The post Korean Authorities Point to Lazarus Group in Upbit’s ₩44.5B Hack appeared on BitcoinEthereumNews.com. South Korea’s regulators say North Korea’s Lazarus Group is now the prime suspect behind the ₩44.5 billion (~$32–36 million) hack on Upbit, the country’s largest crypto exchange. Investigators say the on-chain trail looks almost identical to the group’s previous operations, including Upbit’s infamous 2019 breach. The attack hit on November 27, triggering an immediate freeze on withdrawals and transfers. Upbit confirmed that funds vanished from one of its hot wallets, affecting several assets, SOL, USDC, BONK, JUP, and others. While the exchange says users will be fully compensated from its reserves, the incident marks another damaging blow to trust in local crypto infrastructure. And the fingerprints are familiar. A Pattern Authorities Know Too Well Investigators began tracing the exploited wallet minutes after the hack. What they found matched a blueprint they’ve seen repeatedly over the past five years. The stolen assets were:  Swapped instantly on Jupiter and Raydium  Split across more than 200 wallets  Bridged through Wormhole  Pushed into a laundering cycle resembling mixer-style dispersion The flow mirrors the techniques Lazarus has used in hacks across the world. Korea’s cybercrime teams pointed to “wallet-hopping patterns and mixing behavior identical to Lazarus operations,” according to local media briefings and early reporting from Crypto Times. 🚨UPDATE: Korean authorities say North Korea’s Lazarus Group is the key suspect in Upbit’s ₩44.5B (~$32M) hack. Investigators traced wallet-hops and mixing patterns identical to previous Lazarus ops, including Upbit’s 2019 breach. FSS and KISA have launched an on-site… pic.twitter.com/NhJwskSv1S — The Crypto Times (@CryptoTimes_io) November 28, 2025 Authorities say this includes the same tactics seen in the 2019 Upbit breach, at that time, $50 million in ETH disappeared using a near-identical playbook. The new attack’s precision, timing, and laundering methods only strengthened the suspicion. The $36M Breach: What Happened Upbit classified the event as an external… The post Korean Authorities Point to Lazarus Group in Upbit’s ₩44.5B Hack appeared on BitcoinEthereumNews.com. South Korea’s regulators say North Korea’s Lazarus Group is now the prime suspect behind the ₩44.5 billion (~$32–36 million) hack on Upbit, the country’s largest crypto exchange. Investigators say the on-chain trail looks almost identical to the group’s previous operations, including Upbit’s infamous 2019 breach. The attack hit on November 27, triggering an immediate freeze on withdrawals and transfers. Upbit confirmed that funds vanished from one of its hot wallets, affecting several assets, SOL, USDC, BONK, JUP, and others. While the exchange says users will be fully compensated from its reserves, the incident marks another damaging blow to trust in local crypto infrastructure. And the fingerprints are familiar. A Pattern Authorities Know Too Well Investigators began tracing the exploited wallet minutes after the hack. What they found matched a blueprint they’ve seen repeatedly over the past five years. The stolen assets were:  Swapped instantly on Jupiter and Raydium  Split across more than 200 wallets  Bridged through Wormhole  Pushed into a laundering cycle resembling mixer-style dispersion The flow mirrors the techniques Lazarus has used in hacks across the world. Korea’s cybercrime teams pointed to “wallet-hopping patterns and mixing behavior identical to Lazarus operations,” according to local media briefings and early reporting from Crypto Times. 🚨UPDATE: Korean authorities say North Korea’s Lazarus Group is the key suspect in Upbit’s ₩44.5B (~$32M) hack. Investigators traced wallet-hops and mixing patterns identical to previous Lazarus ops, including Upbit’s 2019 breach. FSS and KISA have launched an on-site… pic.twitter.com/NhJwskSv1S — The Crypto Times (@CryptoTimes_io) November 28, 2025 Authorities say this includes the same tactics seen in the 2019 Upbit breach, at that time, $50 million in ETH disappeared using a near-identical playbook. The new attack’s precision, timing, and laundering methods only strengthened the suspicion. The $36M Breach: What Happened Upbit classified the event as an external…

Korean Authorities Point to Lazarus Group in Upbit’s ₩44.5B Hack

2025/11/29 15:43

South Korea’s regulators say North Korea’s Lazarus Group is now the prime suspect behind the ₩44.5 billion (~$32–36 million) hack on Upbit, the country’s largest crypto exchange.

