South Korean cryptocurrency exchange Upbit suffered a major security breach resulting in the theft of approximately $30 million in digital assets from its Solana wallet. The attack exploited a vulnerability that allowed private key inferencing, enabling the attackers to transfer various tokens, including official Trump, USD Coin, and Bonk, out of Upbit's wallets. Following the incident, Upbit halted all digital asset transactions, initiated a comprehensive security review, and began restructuring its wallet systems. The company has assured customers that all losses will be covered and that the private key vulnerability has been addressed.
South Korean officials and multiple sources have attributed the attack to the North Korean state-backed Lazarus Group, citing similarities in tactics and laundering methods to previous incidents, including a 2019 breach of Upbit. Investigators believe the hackers impersonated Upbit administrators to facilitate the theft and are actively tracking the stolen funds, attempting to freeze assets before they can be moved further. The breach occurred shortly after Naver's $10 billion acquisition of Dunamu, Upbit's parent company, adding further scrutiny to the incident. Authorities continue to investigate, emphasizing the ongoing threat posed by Lazarus to the cryptocurrency sector.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
After the incident, Upbit said it remediated the private key vulnerability, started restructuring its security and wallet systems, and pledged through operator Dunamu to cover customer losses. The company said it would ensure member assets were not harmed by the breach.
In response to the theft, Upbit suspended deposits, withdrawals, and other digital asset transactions while transferring assets to a cold wallet and working to freeze the stolen funds. The exchange also began a broader review of its wallet and security systems.
Following the breach, South Korean officials said the attack was suspected to have been carried out by North Korea's Lazarus Group based on the tactics and laundering methods observed. The incident was also compared to a 2019 Upbit hack previously attributed to Lazarus.
On 2025-11-27, South Korean cryptocurrency exchange Upbit suffered a major security breach that resulted in the theft of about $30 million in digital assets from its Solana wallet. Reports said the attack involved administrator impersonation and exploited a weakness that enabled private key inferencing.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcetherecord.media
Open sourcekoreatimes.co.kr
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.