The post Upbit uncovers private key vulnerability after $30M hack appeared on BitcoinEthereumNews.com. South Korean crypto exchange Upbit says that there is “no excuse” for the “inadequate security management” that has led to a serious private key vulnerability on its platform. Oh Kyung-seok, the CEO of Upbit’s parent company, Dunamu, issued a statement today that claimed the vulnerability, which could allow would-be hackers to guess another user’s private keys, was discovered during its analysis of public Upbit wallet transactions on the blockchain. Translated from Korean using DeepL, Oh apologized for the 44.5 billion Won ($30 million) theft from the firm’s Solana hot wallet, saying, “This intrusion incident resulted from inadequate security management at Upbit, and there is no excuse for this.” Upbit says attackers might have inferred private keys by analyzing user wallet address patterns. If true, I doubt anyone other than North Korean hackers (Lazarus) could do this. pic.twitter.com/cS4I8okrVb — Ki Young Ju (@ki_young_ju) November 28, 2025 CryptoQuant CEO Ki Young Ju thinks Lazarus might be the culprit of Upbit’s hack. Read more: The solution to crypto’s Lazarus problem could be simpler than expected The CEO revealed that 38.6 billion Won ($26.2 million) consisted of “member losses” and that 2.3 billion Won was frozen. Oh also claimed that the other 5.9 billion Won ($4 million) was made up of company losses.  Oh’s statement claims that Upbit was able to address the private key estimation vulnerability and also fully reimburse user losses with Upbit’s remaining reserves. “To protect member assets, Upbit has suspended digital asset deposits and withdrawals, is tracking digital assets moved outside of Upbit, and is taking freezing measures,” it claimed.  Lazarus suspected of private key exploit South Korean news outlet Yonhap News reported that authorities suspect the hack was the result of North Korea’s Lazarus Group, and that an on-site investigation at Upbit is underway.  Upbit was previosuly targeted by… The post Upbit uncovers private key vulnerability after $30M hack appeared on BitcoinEthereumNews.com. South Korean crypto exchange Upbit says that there is “no excuse” for the “inadequate security management” that has led to a serious private key vulnerability on its platform. Oh Kyung-seok, the CEO of Upbit’s parent company, Dunamu, issued a statement today that claimed the vulnerability, which could allow would-be hackers to guess another user’s private keys, was discovered during its analysis of public Upbit wallet transactions on the blockchain. Translated from Korean using DeepL, Oh apologized for the 44.5 billion Won ($30 million) theft from the firm’s Solana hot wallet, saying, “This intrusion incident resulted from inadequate security management at Upbit, and there is no excuse for this.” Upbit says attackers might have inferred private keys by analyzing user wallet address patterns. If true, I doubt anyone other than North Korean hackers (Lazarus) could do this. pic.twitter.com/cS4I8okrVb — Ki Young Ju (@ki_young_ju) November 28, 2025 CryptoQuant CEO Ki Young Ju thinks Lazarus might be the culprit of Upbit’s hack. Read more: The solution to crypto’s Lazarus problem could be simpler than expected The CEO revealed that 38.6 billion Won ($26.2 million) consisted of “member losses” and that 2.3 billion Won was frozen. Oh also claimed that the other 5.9 billion Won ($4 million) was made up of company losses.  Oh’s statement claims that Upbit was able to address the private key estimation vulnerability and also fully reimburse user losses with Upbit’s remaining reserves. “To protect member assets, Upbit has suspended digital asset deposits and withdrawals, is tracking digital assets moved outside of Upbit, and is taking freezing measures,” it claimed.  Lazarus suspected of private key exploit South Korean news outlet Yonhap News reported that authorities suspect the hack was the result of North Korea’s Lazarus Group, and that an on-site investigation at Upbit is underway.  Upbit was previosuly targeted by…

Upbit uncovers private key vulnerability after $30M hack

For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

South Korean crypto exchange Upbit says that there is “no excuse” for the “inadequate security management” that has led to a serious private key vulnerability on its platform.

Oh Kyung-seok, the CEO of Upbit’s parent company, Dunamu, issued a statement today that claimed the vulnerability, which could allow would-be hackers to guess another user’s private keys, was discovered during its analysis of public Upbit wallet transactions on the blockchain.

Translated from Korean using DeepL, Oh apologized for the 44.5 billion Won ($30 million) theft from the firm’s Solana hot wallet, saying, “This intrusion incident resulted from inadequate security management at Upbit, and there is no excuse for this.”

CryptoQuant CEO Ki Young Ju thinks Lazarus might be the culprit of Upbit’s hack.