Investigators say the on-chain trail looks almost identical to the group’s previous operations, including Upbit’s infamous 2019 breach.

The attack hit on November 27, triggering an immediate freeze on withdrawals and transfers. Upbit confirmed that funds vanished from one of its hot wallets, affecting several assets, SOL, USDC, BONK, JUP, and others. While the exchange says users will be fully compensated from its reserves, the incident marks another damaging blow to trust in local crypto infrastructure.

And the fingerprints are familiar.

A Pattern Authorities Know Too Well

Investigators began tracing the exploited wallet minutes after the hack. What they found matched a blueprint they’ve seen repeatedly over the past five years.

The stolen assets were:

  •  Swapped instantly on Jupiter and Raydium
  •  Split across more than 200 wallets
  •  Bridged through Wormhole
  •  Pushed into a laundering cycle resembling mixer-style dispersion

The flow mirrors the techniques Lazarus has used in hacks across the world. Korea’s cybercrime teams pointed to “wallet-hopping patterns and mixing behavior identical to Lazarus operations,” according to local media briefings and early reporting from Crypto Times.

Authorities say this includes the same tactics seen in the 2019 Upbit breach, at that time, $50 million in ETH disappeared using a near-identical playbook. The new attack’s precision, timing, and laundering methods only strengthened the suspicion.

The $36M Breach: What Happened

Upbit classified the event as an external hack minutes after it occurred. Here’s what investigators say unfolded inside the hot wallet:

  •  ₩44.5B (~$36M) drained almost instantly
  •  Assets swapped across DEXes to obscure origin
  •  Funds fragmented into hundreds of small wallets
  •  Movement funneled through the Wormhole bridge
  •  Subsequent dispersion into mixer paths

Blockchain analysts say the process was coordinated, fast, and automated, classic indicators of a large, experienced team. Upbit froze all transfers immediately after detecting abnormal withdrawals.

The exchange clarified that customer funds remain safe and fully backed. “100% covered using corporate reserves,” the platform announced, attempting to contain market panic.

The Strange Date Coincidence Everyone Noticed

Crypto watchers quickly realized something eerie:

This attack happened on November 27. On the exact same date in 2019, Upbit suffered its previous major breach.

  •  Nov 27, 2019 → $50M ETH stolen
  •  Nov 27, 2024 → ~$36M hot-wallet drain

Same day. Same holiday period. Same laundering method. Same exchange. Same suspect.

Analysts on X highlighted the coincidence, questioning whether Lazarus intentionally marks significant dates as part of its operational pattern. Some security experts cited past attacks where state-backed groups have used symbolic timing to send signals or “flex” their capabilities during major news cycles.

This year’s attack landed on the same day Upbit’s parent company, Dunamu, announced a major business merger with Naver. Local investigators claim Lazarus “likes striking on important news days,” calling the overlap suspicious rather than accidental.

Why Lazarus Is the Primary Suspect

South Korea’s cyber units say three major indicators point directly to Lazarus:

1. Reused Tactics From Prior Hacks

The 2019 Upbit breach followed nearly identical steps:

  •  Admin impersonation
  •  Holiday timing
  •  Hot-wallet drain disguised as a transfer
  •  Immediate DEX and cross-chain moves
  •  Multi-layer wallet splitting

This new attack lines up almost line-for-line with that previous playbook.

2. North Korea’s Financial Pressure

With sanctions tightening, the DPRK has leaned more aggressively on crypto hacking as a financial pipeline. Intelligence agencies worldwide estimate Lazarus has generated hundreds of millions for the regime through cyberattacks on exchanges, bridges, and DeFi protocols.

Korean investigators say North Korea’s need for hard currency right now is “extreme,” making the timing of the attack unsurprising.

3. Behavioral Signatures

Forensic analysts pointed to wallet paths, bridge selections, obfuscation techniques, and the particular clustering style Lazarus is known for.

