SBI Crypto's Mining Arm Loses $24 Million Across Five Chains Months After Playing DMM Bitcoin's Rescuer
Roughly six months after stepping in to absorb the customers of hacked exchange DMM Bitcoin — itself the victim of a $308 million North Korean theft — SBI Crypto found itself on the receiving end of what appears to be the same category of attacker.
On September 24, 2025, roughly $24 million left SBI Crypto's wallets across five separate blockchains, even as the mining pool continued to promote itself to institutional clients as a stable, secure operator. The withdrawal went unnoticed for roughly a week, until blockchain investigator ZachXBT published his findings on Telegram on October 1 — by which point the stolen funds had already passed through instant-exchange services and reached Tornado Cash.

Two days after that disclosure, SBI Holdings issued a brief statement acknowledging an "unauthorized outflow" and describing the expected hit to consolidated results as "minor." The notice offered no account of the attack method, no timeline for when the outflow was first detected internally, and no reference to the resemblance between this incident and the compromise that had struck DMM Bitcoin, the very company whose customers SBI had recently taken in.
That leaves the DMM Bitcoin customers who migrated to SBI's platform back in March 2025 in an awkward spot, having moved from one breached operator toward another that has just demonstrated its own vulnerability.
Sources: cryptonews, The Hacker News, CoinDesk, ZachXBT, SBI Group, CryptoSlate, MiningPoolStats, Chainalysis, CoinTelegraph, Tayvano
01A Week of Silence
Addresses tied to SBI Crypto began emptying out on September 24, 2025, with outflows spanning Bitcoin, Ethereum, Litecoin, Dogecoin, and Bitcoin Cash. The pool's mining operations continued running normally throughout, giving no outward sign that anything was wrong.
It took until October 1 for the situation to surface publicly, when ZachXBT posted his analysis to Telegram, describing coordinated outflows funneled through instant exchanges toward Tornado Cash. By then, roughly a week had passed and most of the laundering trail was already cold.
SBI Crypto operates as a mining-pool subsidiary of SBI Holdings, a Prime Market-listed Japanese financial conglomerate. The pool is not a minor operation: it commands close to 20 EH/s of hashrate, placing it 12th among global mining pools, and it accounts for more than 21% of Bitcoin Cash's total network hashrate. None of that scale translated into a prompt public response.
ZachXBT's write-up flagged several features consistent with known DPRK-linked operations — instant-exchange routing, a Tornado Cash endpoint, and coordination across multiple chains at once. He credited Cyvers with assisting the investigation. The pattern pointed toward an organized actor rather than an opportunistic one.
02SBI's Statement Answers Little
On October 2, SBI Holdings published a notice titled "Notice Regarding the Unauthorized Outflow of Crypto Assets at SBI Crypto Co., Ltd." It confirmed an unauthorized outflow of crypto assets owned by the subsidiary itself, stated that the company was still investigating the cause and the total amount lost, and estimated the effect on consolidated results would be "minor."
In effect: assets were drained, the mechanism was still unclear, and the final tally hadn't been finished — an odd basis on which to already characterize the financial impact as minor.
The notice did clarify that SBI VC Trade and BITPoint Japan, the group's domestic exchange businesses, were unaffected, with customer assets intact and operations continuing as normal. That distinction carries some weight given that SBI VC Trade had, only ten months earlier, taken on DMM Bitcoin's customer base following DMM's own $308 million North Korea-linked hack. Now a different arm of the same group had been drained through what looks like a comparable attack pattern.
The statement closed by mentioning "possible business restructuring going forward" for SBI Crypto's operations, without elaborating.
What the notice left out was arguably more notable than what it included: no description of the attack vector, no detection timeline, and no acknowledgment that the "thorough investigation" it referenced was already a week behind independent blockchain researchers who had documented the theft in detail.
03The Mechanics of the Theft
The September 24 outflows hit Bitcoin, Ethereum, Litecoin, Dogecoin, and Bitcoin Cash in a coordinated fashion — a scope that implies either substantial advance preparation or detailed familiarity with SBI Crypto's wallet setup, possibly both.