Read more: The solution to crypto’s Lazarus problem could be simpler than expected

The CEO revealed that 38.6 billion Won ($26.2 million) consisted of “member losses” and that 2.3 billion Won was frozen. Oh also claimed that the other 5.9 billion Won ($4 million) was made up of company losses. 

Oh’s statement claims that Upbit was able to address the private key estimation vulnerability and also fully reimburse user losses with Upbit’s remaining reserves.

“To protect member assets, Upbit has suspended digital asset deposits and withdrawals, is tracking digital assets moved outside of Upbit, and is taking freezing measures,” it claimed. 

Lazarus suspected of private key exploit

South Korean news outlet Yonhap News reported that authorities suspect the hack was the result of North Korea’s Lazarus Group, and that an on-site investigation at Upbit is underway. 

Upbit was previosuly targeted by the group six years ago when it stole $50 million worth of ether in 2019. 

The crypto exchange said today that “Upbit has consistently strived to safeguard member assets, but this incident has once again made us realize that there is no such thing as perfect security preparedness.”

Read more: OpenAI, CoinTracker user data leaked after third-party hacked via SMS

Crypto security firm CertiK has warned in a report this year about the potential for hackers to predict, or even reconstruct, the private keys of crypto wallets. 

It highlights how the private key generator Profanity could be exploited via a brute force attack, and was likely the source of a private key leak that led to the $160 million hack of the market maker Wintermute.  

Because Profanity’s address generator only has “2^32 possible initial key pairs and each iteration is reversible, attackers could recover any Profanity-generated private key from its corresponding public key,” CertiK claimed.

Got a tip? Send us an email securely via Protos Leaks. For more informed news, follow us on X, Bluesky, and Google News, or subscribe to our YouTube channel.

Source: https://protos.com/upbit-uncovers-private-key-vulnerability-after-30m-hack/

Market Opportunity
PUBLIC Logo
PUBLIC Price(PUBLIC)
$0.01545
$0.01545$0.01545
+0.52%
USD
PUBLIC (PUBLIC) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.
Tags:

You May Also Like

Franklin Templeton CEO Dismisses 50bps Rate Cut Ahead FOMC

Franklin Templeton CEO Dismisses 50bps Rate Cut Ahead FOMC

The post Franklin Templeton CEO Dismisses 50bps Rate Cut Ahead FOMC appeared on BitcoinEthereumNews.com. Franklin Templeton CEO Jenny Johnson has weighed in on whether the Federal Reserve should make a 25 basis points (bps) Fed rate cut or 50 bps cut. This comes ahead of the Fed decision today at today’s FOMC meeting, with the market pricing in a 25 bps cut. Bitcoin and the broader crypto market are currently trading flat ahead of the rate cut decision. Franklin Templeton CEO Weighs In On Potential FOMC Decision In a CNBC interview, Jenny Johnson said that she expects the Fed to make a 25 bps cut today instead of a 50 bps cut. She acknowledged the jobs data, which suggested that the labor market is weakening. However, she noted that this data is backward-looking, indicating that it doesn’t show the current state of the economy. She alluded to the wage growth, which she remarked is an indication of a robust labor market. She added that retail sales are up and that consumers are still spending, despite inflation being sticky at 3%, which makes a case for why the FOMC should opt against a 50-basis-point Fed rate cut. In line with this, the Franklin Templeton CEO said that she would go with a 25 bps rate cut if she were Jerome Powell. She remarked that the Fed still has the October and December FOMC meetings to make further cuts if the incoming data warrants it. Johnson also asserted that the data show a robust economy. However, she noted that there can’t be an argument for no Fed rate cut since Powell already signaled at Jackson Hole that they were likely to lower interest rates at this meeting due to concerns over a weakening labor market. Notably, her comment comes as experts argue for both sides on why the Fed should make a 25 bps cut or…
Share
BitcoinEthereumNews2025/09/18 00:36
From Early Trading Losses to Global Impact: Somesh’s Journey to Building an Int’l Trading Community

From Early Trading Losses to Global Impact: Somesh’s Journey to Building an Int’l Trading Community

When Somesh started trading at 19, he lost nearly everything in three weeks. Today, he’s one of the most-followed day traders in the world with over one million
Share
Techbullion2026/03/24 13:12
USD/JPY Forecast: Critical Surge to 158.80 as Bulls Face Decisive 200-EMA Test

USD/JPY Forecast: Critical Surge to 158.80 as Bulls Face Decisive 200-EMA Test

BitcoinWorld USD/JPY Forecast: Critical Surge to 158.80 as Bulls Face Decisive 200-EMA Test TOKYO, May 2025 – The USD/JPY currency pair has surged decisively into
Share
bitcoinworld2026/03/24 13:05