In past attacks, including those on Bybit, WazirX, and numerous token bridges, Lazarus used:

  •  rapid swaps to volatile tokens
  •  fragmentation into 100–300 small wallets
  •  cross-chain exit routes
  •  mixer-like dispersion patterns to conceal origin

Every hallmark is here.

Lazarus and the Industry’s Biggest Hacks

If confirmed, the Upbit incident adds to a long list of high-profile targets linked to Lazarus. Over the past few years, the group has been tied to major thefts across the crypto industry:

  •  WazirX breach
  •  Bybit exploit
  •  Multiple bridge hacks, including cross-chain protocols
  •  Numerous attacks on centralized exchanges worldwide

State-backed groups like Lazarus have become highly sophisticated players in crypto markets. Their operations involve multi-level automation, high-end exploit development, and laundering networks that run across dozens of chains.

Is Crypto Ready for State-Level Adversaries?

The Upbit case underscores a growing reality:

  • Nation-state hackers now treat crypto exchanges like high-speed ATMs.

Upbit emphasized that user funds are safe, but the psychological hit is still severe. Trust in centralized exchanges, already fragile since 2022, takes another blow each time a major platform is compromised.

Cyber experts warn that crypto infrastructure isn’t evolving as quickly as the attackers targeting it. Lazarus, backed by state resources and years of operational experience, continues to move faster than most private security teams.

The Bigger Picture: A Warning for Global Markets

As Korean authorities continue their investigation, the industry faces a difficult question:

If even the largest, most regulated exchange in the country can suffer repeated breaches from the same adversary, what does that say about the state of crypto security?

The Upbit hack highlights three trends reshaping the landscape:

  •  State-backed hackers dominate the high-end attack surface
  •  Cross-chain bridges are still the weakest link
  •  Centralized exchange hot wallets remain prime targets

The Lazarus Group, if confirmed, once again demonstrates a level of coordination and consistency unmatched by typical cybercriminals.

For Upbit, the response is swift. For users, the reassurance is welcome.

But the message behind the attack is louder than ever:

Crypto’s biggest threat isn’t retail panic or market volatility.

It’s state-sponsored entities playing a long-term, high-stakes game.

Disclosure: This is not trading or investment advice. Always do your research before buying any cryptocurrency or investing in any services.

Follow us on Twitter @nulltxnews to stay updated with the latest Crypto, NFT, AI, Cybersecurity, Distributed Computing, and Metaverse news!

Source: https://nulltx.com/korean-authorities-point-to-lazarus-group-in-upbits-%E2%82%A944-5b-hack/

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Adam Wainwright Takes The Mound Again Honor Darryl Kile

Adam Wainwright Takes The Mound Again Honor Darryl Kile

The post Adam Wainwright Takes The Mound Again Honor Darryl Kile appeared on BitcoinEthereumNews.com. Adam Wainwright of the St. Louis Cardinals in the dugout during the second inning against the Miami Marlins at Busch Stadium on July 18, 2023 in St. Louis, Missouri. (Photo by Brandon Sloter/Image Of Sport/Getty Images) Getty Images St. Louis Cardinals lifer Adam Wainwright is a pretty easygoing guy, and not unlikely to talk with you about baseball traditions and barbecue, or even share a joke. That personality came out last week during our Zoom call when I mentioned for the first time that I’m a Chicago Cubs fan. He responded to the mention of my fandom, “So far, I don’t think this interview is going very well.” Yet, Wainwright will return to Busch Stadium on September 19 on a more serious note, this time to honor another former Cardinal and friend, the late Darryl Kile. Wainwright will take the mound not as a starting pitcher, but to throw out the game’s ceremonial first pitch. Joining him on the mound will be Kile’s daughter, Sierra, as the two help launch a new program called Playing with Heart. “Darryl’s passing was a reminder that heart disease doesn’t discriminate, even against elite athletes in peak physical shape,” Wainwright said. “This program is about helping people recognize the risks, take action, and hopefully save lives.” Wainwright, who played for the St. Louis Cardinals as a starting pitcher from 2005 to 2023, aims to merge the essence of baseball tradition with a crucial message about heart health. Kile, a beloved pitcher for the Cardinals, tragically passed away in 2002 at the age of 33 as a result of early-onset heart disease. His sudden death shook the baseball world and left a lasting impact on teammates, fans, and especially his family. Now, more than two decades later, Sierra Kile is stepping forward with Wainwright to…
Share
BitcoinEthereumNews2025/09/18 02:08
XRP Awaits 400% Network Surge: But It Might Not Help Price

