South Korean authorities suspect that the November Upbit hack may have been masterminded by the notorious Lazarus Group. Unnamed industry sources told local media that the North Korean state-backed hackers may have been behind the breach, as the recent attack…South Korean authorities suspect that the November Upbit hack may have been masterminded by the notorious Lazarus Group. Unnamed industry sources told local media that the North Korean state-backed hackers may have been behind the breach, as the recent attack…

South Korea links $30M Upbit hack to North Korea’s Lazarus Group

2025/11/28 14:16
4 min di lettura
Per feedback o dubbi su questo contenuto, contattateci all'indirizzo crypto.news@mexc.com.

South Korean authorities suspect that the November Upbit hack may have been masterminded by the notorious Lazarus Group.

Summary
  • South Korean authorities suspect Lazarus Group orchestrated the Upbit breach that drained more than $30M in crypto.
  • At least 24 Solana‑based assets were taken from a compromised hot wallet.
  • On‑chain data shows the stolen funds were converted to USDC and moved to Ethereum.

Unnamed industry sources told local media that the North Korean state-backed hackers may have been behind the breach, as the recent attack bears a strong resemblance to a similar incident that hit the exchange back in 2019.

Over $30M stolen

Bad actors stole over 44.5 billion won worth of cryptocurrencies from Upbit on Thursday. Initial estimates reported an even higher loss at around 54 billion won.

According to the exchange, at least 24 different Solana-based tokens were siphoned off from a hot wallet, prompting the company to suspend all deposits and withdrawals until further notice. Upbit has vowed to reimburse all affected users from its own reserves, while an official post-mortem explaining exactly how the breach occurred is yet to be released.

However, based on initial findings, authorities believe the attack shares striking similarities with the 2019 breach when the Lazarus Group managed to siphon off around 342,000 ETH from Upbit, then worth close to $50 million.

“Instead of attacking the server, it is possible that hackers compromised administrators’ accounts or posed as administrators to make the transfer,” one of the sources speculated.

Based on previous investigations, the Lazarus Group is known to employ complex and highly targeted social engineering tactics to breach security systems, often starting with phishing or developer-targeted exploits.

Over the years, the group has stolen billions of dollars’ worth of digital assets, with many experts and intelligence agencies concluding that these funds help finance North Korea’s weapons program.

Although major jurisdictions have attempted to contain the threat by imposing sanctions and cracking down on known affiliates, Lazarus continues to operate globally and remains a persistent threat to the crypto sector.

On-chain analysis conducted by blockchain intelligence firm Dethective shows that the stolen funds were swapped for USDC and bridged to Ethereum, a laundering path that has frequently been used in past Lazarus operations.

“It is the tactic of Lazarus to transfer crypto to wallets at other exchanges and attempt money laundering,” a security official said, stressing that such obfuscation makes the stolen assets significantly harder to trace.

To further mask their movements, bad actors, including the Lazarus Group, often rely on privacy-enhancing tools such as crypto mixers, which have come under increasing scrutiny by regulators over the past year due to their frequent association with these incidents.

However, one security official cited in the report speculated that the timing of the attack may have been intentional, describing it as a possible act of “self-display” to coincide with Naver Corp.’s announcement.

Upbit’s parent company, Dunamu, and Naver’s merger, which was officially announced just a day before the breach, is expected to close soon. The acquisition paves the way for a potential public listing in the United States, signaling Upbit’s broader expansion plans.

Lazrus Group is behind one of the largest crypto hacks

A number of high-profile security incidents this year, including multiple attacks on crypto exchanges, are believed to have been orchestrated by the state-sponsored hacking group.

One of the biggest attacks masterminded by the group transpired in February this year, with the group managing to get away with roughly $1.5 billion siphoned off the crypto exchange ByBit. Investigations conducted by the FBI attributed the hack to Lazarus Group’s “TraderTraitor” subunit, which has been previously linked to other sophisticated state-sponsored exploits.

Disclaimer: gli articoli ripubblicati su questo sito provengono da piattaforme pubbliche e sono forniti esclusivamente a scopo informativo. Non riflettono necessariamente le opinioni di MEXC. Tutti i diritti rimangono agli autori originali. Se ritieni che un contenuto violi i diritti di terze parti, contatta crypto.news@mexc.com per la rimozione. MEXC non fornisce alcuna garanzia in merito all'accuratezza, completezza o tempestività del contenuto e non è responsabile per eventuali azioni intraprese sulla base delle informazioni fornite. Il contenuto non costituisce consulenza finanziaria, legale o professionale di altro tipo, né deve essere considerato una raccomandazione o un'approvazione da parte di MEXC.

Potrebbe anche piacerti

Pundit: Every XRP Holder Needs to Understand What’s Happening Right Now

Pundit: Every XRP Holder Needs to Understand What’s Happening Right Now

Rising geopolitical tension often exposes the hidden cracks in global finance, and few regions demonstrate this more clearly than the Strait of Hormuz. As a critical
Condividi
Timestabloid2026/03/24 04:05
US Dollar and Oil fall as Trump signals Iran de-escalation

US Dollar and Oil fall as Trump signals Iran de-escalation

The post US Dollar and Oil fall as Trump signals Iran de-escalation appeared on BitcoinEthereumNews.com. Here is what you need to know for Tuesday, March 24: The
Condividi
BitcoinEthereumNews2026/03/24 04:06
Adoption Leads Traders to Snorter Token

Adoption Leads Traders to Snorter Token

The post Adoption Leads Traders to Snorter Token appeared on BitcoinEthereumNews.com. Largest Bank in Spain Launches Crypto Service: Adoption Leads Traders to Snorter Token Sign Up for Our Newsletter! For updates and exclusive offers enter your email. Leah is a British journalist with a BA in Journalism, Media, and Communications and nearly a decade of content writing experience. Over the last four years, her focus has primarily been on Web3 technologies, driven by her genuine enthusiasm for decentralization and the latest technological advancements. She has contributed to leading crypto and NFT publications – Cointelegraph, Coinbound, Crypto News, NFT Plazas, Bitcolumnist, Techreport, and NFT Lately – which has elevated her to a senior role in crypto journalism. Whether crafting breaking news or in-depth reviews, she strives to engage her readers with the latest insights and information. Her articles often span the hottest cryptos, exchanges, and evolving regulations. As part of her ploy to attract crypto newbies into Web3, she explains even the most complex topics in an easily understandable and engaging way. Further underscoring her dynamic journalism background, she has written for various sectors, including software testing (TEST Magazine), travel (Travel Off Path), and music (Mixmag). When she’s not deep into a crypto rabbit hole, she’s probably island-hopping (with the Galapagos and Hainan being her go-to’s). Or perhaps sketching chalk pencil drawings while listening to the Pixies, her all-time favorite band. This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy Center or Cookie Policy. I Agree Source: https://bitcoinist.com/banco-santander-and-snorter-token-crypto-services/
Condividi
BitcoinEthereumNews2025/09/17 23:45