Upbit said it discovered a vulnerability that could have allowed attackers to infer private keys from onchain wallet data.Upbit said it discovered a vulnerability that could have allowed attackers to infer private keys from onchain wallet data.

Upbit says emergency audit of $30M hack uncovered internal wallet flaw that could let attackers derive private keys

2025/11/28 19:29
3 min di lettura
Per feedback o dubbi su questo contenuto, contattateci all'indirizzo crypto.news@mexc.com.

Upbit said it uncovered and patched a serious vulnerability in its internal wallet system while conducting an emergency investigation into the $30 million theft that hit the South Korean exchange earlier this week — but it remains unclear if the flaw was connected to the hack.

According to a translation of a company statement on Friday, CEO Oh Kyung-seok said the exchange identified "a security vulnerability in our system that could have allowed someone analyzing publicly visible Upbit wallet transactions on the blockchain to infer private keys," referring to the cryptographic credentials that control access to funds.

While normal blockchain data does not reveal private keys, it appears Upbit's own wallet software had a flaw that produced weak or predictable signature data, meaning an attacker analyzing the crypto exchange's past onchain transactions could mathematically reconstruct certain wallet private keys due to a serious implementation bug on Upbit's end.

The exchange did not link the vulnerability to the breach directly and said the issue was discovered only after Upbit began a systemwide review following irregular withdrawals from its Solana-related wallets on Nov. 27.

"We identified and addressed the vulnerability during a comprehensive inspection of all related networks and wallet systems," Oh said, adding that the company had activated an emergency response system and suspended all deposits and withdrawals until its infrastructure is fully verified as secure.

According to the notice, Upbit confirmed the hack resulted in losses totaling approximately 44.5 billion KRW or roughly $30 million, including 38.6 billion KRW worth an estimated $26 million in customer assets. About 2.3 billion KRW ($1.5 million) of stolen funds have already been frozen, the firm added.

Upbit is now conducting a broader security review across its infrastructure, noting the incident serves as a reminder that "no security system can ever be considered perfect," pledging deeper upgrades to prevent future breaches.

The crypto exchange said it will provide ongoing public updates and will resume deposits and withdrawals once its wallet systems complete final security checks. The platform has committed to covering all customer losses using its own reserves.

Authorities investigating Lazarus Group involvement

On Nov. 26, the crypto exchange halted withdrawals immediately after detecting abnormal Solana-based outflows, including tokens such as SOL, ORCA, RAY, and JUP, among others.

It subsequently moved remaining assets to cold storage and began a full wallet overhaul.

Upbit is South Korea's largest exchange by trading volume, operating under parent company Dunamu, which is currently preparing for a merger with internet conglomerate Naver ahead of a potential public market listing.

South Korean authorities have also opened an investigation into the incident.

As The Block reported Thursday, local media outlets have cited early intelligence assessments suggesting North Korea's Lazarus Group may be a suspect. However, Upbit and regulators have not publicly confirmed attribution.

Upbit said it continues to coordinate with law enforcement and blockchain projects to freeze and recover stolen assets where possible.


Disclaimer: The Block is an independent media outlet that delivers news, research, and data. As of November 2023, Foresight Ventures is a majority investor of The Block. Foresight Ventures invests in other companies in the crypto space. Crypto exchange Bitget is an anchor LP for Foresight Ventures. The Block continues to operate independently to deliver objective, impactful, and timely information about the crypto industry. Here are our current financial disclosures.

© 2025 The Block. All Rights Reserved. This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.

Opportunità di mercato
Logo Ambire Wallet
Valore Ambire Wallet (WALLET)
$0.0101
$0.0101$0.0101
+1.10%
USD
Grafico dei prezzi in tempo reale di Ambire Wallet (WALLET)
Disclaimer: gli articoli ripubblicati su questo sito provengono da piattaforme pubbliche e sono forniti esclusivamente a scopo informativo. Non riflettono necessariamente le opinioni di MEXC. Tutti i diritti rimangono agli autori originali. Se ritieni che un contenuto violi i diritti di terze parti, contatta crypto.news@mexc.com per la rimozione. MEXC non fornisce alcuna garanzia in merito all'accuratezza, completezza o tempestività del contenuto e non è responsabile per eventuali azioni intraprese sulla base delle informazioni fornite. Il contenuto non costituisce consulenza finanziaria, legale o professionale di altro tipo, né deve essere considerato una raccomandazione o un'approvazione da parte di MEXC.