XRP Awaits 400% Network Surge: But It Might Not Help Price

The post XRP Awaits 400% Network Surge: But It Might Not Help Price appeared on BitcoinEthereumNews.com. What moves XRP forward Moving averages sloping down Over the last three months, XRP’s on-chain activity has increased dramatically, with a number of network metrics approaching levels that resemble a 400% surge in comparison to their late-summer baselines. What moves XRP forward The total volume of payments, the number of payments made between accounts and the overall transaction throughput have all significantly increased. However, the price chart presents a far less optimistic picture, and this discrepancy is the main risk moving forward. There is an improvement in network throughput. Daily payments usually fall into the upper end of the multi-month range, and spikes in payment volume show increasing value movement throughout the network. XRP/USDT Chart by TradingView However, this momentum is not reflected in the market structure. The price of XRP is still stuck in a distinct downward channel and keeps missing declining resistance. More worrisomely, all attempts to break above the 20- and 50-day moving averages are swiftly rejected. Moving averages sloping down The 50-day, 100-day and 200-day major moving averages all slope downward, indicating a persistent bearish environment. The chart was momentarily distorted by a single vertical liquidation wick in October, but price action quickly re-anchored inside the broader downtrend, confirming rather than refuting structural weakness. You Might Also Like This is where reality and the surge narrative clash. Growing network usage frequently indicates early strength for emerging ecosystems, but XRP has shown time and time again that transaction growth by itself does not translate into market demand. Because a large portion of the activity is driven by automated flows, arbitrage paths and institutional routing rather than speculative accumulation, the ledger processes high volumes even during times of poor price performance. Source: https://u.today/xrp-awaits-400-network-surge-but-it-might-not-help-price
Share
BitcoinEthereumNews2025/12/07 21:20
Eric Trump’s Wealth Surges With His Family-Backed Crypto Companies

Eric Trump’s Wealth Surges With His Family-Backed Crypto Companies

The post Eric Trump’s Wealth Surges With His Family-Backed Crypto Companies appeared on BitcoinEthereumNews.com. Eric Trump’s wealth has surged as crypto becomes the Trump family’s fastest-growing financial engine. Major stakes in American Bitcoin and World Liberty Financial have added hundreds of millions to his net worth. Eric remains committed to crypto as traditional Trump businesses expand globally. The Trump family’s business ecosystem is entering a new phase in which real estate, media, and politics increasingly intersect with crypto. Recent Forbes reporting shows that crypto has become a major source of wealth for the family, especially for Eric Trump, whose net worth has grown ten times since his father returned to the White House. Eric Trump’s Net Worth Surges on Crypto Boom Forbes estimates that Eric Trump is now worth about $400 million, a dramatic jump from his wealth before Donald Trump’s return to political power. The biggest reason is his stake in American Bitcoin, a fast-growing crypto mining company. The company holds 3,418 BTC, worth more than $320 million at current prices. With a market cap above $2 billion, Eric’s 7.3% stake is worth about $160 million. During a temporary surge in early September, his 68 million shares were worth nearly $1 billion on paper before the stock cooled. Despite the volatility, shares dropped from $14.52 to $2.39, Eric insists he is “100% committed” to the project. Related: Trump Sons-Backed ‘American Bitcoin’ to Debut on Nasdaq World Liberty Financial Adds Another Crypto Windfall Another major contributor is World Liberty Financial (WLF), a crypto firm launched by Donald Trump alongside Eric, Donald Jr., and Barron. WLF issues USD1, a stablecoin, and WLFI, a governance token. According to Forbes estimates, Eric gained about $80 million in cash after taxes from token sales. Meanwhile, he has $36 million worth of WLFI tokens and $19 million linked to the stablecoin business. In total, WLF has added roughly $135…
Share
BitcoinEthereumNews2025/12/07 21:12