Ethereum
The Ethereum attacker wallet, 0x40d76a78ddba2ea81fb0f9fba147a08bcfc2b866, received $6.4 million pulled from an SBI Crypto pool address labeled on Arkham, 0x9f25779098c5632da2ec55d161c4e5f2afc4e0ec.
From there, 1,443 ETH moved to an intermediary address, 0xd2C8EDe41fb84d18353A7ABBcf6448f2E6B664e0. That wallet sent 924 ETH into Tornado Cash across 15 separate transactions, plus 30 ETH to the instant-exchange service SideShift in two 15 ETH batches.
In a notable twist, 246 ETH was routed back through one of SBI Crypto's own addresses before being swapped via the OpenOcean DEX using a Rabby wallet — the attacker effectively using the victim's own infrastructure as part of the laundering path.
Total stolen on Ethereum: $6.4 million.
Bitcoin
The bulk of the loss occurred on Bitcoin. The attacker's address, bc1qx0a2kfjd7eweczv8xqjm6rggm40v0nkhfss78l, took in $17.45 million pulled from several SBI wallets labeled by Arkham: bc1qte0s6pz7gsdlqq2cf6hv5mxcfksykyyyjkdfd5, bc1qrpp7g75sx3ejclvsfdw2uahzchtyu7vumkuadu, bc1q8uyg2xpp6vjlmn0g5c9kujr7scm4hry5g67uqe, and bc1qe2esaxek04jx7vn2eelu4u7fee90cd6nh09dhn.
As of October 3, 143.2 BTC remained sitting untouched in that address — either the attacker is waiting out attention before moving it, or a sum that size risks drawing scrutiny they aren't ready to invite yet.
Bitcoin Cash
The Bitcoin Cash attacker wallet, qpv9nh5ktagsmtkqle8z2w4dd3mksskpmy499z7c9k, took in 126.56 BCH from an SBI Crypto wallet not labeled on Arkham, qqzxuj5qvglktpq49v2wrg790a935z3cyssnfg4n4x. The funds were then split into 25.56 BCH and 101 BCH across two addresses, with the 101 BCH portion breaking down further through repeated two-way transfers, each hop shrinking the balance slightly through fees. As of October 3, this portion of the funds was still moving every few hours.
Total stolen on Bitcoin Cash: $67,874.
Litecoin
The Litecoin attacker address, ltc1qjyrn9p803efj3p8a0g3fmlevs45kq704ns363t, collected 719 LTC from two SBI Crypto wallets not labeled on Arkham: ltc1qczll7dppteakes3drx004e86um85pwvzzwwpyq and ltc1qn9hdc32jakpyavtnujvr7k08acwh8sg8qywjcy. The theft came in two batches: 504 LTC from the first wallet and 214 LTC from the second, the latter assembled from several smaller transfers. Funds were then split into 119 LTC and 385 LTC, followed by additional hops meant to fragment the trail.
Total stolen on Litecoin: $76,343.
Dogecoin
The Dogecoin attacker wallet, DRiEQuJ9pt3GgNraQmHVTjNg4B7uv1XuGb, received roughly 180,000 DOGE from an Arkham-labeled SBI Crypto wallet, DJJ9Rdcuama5GEjJo2oYfeKdvQEXA54BVL. The theft occurred in two waves: 92,115 DOGE, then 87,893 DOGE. Funds were then routed through a cluster of FixedFloat exchange addresses, splitting further with each hop.
Total stolen on Dogecoin: $42,718.
Combined total across all five chains: approximately $24 million.
Even though the Bitcoin Cash and Litecoin wallets involved lack Arkham labels, blockchain analysis confirms they were drained as part of the September 24 attack.
