📈 Get daily crypto insights that make you smarter about your money

Upbit Resets All Deposit Addresses After $37 Million Breach Exposes Digital Signature Vulnerability

South Korea’s largest cryptocurrency exchange Upbit has executed one of the most drastic security measures in recent memory, deleting all existing deposit addresses for its entire user base on December 5, 2025. The unprecedented move comes just eight days after a devastating security breach that saw approximately 44.5 billion Korean won, equivalent to roughly $30 to $37 million, siphoned from the exchange’s hot wallets. As Bitcoin trades at $89,388 and Ethereum hovers around $3,024, the incident underscores how even the most established platforms remain vulnerable to sophisticated attack vectors.

The Exploit Mechanics

On November 27, 2025, at approximately 4:42 AM Korean Standard Time, Upbit’s monitoring systems detected abnormal outflows from the exchange’s hot wallet. The attackers had already begun draining Solana-based tokens including SOL, ORCA, RAY, JUP, BONK, and RENDER. Security researchers who analyzed the breach subsequently discovered that the attack vector exploited a critical flaw in Upbit’s digital signature algorithm. The vulnerability produced weak or predictable signing data, which potentially allowed the attackers to derive private keys from publicly accessible blockchain transaction history. This is a particularly insidious method because the attack surface exists in plain sight on the blockchain itself, rather than relying on social engineering or traditional network intrusion techniques.

The stolen funds totaled approximately 44.5 billion Korean won. South Korean authorities quickly pointed to North Korea’s Lazarus Group as the primary suspect. The timing carries a chilling symmetry: the breach occurred almost exactly six years after Upbit’s previous major hack on November 27, 2019, when 342,000 Ethereum worth $41.5 million were stolen in an attack also attributed to Lazarus Group.

Affected Systems

The November 27 breach compromised Upbit’s hot wallet infrastructure, which handles the exchange’s day-to-day deposit and withdrawal operations. In response, Upbit suspended all deposits and withdrawals while conducting a comprehensive security audit of its wallet systems. The scope of the response is massive: every single deposit address for every user on the platform has been invalidated. This means that any user who had registered their Upbit deposit address in external wallets or on other exchanges must generate a new address before making any transfers.

The phased restoration began on December 5 at 5:00 PM KST, covering 33 digital assets across 21 blockchain networks. Networks included in the first restoration wave include Algorand, Filecoin, Hedera, Tezos, VeChain, Stacks, and Flow, among others. Upbit has stated that additional assets will be restored sequentially as their wallet systems pass security inspection.

The Mitigation Strategy

Upbit’s decision to invalidate all deposit addresses represents a nuclear option in exchange security. By forcing every user to generate new addresses, the exchange effectively neutralizes any residual access the attackers may have gained through the compromised signature system. The exchange has also urged users to proactively delete any old Upbit deposit addresses stored in personal wallets or registered on other platforms to prevent future misuse.

For certain networks, such as Vaulta and WAX, new deposit addresses are being issued using the same address generation system as before, suggesting the vulnerability was specific to particular wallet implementations rather than a systemic flaw across all supported chains. Digital assets received through airdrops, those with ended trading support, or those placed on watchlists will only have withdrawal functionality restored, with deposits remaining suspended pending further review.

Lessons Learned

The Upbit breach reveals several critical lessons for the cryptocurrency industry. First, digital signature implementation quality matters enormously. A seemingly minor weakness in signature generation can cascade into a catastrophic key derivation attack. Second, the attack pattern attributed to Lazarus Group shows that nation-state threat actors continue to view cryptocurrency exchanges as high-value targets. Third, the timing coincidence with the 2019 hack and the Naver acquisition announcement for Dunamu, Upbit’s parent company, suggests the attackers may have been monitoring corporate developments to time their strike for maximum impact and media confusion.

The broader market context adds urgency to these lessons. With Bitcoin at $89,388 and total crypto market capitalization exceeding $3.5 trillion, the stakes of exchange security failures have never been higher. The attack also coincided with the React2Shell vulnerability crisis, CVE-2025-55182, which was actively being exploited by multiple threat groups on the same day, creating a perfect storm of security challenges across the crypto ecosystem.

User Action Required

Upbit users must take immediate action. First, log into the platform and generate new deposit addresses for all assets. Second, delete any old Upbit deposit addresses stored in external wallets or registered on other exchanges. Third, verify that any pending transfers are directed to the new addresses. Fourth, monitor account activity for unauthorized transactions during the transition period. Fifth, enable all available two-factor authentication methods on the account. Users who notice any discrepancies should contact Upbit support immediately and document all relevant transaction hashes.

Disclaimer: This article is for informational purposes only and does not constitute financial or security advice. Always conduct your own research and consult with qualified professionals before making security decisions regarding your digital assets.

🌱 FOR BUSINESSES BitcoinsNews.com
Reach 100K+ Crypto Readers
Sponsored content, press releases, banner ads, and newsletter placements. Put your brand in front of Bitcoin's most engaged audience.

