Upbit, South Korea’s largest cryptocurrency exchange, suffered a significant security breach resulting in the theft of Solana-based tokens. The company reported an unauthorized transfer of assets valued at approximately $30 million, prompting an immediate suspension of all deposit and withdrawal transactions. In response, Upbit moved its remaining assets to a secure cold wallet to prevent further losses and began investigating the incident.
The hack was discovered just hours after Naver Corp., the country’s largest search engine, announced a $10 billion acquisition of Upbit’s parent company, Dunamu. While initial reports varied on the total value of stolen assets, the incident highlights ongoing vulnerabilities in the cryptocurrency sector and follows a series of high-profile crypto exchange breaches in recent years. Upbit’s swift response aimed to contain the damage and reassure users amid heightened scrutiny following the acquisition news.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Following the breach, Upbit stated that customer assets would be fully covered from its own funds. Reports also said the exchange had frozen some of the stolen assets while continuing its investigation.
In response to the hack, Upbit halted deposits and withdrawals and implemented emergency security measures, including transferring assets to cold wallets. The exchange also said it was investigating the incident and working to contain the impact.
Upbit discovered unauthorized transfers of Solana-based assets to an unknown external wallet, with reported losses of about ₩44.5 billion, or roughly $30 million. Multiple reports say the breach was identified hours after the acquisition announcement.
Naver Corp. announced an all-stock deal valued at about $10.27 billion to $10.3 billion to acquire Dunamu, the parent company of South Korean crypto exchange Upbit. The announcement came shortly before the later-reported security incident at Upbit.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
go.theregister.com
Open sourcetomshardware.com
Open sourcesecurityonline.info
Open sourcetechrepublic.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.