Across every chain, the amounts moved appear calibrated — large enough to be worthwhile, small enough to stay under common monitoring thresholds. The routing choices, the use of instant exchanges with minimal KYC, and the mix of DeFi protocols suggest the perpetrators had a working knowledge of which aggregators, exchanges, and privacy tools would obscure the trail most effectively while limiting exposure. The process varied by chain: rapid and technically involved for Ethereum, patient for Bitcoin (given the still-dormant 143.2 BTC), and heavily fragmented for the remaining three assets. Enough activity was left on-chain for investigators to trace the flow of funds, but not enough to make recovery realistic.
04What Remains Unexplained: The Entry Point

SBI Holdings' notice confirmed the outflow but did not address the central question: how did an attacker gain the access needed to drain wallets across five separate blockchains?
Two broad explanations are possible, and neither reflects well on a firm marketing itself on institutional-grade security.
Private key compromise. If the attacker obtained hot wallet private keys directly, no approvals or exploit chains were needed — key possession is control. This method accounted for 43.8% of stolen crypto in 2024, largely because it is straightforward when it works. Keys can leak through phishing, malware, keylogging, plaintext storage in cloud services, or overprivileged third-party vendors. Around the time of the incident, Tayvano publicly warned people to stop updating their "zoom sdk," noting it isn't a real update but malware. SBI Crypto has prior history with vendor disputes: in 2023 it sued Whinstone US for fraud and negligence after the Texas hosting facility supplied corroded, dust-clogged mining equipment lacking basic filters — evidence that trust placed in partners has misfired before.
Supply chain compromise. Alternatively, the attacker may never have needed keys at all, instead targeting surrounding infrastructure such as production servers, account logic, or security controls. BigONE suffered this kind of attack in July, when intruders altered its risk-control servers. In September, SwissBorg's staking partner Kiln had its API compromised, with attackers embedding unauthorized instructions inside otherwise-routine transactions before extracting $41.5 million. Separately, SBI's Zodia Custody joint venture in Japan was dissolved in September 2025 — the same month as the mining pool theft, a coincidence in timing worth noting even without a confirmed link.
Taken together, SBI's recent history includes the Whinstone litigation, the DMM Bitcoin customer absorption, the Zodia dissolution, and now this theft — a recurring pattern of partnerships turning costly.
The indicators ZachXBT identified — instant exchanges, Tornado Cash, coordinated multi-chain withdrawals — align with tactics generally attributed to Lazarus Group and other DPRK-linked actors, who are also known for social-engineering campaigns that target developers and employees with fake job offers designed to plant malicious code disguised as pre-employment tests. That was precisely the method behind DMM Bitcoin's May 2024 breach: a North Korean operative posing as a recruiter targeted an employee at Ginco, a firm managing DMM's wallets, and sent a link to a malicious Python script hosted on GitHub under the guise of a coding test. The script was later exploited, and $308 million was gone.
Whether this new incident used the same social-engineering approach or a different infrastructure-level exploit, SBI has not said. It has not indicated whether the case involves an insider element or a purely external breach. The lack of detail could reflect an active law-enforcement process, reluctance to disclose an embarrassing failure, or both.
Draining five separate blockchains without triggering alarms points either to extended reconnaissance of SBI Crypto's wallet architecture or prior insider-level knowledge of it.
05The Bigger Picture
SBI Crypto now joins a list of Japanese crypto firms that marketed strong security while losing significant funds to North Korea-linked actors. Roughly $24 million left the company through a process it has yet to explain, bearing hallmarks similar to the attack that had earlier destroyed DMM Bitcoin — the very exchange SBI had stepped in to rescue.
The September dissolution of the Zodia Custody joint venture, occurring in the same month as the mining pool theft, adds to a broader picture of instability rather than an isolated incident.
It remains unknown whether the attackers obtained private keys directly or compromised supporting infrastructure — SBI has disclosed neither. What is clear is that a mining operation processing institutional-scale flows across five blockchains does not typically get drained this systematically without either significant advance research by the attacker or some form of insider knowledge.
For the DMM Bitcoin customers who moved their assets to SBI's platform in March 2025 on the premise of improved security, the episode raises an uncomfortable question about how much protection that move actually provided.
Get new scam files the moment we publish them — usually 2–3 emails a week.