TLDR South Korean authorities suspect North Korea’s Lazarus Group orchestrated the Upbit hack that stole approximately $36 million in crypto assets on Thursday Upbit suspended all deposits and withdrawals after detecting unusual activity in Solana network tokens from its hot wallet The attack methods matched those used in Upbit’s 2019 breach, where Lazarus stole 342,000 [...] The post Upbit Exchange Hack: North Korea Suspected in $36 Million Crypto Theft appeared first on Blockonomi.TLDR South Korean authorities suspect North Korea’s Lazarus Group orchestrated the Upbit hack that stole approximately $36 million in crypto assets on Thursday Upbit suspended all deposits and withdrawals after detecting unusual activity in Solana network tokens from its hot wallet The attack methods matched those used in Upbit’s 2019 breach, where Lazarus stole 342,000 [...] The post Upbit Exchange Hack: North Korea Suspected in $36 Million Crypto Theft appeared first on Blockonomi.

Upbit Exchange Hack: North Korea Suspected in $36 Million Crypto Theft

2025/11/28 18:35
3 min read
For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

TLDR

  • South Korean authorities suspect North Korea’s Lazarus Group orchestrated the Upbit hack that stole approximately $36 million in crypto assets on Thursday
  • Upbit suspended all deposits and withdrawals after detecting unusual activity in Solana network tokens from its hot wallet
  • The attack methods matched those used in Upbit’s 2019 breach, where Lazarus stole 342,000 ETH worth hundreds of millions
  • Hackers likely compromised or impersonated admin accounts rather than directly attacking servers, similar to Lazarus tactics
  • The timing coincided with a merger announcement between Upbit’s parent company Dunamu and Korean tech giant Naver

South Korea’s largest crypto exchange Upbit suffered a major security breach on Thursday. The exchange suspended all deposit and withdrawal services after detecting unauthorized transactions involving Solana-based tokens.

Upbit initially reported losses of 54 billion Korean won, approximately $36.8 million. The exchange later revised this figure down to 44.5 billion won, or roughly $30.4 million. The funds were stolen from one of Upbit’s hot wallets, which store crypto assets online for quick access.

South Korean authorities are now investigating the incident. Government and industry sources told Yonhap News Agency that investigators suspect North Korea’s Lazarus Group orchestrated the theft. Officials are preparing an on-site inspection of Upbit’s facilities.

Pattern Matches Previous Attack

The attack methods used in Thursday’s hack closely resemble tactics employed in a 2019 Upbit breach. In that incident, hackers stole 342,000 ETH from the exchange. South Korean police concluded last year that Lazarus was responsible for the 2019 theft.

Security experts believe the hackers compromised administrator credentials rather than directly attacking Upbit’s servers. A government official explained that the attackers likely hijacked admin accounts or impersonated administrators to authorize the fraudulent transfers. This approach matches known Lazarus Group techniques.

Some security analysts noted that North Korea faces ongoing foreign currency shortages. These financial pressures provide motivation for state-sponsored hacking operations. Blockchain analysis shows the stolen funds were laundered using mixing techniques, a method commonly associated with Lazarus.

Suspicious Timing

The hack occurred on November 27, the same day Naver Financial confirmed its merger with Dunamu. Naver Financial announced it would integrate Dunamu as a wholly-owned subsidiary. The company stated the merger would “secure future growth momentum based on digital assets.”

The timing has fueled speculation about whether Lazarus deliberately chose this date. A security expert speaking to Yonhap suggested hackers often seek to demonstrate their capabilities. The expert said they may have selected the merger announcement date to maximize attention.

This marks Upbit’s second major hot wallet breach in six years. The exchange has not disclosed specific details about its security protocols or how the breach occurred.

Blockchain analysis provider Dethective tracked onchain movements of the stolen funds. Data shows a wallet linked to the hacker swapped Solana tokens for USDC stablecoin. The funds are being bridged to the Ethereum network.

Investigation Continues

South Korean authorities continue to gather evidence in the case. They have not formally charged any individuals or groups. The investigation includes analysis of transaction patterns and digital forensics on Upbit’s systems.

Upbit has not announced when it plans to resume normal deposit and withdrawal services. The exchange confirmed it will cover all customer losses from the breach using its own reserves.

The post Upbit Exchange Hack: North Korea Suspected in $36 Million Crypto Theft appeared first on Blockonomi.

Market Opportunity
Holo Token Logo
Holo Token Price(HOT)
$0.0004487
$0.0004487$0.0004487
+0.38%
USD
Holo Token (HOT) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Pundit: Every XRP Holder Needs to Understand What’s Happening Right Now

Pundit: Every XRP Holder Needs to Understand What’s Happening Right Now

Rising geopolitical tension often exposes the hidden cracks in global finance, and few regions demonstrate this more clearly than the Strait of Hormuz. As a critical
Share
Timestabloid2026/03/24 04:05
US Dollar and Oil fall as Trump signals Iran de-escalation

US Dollar and Oil fall as Trump signals Iran de-escalation

The post US Dollar and Oil fall as Trump signals Iran de-escalation appeared on BitcoinEthereumNews.com. Here is what you need to know for Tuesday, March 24: The
Share
BitcoinEthereumNews2026/03/24 04:06
Adoption Leads Traders to Snorter Token

Adoption Leads Traders to Snorter Token

The post Adoption Leads Traders to Snorter Token appeared on BitcoinEthereumNews.com. Largest Bank in Spain Launches Crypto Service: Adoption Leads Traders to Snorter Token Sign Up for Our Newsletter! For updates and exclusive offers enter your email. Leah is a British journalist with a BA in Journalism, Media, and Communications and nearly a decade of content writing experience. Over the last four years, her focus has primarily been on Web3 technologies, driven by her genuine enthusiasm for decentralization and the latest technological advancements. She has contributed to leading crypto and NFT publications – Cointelegraph, Coinbound, Crypto News, NFT Plazas, Bitcolumnist, Techreport, and NFT Lately – which has elevated her to a senior role in crypto journalism. Whether crafting breaking news or in-depth reviews, she strives to engage her readers with the latest insights and information. Her articles often span the hottest cryptos, exchanges, and evolving regulations. As part of her ploy to attract crypto newbies into Web3, she explains even the most complex topics in an easily understandable and engaging way. Further underscoring her dynamic journalism background, she has written for various sectors, including software testing (TEST Magazine), travel (Travel Off Path), and music (Mixmag). When she’s not deep into a crypto rabbit hole, she’s probably island-hopping (with the Galapagos and Hainan being her go-to’s). Or perhaps sketching chalk pencil drawings while listening to the Pixies, her all-time favorite band. This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy Center or Cookie Policy. I Agree Source: https://bitcoinist.com/banco-santander-and-snorter-token-crypto-services/
Share
BitcoinEthereumNews2025/09/17 23:45