Potrebbe anche piacerti

Coinbase Slams ‘Patchwork’ State Crypto Laws, Calls for Federal Preemption

Coinbase Slams ‘Patchwork’ State Crypto Laws, Calls for Federal Preemption

The post Coinbase Slams ‘Patchwork’ State Crypto Laws, Calls for Federal Preemption appeared on BitcoinEthereumNews.com. In brief Coinbase has filed a letter with the DOJ urging federal preemption of state crypto laws, citing Oregon’s securities suit, New York’s ETH stance, and staking bans. Chief Legal Officer Paul Grewal called state actions “government run amok,” warning that patchwork enforcement “slows innovation and harms consumers.” A legal expert told Decrypt that states risk violating interstate commerce rules and due process, and DOJ support for preemption may mark a potential turning point. Coinbase has gone on the offensive against state regulators, petitioning the Department of Justice that a patchwork of lawsuits and licensing schemes is tearing America’s crypto market apart. “When Oregon can sue us for services that are legal under federal law, something’s broken,” Chief Legal Officer Paul Grewal tweeted on Tuesday. “This isn’t federalism—this is government run amok.” When Oregon can sue us for services that are legal under federal law, something’s broken. This isn’t federalism–this is government run amok. We just sent a letter to @TheJusticeDept urging federal action on crypto market structure to remedy this. 1/3 — paulgrewal.eth (@iampaulgrewal) September 16, 2025 Coinbase’s filing says that states are “expansively interpreting their securities laws in ways that undermine federal law” and violate the dormant Commerce Clause by projecting regulatory preferences beyond state borders. “The current patchwork of state laws isn’t just inefficient – it slows innovation and harms consumers” and demands “federal action on crypto market structure,” Grewal said.  States vs. Coinbase It pointed to Oregon’s securities lawsuit against the exchange, New York’s bid to classify Ethereum as a security, and cease-and-desist orders on staking as proof that rogue states are trying to resurrect the SEC’s discredited “regulation by enforcement” playbook. Oregon Attorney General Dan Rayfield sued Coinbase in April for promoting unregistered securities, and in July asked a federal judge to return the…
Condividi
BitcoinEthereumNews2025/09/18 11:52
Time Management For Entrepreneurs

Time Management For Entrepreneurs

When you’re managing everything on your own, time is your biggest asset. Yet while most entrepreneurs focus on leadership, growth and networking, they often overlook
Condividi
Techbullion2026/03/24 20:21
Vitalik Buterin lays out new Ethereum roadmap at EDCON

Vitalik Buterin lays out new Ethereum roadmap at EDCON

The post Vitalik Buterin lays out new Ethereum roadmap at EDCON appeared on BitcoinEthereumNews.com. At EDCON 2025 in Osaka, Ethereum co-founder Vitalik Buterin delivered fresh details of Ethereum’s technical roadmap, delineating both short-term scaling goals and longer-term protocol transformations. The immediate priority, according to slides from the presentation, is scaling at the L1 level by raising the gas limit while maintaining decentralization. Tools such as block-level access lists, ZK-EVMs, gas repricing, and slot optimization were highlighted as means to improve throughput and efficiency. A central theme of the presentation was privacy, divided into protections for on-chain “writes” (transactions, voting, DeFi operations) and “reads” (retrieving blockchain state). Write privacy could be achieved through client-side zero-knowledge proofs, encrypted voting, and mixnet-based transaction relays. Read privacy efforts include trusted execution environments, private information retrieval techniques, dummy queries to obscure access patterns, and partial state nodes that reveal only necessary data. These measures aim to reduce information leakage across both ends of user interaction. In the medium term, Ethereum’s focus shifts to cross-Layer-2 interoperability. Vitalik described trustless L2 asset transfers, proof aggregation, and faster settlement mechanisms as key milestones toward a seamless rollup ecosystem. Faster slots and stronger finality, supported by techniques like erasure coding and three-stage finalization (3SF), are also in scope to enhance responsiveness and security. The roadmap also includes Stage 2 rollup advancements to strengthen verification efficiency, alongside a call for broader community participation to help build and maintain these improvements. The long-term “Lean Ethereum” blueprint emphasizes security, simplicity and optimization, with ambitions for quantum-resistant cryptography, formal verification of the protocol, and adoption of ideal primitives for hashing, signatures, and zero-knowledge proofs. Buterin stressed that these improvements are not just for scalability but to make Ethereum a stable, trustworthy foundation for the broader decentralized ecosystem. This is a developing story. This article was generated with the assistance of AI and reviewed by editor Jeffrey Albus before publication.…
Condividi
BitcoinEthereumNews2025/09/18 03:22