North Korea’s notorious Lazarus Group is suspected of stealing about $30.6 million from Upbit, the largest crypto exchange in South Korea.  That’s according to a [...]North Korea’s notorious Lazarus Group is suspected of stealing about $30.6 million from Upbit, the largest crypto exchange in South Korea.  That’s according to a [...]

North Korea’s Lazarus Group Suspected In $30M Upbit Hack

North Korea’s notorious Lazarus Group is suspected of stealing about $30.6 million from Upbit, the largest crypto exchange in South Korea. 

That’s according to a Nov. 28 report by Yonhap News Agency that cited anonymous government and industry sources as saying they are increasingly confident the recent incident was orchestrated by the Lazarus Group, which has been linked to some of the biggest hacks in crypto’s history. 

Upbit said it would reimburse customers whose assets were stolen in the incident using its own reserves. Trading activities on the platform are still active but investors are unable to add or remove assets from the platform until the investigation is completed. 

The sources said the authorities are getting ready to perform an on-site inspection of Upbit.

News of the hack came shortly after Naver announced a $10.3 billion acquisition of Upbit’s parent, Dunamu, via an all-stock deal. 

Upbit Says The Amount Stolen Was Less Than Originally Reported

Upbit said on Nov. 27 that it had detected suspicious withdrawals linked to one of its hot wallets and that it quickly reacted by suspending withdrawals and deposits. 

It said it transferred its remaining assets to a cold wallet, which is a wallet that is not connected to the internet. Upbit said it had also initiated on-chain freezing for the stolen assets. 

Tokens that were transferred in the incident (Source: Upbit)

A large portion of the assets were SOL ecosystem tokens, and included Jupiter (JUP), Cat in a Dogs World (MEW), and Wormhole (W). 

Initially, Upbit said that 54 billion won ($36.8 million) was stolen, but later revised the figure to around 44.5 billion won ($30.4 million). 

Attack Methods Used In Upbit Incident Similar To 2019 Theft

The attack methods used in the latest incident were similar to those used in a November 2019 theft of 342k ETH from Upbit, which raised further suspicions that the Lazarus Group was behind it. South Korean police concluded that Lazarus was behind that heist. 

In the latest incident, the hackers didn’t specifically target the exchange’s servers. Instead, authorities believe they likely compromised accounts with administrator privileges or impersonated administrators to authorize the transfers.

Following the incident, hackers appear to have already swapped stolen Solana for USD Coin (USDC) and are in the process of bringing the funds to the Ethereum blockchain, according to blockchain analysts from Dethective. 

The on-chain sleuth said on X that the hackers hold approximately $1.6 million in ETH. 

Lazarus Has Hacked Other Platforms This Year

The Lazarus Group is suspected of orchestrating multiple other attacks this year, including in February a $1.5 billion theft of about 400k ETH tokens from crypto exchange Bybit. 

According to on-chain investigators, the attackers had manipulated a “routine wallet transfer,” and tricked cold-wallet signers into approving what looked like legitimate transactions. Meanwhile, the underlying smart contract logic was altered to divert funds. 

The Bybit attack is widely regarded as the largest crypto exchange theft in the history of digital assets. 

The Lazarus Group is also suspected to have been behind the $11.5 million theft from the Taiwanese exchange BitoPro in May. Third party firms said that the heist matched the modus operandi of the hacker group. 

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Trading time: Tonight, the US GDP and the upcoming non-farm data will become the market focus. Institutions are bullish on BTC to $120,000 in the second quarter.

Trading time: Tonight, the US GDP and the upcoming non-farm data will become the market focus. Institutions are bullish on BTC to $120,000 in the second quarter.

Daily market key data review and trend analysis, produced by PANews.
Share
PANews2025/04/30 13:50
Volume Jumps 1,600% in 24 Hours

Volume Jumps 1,600% in 24 Hours

The post Volume Jumps 1,600% in 24 Hours appeared on BitcoinEthereumNews.com. Axie Infinity (AXS) is trading at $1.29 at the time of writing, up more than 33% in
Share
BitcoinEthereumNews2026/01/15 01:21
Polygon Tops RWA Rankings With $1.1B in Tokenized Assets

Polygon Tops RWA Rankings With $1.1B in Tokenized Assets

The post Polygon Tops RWA Rankings With $1.1B in Tokenized Assets appeared on BitcoinEthereumNews.com. Key Notes A new report from Dune and RWA.xyz highlights Polygon’s role in the growing RWA sector. Polygon PoS currently holds $1.13 billion in RWA Total Value Locked (TVL) across 269 assets. The network holds a 62% market share of tokenized global bonds, driven by European money market funds. The Polygon POL $0.25 24h volatility: 1.4% Market cap: $2.64 B Vol. 24h: $106.17 M network is securing a significant position in the rapidly growing tokenization space, now holding over $1.13 billion in total value locked (TVL) from Real World Assets (RWAs). This development comes as the network continues to evolve, recently deploying its major “Rio” upgrade on the Amoy testnet to enhance future scaling capabilities. This information comes from a new joint report on the state of the RWA market published on Sept. 17 by blockchain analytics firm Dune and data platform RWA.xyz. The focus on RWAs is intensifying across the industry, coinciding with events like the ongoing Real-World Asset Summit in New York. Sandeep Nailwal, CEO of the Polygon Foundation, highlighted the findings via a post on X, noting that the TVL is spread across 269 assets and 2,900 holders on the Polygon PoS chain. The Dune and https://t.co/W6WSFlHoQF report on RWA is out and it shows that RWA is happening on Polygon. Here are a few highlights: – Leading in Global Bonds: Polygon holds 62% share of tokenized global bonds (driven by Spiko’s euro MMF and Cashlink euro issues) – Spiko U.S.… — Sandeep | CEO, Polygon Foundation (※,※) (@sandeepnailwal) September 17, 2025 Key Trends From the 2025 RWA Report The joint publication, titled “RWA REPORT 2025,” offers a comprehensive look into the tokenized asset landscape, which it states has grown 224% since the start of 2024. The report identifies several key trends driving this expansion. According to…
Share
BitcoinEthereumNews2025/09/18 00:40