📈 Get daily crypto insights that make you smarter about your money

Upbit Exchange Breached for $30.4 Million as South Korea Probes Lazarus Group Link

South Korea’s largest cryptocurrency exchange, Upbit, has fallen victim to a sophisticated cyberattack that resulted in the theft of approximately $30.4 million in digital assets. The breach, detected on November 28, 2025, has sent shockwaves through the Asian crypto market and prompted an immediate investigation by South Korean authorities who suspect the involvement of North Korea’s notorious Lazarus Group.

The Exploit Mechanics

The attack began with the detection of abnormal withdrawal patterns involving several Solana-based tokens on the Upbit platform. According to early findings shared with Yonhap News Agency by government and industry sources, the attackers gained access to administrative accounts on the exchange. Investigators believe they either impersonated staff members or compromised credentials to authorize unauthorized transfers. This approach indicates targeted account manipulation rather than a direct assault on Upbit’s server infrastructure, a hallmark of Lazarus Group operations.

Upbit initially estimated losses at approximately $38 million but revised the figure downward to $30.4 million (44.5 billion won) after completing a comprehensive asset review. The exchange acted swiftly, pausing all deposits and withdrawals within minutes of detecting the anomalous activity.

Affected Systems

The breach primarily affected Solana-based token holdings on the exchange. Blockchain analysis provider Dethective reported that a wallet linked to the suspected hacker immediately began moving funds after the theft. The attacker converted stolen Solana tokens into USDC and began transferring assets to the Ethereum network through cross-chain bridges, following a laundering pattern commonly observed after major cryptocurrency thefts.

The timing of the breach adds another layer of complexity. Just one day before the hack, Naver Financial confirmed it would acquire Upbit’s parent company, Dunamu, as a wholly owned subsidiary. This corporate transition means Upbit now faces both a critical security incident and a structural reorganization simultaneously, raising questions about whether the transition period may have created exploitable gaps in security protocols.

The Mitigation Strategy

South Korean regulators have arranged an on-site inspection of Upbit to identify vulnerabilities and understand exactly how the attackers gained internal access. The review will examine the exchange’s administrative access controls, multi-factor authentication requirements, and withdrawal approval processes.

For users, the incident underscores the persistent risks associated with keeping large amounts of cryptocurrency on centralized exchanges. While Upbit’s rapid response in freezing deposits and withdrawals likely prevented greater losses, the $30.4 million theft represents a significant failure in access control and administrative account protection.

Lessons Learned

This breach bears striking similarities to Upbit’s 2019 hack, in which 342,000 ETH were stolen. South Korean police concluded last year that Lazarus was responsible for that earlier theft. The recurrence of a similar attack on the same exchange raises serious concerns about whether sufficient security improvements were implemented after the first incident.

Key takeaways from this incident include the critical importance of securing administrative accounts with hardware-based multi-factor authentication, implementing time-locked withdrawal limits for large transfers, maintaining continuous monitoring for anomalous transaction patterns, and ensuring that corporate transitions do not weaken security postures.

User Action Required

Upbit users should monitor their accounts for any unauthorized activity, enable all available security features including two-factor authentication, and consider transferring significant holdings to personal hardware wallets rather than keeping them on the exchange. Users who may have been affected by the breach should contact Upbit’s customer support and document any suspicious transactions. As the investigation unfolds, additional guidance from both Upbit and South Korean regulators is expected in the coming days.

Disclaimer: This article is for informational purposes only and does not constitute financial advice. Readers are encouraged to conduct their own research before making any investment decisions.

🌱 FOR BUSINESSES BitcoinsNews.com
Reach 100K+ Crypto Readers
Sponsored content, press releases, banner ads, and newsletter placements. Put your brand in front of Bitcoin's most engaged audience.

25 thoughts on “Upbit Exchange Breached for $30.4 Million as South Korea Probes Lazarus Group Link”

    1. solsurvivor immediate conversion to USDC then bridge to ETH. lazarus playbook is so predictable now but exchanges still cant stop it

      1. Mika Okafor convert to USDC bridge to ETH scatter. same playbook as Ronin and Harmony. exchanges need real-time bridge monitoring

        1. usdc_flight_ real time bridge monitoring is the only defense at this point. every exchange knows the Lazarus playbook by now and still nobody stops it

      2. lazarus_track

        solsurvivor lazarus playbook is so predictable now but exchanges still cant stop it. convert to USDC, bridge to ETH, scatter across wallets. same pattern every time

    1. naver_watch_

      chen Y naver acquiring dunamu one day before the hack is wild. either terrible timing or the attackers had inside info on the transition period

      1. Chen Xiaoming

        naver acquiring dunamu one day before is either terrible luck or the attackers knew about internal security gaps during the transition

    1. exchange_ops_

      30M in a hot wallet. admins got compromised not the infrastructure. lazarus targets people not code and exchanges keep underestimating social engineering

      1. exchange_ops_ admins not infrastructure. same story every time. when will exchanges learn that social engineering beats firewalls

    1. hotwallet_roulette 30M in a hot wallet is the real issue. no exchange should have that kind of exposure without time-locked withdrawals

  1. north_korea_watch_

    lazarus got admin credentials on the largest korean exchange and only walked away with 30M. could have been way worse if they targeted hot wallets directly

    1. impersonating staff to get admin creds is the oldest trick. phishing works because exchanges still rely on human approvals for withdrawals

  2. upbit handling solana tokens with admin access and no multisig is wild. korean exchanges process billions in volume and their security is held together with tape

  3. impersonating staff to get admin access is literally social engineering 101. upbit has how big of a security budget and they fell for that

    1. Sonja D. social engineering beating firewalls. helpdesk hands over admin credentials and 30M disappears. same story since Mt Gox

  4. naver buying dunamu the day before is too convenient. lazarus scouts M&A activity for security gaps during transitions

    1. Jiwoo P. the M&A timing angle doesnt get enough attention. every major exchange hack happens during infrastructure transitions when access controls are messy

  5. revised from 38M down to 30.4M. so they lost track of 8 million dollars during the audit? inspiring confidence all around

    1. Minchul P. losing track of 8 million during the audit is insane. imagine being the CFO explaining that discrepancy to the board

  6. dunamus_watch_

    naver acquiring dunamu one day before the hack is still the craziest coincidence. lazarus scouts M&A transitions for security gaps during handover periods

  7. timelock_advocate

    hotwallet_roulette 30M in a hot wallet without time-locked withdrawals in 2025 is inexcusable. every CEX should have 24h withdrawal delays above 1M

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$64,742.00-0.3%ETH$1,912.69-0.2%SOL$75.96+1.9%BNB$601.15+1.4%XRP$1.04+0.3%ADA$0.1979-1.3%DOGE$0.0700-0.2%DOT$0.8120-1.0%AVAX$6.46-1.1%LINK$8.29+0.4%UNI$3.97-1.1%ATOM$1.38+0.7%LTC$45.97+1.0%ARB$0.0781-0.9%NEAR$1.62+1.1%FIL$0.7116+2.5%SUI$0.6915+1.6%BTC$64,742.00-0.3%ETH$1,912.69-0.2%SOL$75.96+1.9%BNB$601.15+1.4%XRP$1.04+0.3%ADA$0.1979-1.3%DOGE$0.0700-0.2%DOT$0.8120-1.0%AVAX$6.46-1.1%LINK$8.29+0.4%UNI$3.97-1.1%ATOM$1.38+0.7%LTC$45.97+1.0%ARB$0.0781-0.9%NEAR$1.62+1.1%FIL$0.7116+2.5%SUI$0.6915+1.6%
Scroll to Top