27 thoughts on “Upbit Resets All Deposit Addresses After $37 Million Breach Exposes Digital Signature Vulnerability”

  1. deleting every single deposit address is brutal but probably the right call. if the signing algorithm was compromised you cant just rotate keys and hope for the best

    1. Petr H. exactly. the weak signature data means attackers could potentially derive keys from past txs too. a full wipe is the only safe response

  2. $37M gone and SOL ecosystem tokens specifically targeted. Upbit handling a third of Korean volume with this kind of signing vulnerability is terrifying

  3. key_rot_advocate_

    deleting ALL deposit addresses is the nuclear option but probably the right call. 37M gone and the attack vector was weak signatures. you cant half-fix something like that

  4. weak signing data producing predictable signatures is a fundamental crypto implementation failure. this isnt a hot wallet issue its a core architecture flaw. Upbit got lucky it was only 37M

    1. SOL ORCA RAY JUP BONK RENDER all drained. the attacker specifically targeted Solana tokens which suggests they knew the signing weakness was chain-specific not wallet-specific

    1. Paolo Marchetti

      resetting all deposit addresses is the nuclear option. means every single user has to generate new addresses and verify them. logistical nightmare for 8M+ users

      1. resetting all deposit addresses for 8M+ users is not just a logistical nightmare. its a trust nightmare. users will question whether the exchange is safe regardless of what the team says

      2. Paolo Marchetti 8M+ users generating new addresses is a support nightmare. upbit customer service is about to get flooded with why is my deposit not showing up tickets for weeks

        1. deposit_pain_ 8M users getting new addresses is going to be a mess. expect weeks of stuck deposits, angry tickets, and probably some users sending to old addresses out of habit. the support cost alone is brutal

    1. six_year_gap_

      exact same date as the 2019 hack. nov 27 both times. lazarus operating on a schedule or is this coincidence

      1. nov 27 in 2019 and nov 27 in 2025. lazarus reusing dates is either operational security failure or they just dont care because sanctions make it impossible to prosecute anyway

      2. six_year_gap_ nov 27 twice is either lazarus reusing a playbook or same holiday staffing vulnerability. either way Upbit should have had heightened monitoring on that exact date

      3. six_year_gap_ nov 27 in 2019 and 2025 is wild. either lazarus has a fixed schedule or they exploit the same holiday staffing patterns every cycle

  5. 8 million users getting new addresses generated is a customer support apocalypse. my exchange did a smaller migration in 2023 and support tickets spiked 400 percent for a month

  6. resetting every deposit address is the right call even though its chaotic. the signature vulnerability means old addresses were potentially compromised at the key level

  7. nov 27 twice is not coincidence. lazarus group operates on south korean holidays when staffing is thin. the six year gap is just them waiting for exchanges to forget and get comfortable

    1. Yeon-hee P. nov 27 is South Korean Thanksgiving equivalent timing. staff is thin, monitoring is reduced. lazarus has used this playbook against Korean exchanges for years. its not coincidence, its calendar

    2. Yeon-hee P. the holiday staffing theory is right. Korean Thanksgiving in 2019, same window in 2025. lazarus calendars their attacks around SK red days every single time

  8. the signature vulnerability producing predictable signing data is terrifying. that means the attacker can derive keys from observed transactions. resetting addresses is the only fix but every exchange should be auditing their sig implementation this week

    1. key_derive_skep

      sig_fault_ if the signature was producing predictable nonces then every tx Upbit ever signed was leaking key material. this isnt just about the 37M, its about how long attackers had access before the drain

    2. sig_fault_ deriving private keys from observed transactions means every signature before the fix was potentially leaking key material. this is worst case scenario for any exchange

    3. sig_fault_ the scariest part is they dont know how long the sig vulnerability was exploited before detection. could be weeks of leaked signing data

  9. 8M users generating new addresses means weeks of deposit confusion. phishing scams are going to have a field day pretending to be upbit support

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$64,793.00-0.1%ETH$1,914.44+0.1%SOL$75.90+2.7%BNB$600.45+1.5%XRP$1.04+0.5%ADA$0.1987-0.6%DOGE$0.0700+0.2%DOT$0.8138-0.6%AVAX$6.48-0.9%LINK$8.29+1.4%UNI$3.98-0.4%ATOM$1.38+0.8%LTC$45.94+0.8%ARB$0.0782+0.1%NEAR$1.62+1.9%FIL$0.7135+3.4%SUI$0.6891+1.7%BTC$64,793.00-0.1%ETH$1,914.44+0.1%SOL$75.90+2.7%BNB$600.45+1.5%XRP$1.04+0.5%ADA$0.1987-0.6%DOGE$0.0700+0.2%DOT$0.8138-0.6%AVAX$6.48-0.9%LINK$8.29+1.4%UNI$3.98-0.4%ATOM$1.38+0.8%LTC$45.94+0.8%ARB$0.0782+0.1%NEAR$1.62+1.9%FIL$0.7135+3.4%SUI$0.6891+1.7%
Scroll to Top