Home Active SKN | South Korea Eyes Lazarus Group in $36M Upbit Hack Investigation
Active

SKN | South Korea Eyes Lazarus Group in $36M Upbit Hack Investigation

Share
Share

South Korean authorities are investigating whether the notorious North Korea-linked Lazarus Group was behind the latest major breach at Upbit, the country’s largest cryptocurrency exchange. The probe follows a high-impact incident in which roughly 54 billion Korean won ($36–$37 million) in Solana-based assets were siphoned from one of the platform’s hot wallets.

Upbit Confirms Hot Wallet Breach After Suspicious Solana Activity

Upbit suspended both deposits and withdrawals on Thursday after detecting abnormal movements across its Solana token holdings. The exchange later confirmed that an unauthorized withdrawal from its hot wallet had taken place, marking Upbit’s second major hot-wallet-related breach since 2019.

Authorities now believe the attackers may have exploited or impersonated Upbit’s internal administrative credentials — a tactic that closely resembles the methods used in past Lazarus-related operations.

Cybersecurity analysts also pointed out that the way the stolen funds were laundered aligns with known Lazarus mixing patterns. With North Korea’s foreign currency shortages intensifying, experts say the country has strong incentives to scale its cyber-theft operations.

Lazarus Pattern Mirrors 2019 Upbit Breach

Investigators noted multiple similarities between this attack and the 2019 Upbit hack, which resulted in the loss of $49 million and was later linked to Lazarus. Both incidents involved hot-wallet vulnerabilities and sophisticated credential-level manipulation rather than typical phishing or infrastructure attacks.

Security commentators emphasized that the group frequently leverages advanced operational security, fast fund-movement protocols, and onchain obfuscation tools — all present in the Upbit 2025 breach.

Suspicious Timing Raises Further Questions

The breach took place on Nov. 27, the same day that Upbit’s parent company, Dunamu, announced a major merger initiative with Korean tech conglomerate Naver. The coincidence has fueled speculation about whether the hackers intentionally selected the date for symbolic impact.

A cybersecurity expert quoted by Yonhap suggested that the timing may have been deliberate, stating that attackers “often have a strong desire to show off” and may have chosen the merger announcement day to amplify disruption or signal capability.

Ongoing Investigation

Upbit has since secured affected wallets and is working with law enforcement and blockchain analytics firms to trace the stolen assets. South Korean regulators and intelligence agencies are now assessing whether Lazarus’ known digital fingerprints match the activity observed during the breach.

Authorities have not yet issued a final attribution, but early indications point strongly toward the North Korea-linked hacking collective, which remains one of the most prolific state-sponsored cyber-crime groups targeting global crypto infrastructure.

Comparison, examination, and analysis between investment houses

Leave your details, and an expert from our team will get back to you as soon as possible

    Share

    Leave a comment

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    Don't Miss

    SKN | Bitcoin RSI Signals Momentum Shift, Pointing to Potential $105,000 Rebound

    Bitcoin’s technical setup is flashing early signs of renewed upside momentum, with multiple relative strength index (RSI) signals aligning across higher and lower...

    SKN | Ripple Secures UK FCA Approval, Strengthening Its Regulatory Foothold in Europe

    Ripple has received regulatory approval from the UK Financial Conduct Authority (FCA), marking a significant milestone for the blockchain payments firm as it...

    Related Articles

    SKN | Crypto Daily: KuCoin Gets MiCA Nod, Bitcoin Slumps, Balancer Plans Reimbursements

    Crypto markets continued to shift under regulatory, technical and security pressures today,...

    SKN | DOGE Underperforms Majors as Support Failure Confirms Bearish Shift

    Dogecoin slipped below the critical $0.152 support level in a heavy-volume breakdown...

    SKN | Bitcoin Slips Below $93K as Crypto Weakness Deepens — Analysts Warn a Local Bottom May Be Near

    Bitcoin recently dropped under $93,000, intensifying a broader crypto market downturn amid...

    SKN | Bitcoin Slides Below $95K Amid Worst Week Since March; Analyst Sees Potential Drop to $84K

    Bitcoin (BTC) slipped below $95,000 this week, marking its worst weekly performance since...

    Investcoin

    GET A FREE, EXPERT-BACKED
    INVESTMENT COMPARISON TODAY