridge hack. they learned from earlier tracing and added layers each cycle
the chain-hopping pattern zach described is textbook lazarus. mixers, bridges, stablecoin swaps, repeat. same playbook since 2019
same playbook since 2019 and huione is still operating freely. at what point does the cambodian government face actual pressure to shut it down
Minho P. cambodian government wont shut down huione because its generating foreign currency inflow. enforcement actions are performative at best
Minho P. Huione operates openly because the Cambodian government gets a cut. its not ignorance, its complicity at this point
rektagain_ DMM raising 320 million to compensate users was honorable but it also shows how thin exchange reserves really are. 4502 BTC gone in minutes
DMM raising $320M to make users whole is commendable but its also proof that exchange insurance funds are woefully inadequate for nation state attacks
darkforest_ DMM compensating users with 320M raised post-hack is more than FTX ever did. but you are right that insurance funds are a joke against state actors
zachxbt tracing 35 million through huione guarantee solo while governments do nothing. one guy outperforming entire three letter agencies
zachxbt_fan one guy tracing 35M through huione solo while three letter agencies do nothing. the gap between individual researchers and government action is wild
4502 BTC stolen and DMM made users whole with 320M raised. compare that to FTX where customers are still waiting years later. DMM handled it right
treasury_bleed_ 4502 BTC stolen and DMM raised 320M to make users whole. compare that to FTX where customers are still waiting years later
DMM raising 320 million in weeks also shows the model only works when the parent company is huge. A mid size exchange gets hit like that, it is simply gone
at least dmm had a parent with deep pockets. the lesson retail keeps refusing is that custody risk is the actual position
thorchain and threshold getting namechecked as laundering rails and somehow both still operating at full capacity afterward. bridges are the mixer now and nobody enforces anything
35 million traced through huione is what, a tenth of the haul. the other 270 million is still walking and nobody posts about that part
part of it walked through macau casinos years before zach flagged it. cash out via junkets is the oldest lazarus move in the book, chain analysis just cant follow it
and the 35M only got followed because they wanted it seen. the loud stretch of the trail is usually the distraction
DMM covering users with 320M raised in weeks sets a precedent no exchange can afford to repeat. one mid size platform takes this hit and its simply gone