The post North Korean Lazarus Group Suspected in Major Upbit Security Incident appeared on BitcoinEthereumNews.com. Crime South Korean regulators are preparing an on-site investigation at the Upbit exchange after a sudden outflow of digital assets triggered nationwide alerts. Key Takeaways: Upbit lost roughly 45 billion won in crypto after unauthorized transfers traced to external wallets. Investigators believe attackers abused high-level administrative access, consistent with previous Lazarus-linked breaches. Dunamu will reimburse all affected users while authorities conduct an on-site probe at the exchange. The transfers — now calculated at roughly 45 billion won — were traced to external wallets shortly before authorities flagged abnormal administrative activity. Why investigators immediately traced it to Lazarus Officials reviewing early telemetry say the pattern of the breach looked familiar before the destination of the funds was even identified. Rather than exploiting backend infrastructure, the attackers appear to have gained high-level account authority, enabling withdrawals without attacking servers directly.The method mirrors a well-documented 2019 incident in which the same state-linked hacking organization stole 58 billion won in ETH. Rather than celebrating technical sophistication, analysts called the method “practical, predictable, and consistent with financially motivated cybercrime.” Political and financial backdrop The attack lands at a moment when North Korea is widely believed to be relying on cyber-enabled revenue for foreign currency. Intelligence groups tracking the Lazarus group say the operation aligns with an ongoing strategy: steal crypto, move assets between exchanges quickly, and launder through networks engineered to sever transaction trails from original sources. The exchange’s operator, Dunamu, said affected users will be fully compensated using corporate reserves, guaranteeing no losses for retail account holders. The timing raises questions, not coincidences The breach occurred one day after Naver Corp. announced a full share-swap agreement to acquire Dunamu. Cybersecurity analysts argue that Lazarus has a habit of targeting moments when attention is heightened around a company — not only for financial gain but… The post North Korean Lazarus Group Suspected in Major Upbit Security Incident appeared on BitcoinEthereumNews.com. Crime South Korean regulators are preparing an on-site investigation at the Upbit exchange after a sudden outflow of digital assets triggered nationwide alerts. Key Takeaways: Upbit lost roughly 45 billion won in crypto after unauthorized transfers traced to external wallets. Investigators believe attackers abused high-level administrative access, consistent with previous Lazarus-linked breaches. Dunamu will reimburse all affected users while authorities conduct an on-site probe at the exchange. The transfers — now calculated at roughly 45 billion won — were traced to external wallets shortly before authorities flagged abnormal administrative activity. Why investigators immediately traced it to Lazarus Officials reviewing early telemetry say the pattern of the breach looked familiar before the destination of the funds was even identified. Rather than exploiting backend infrastructure, the attackers appear to have gained high-level account authority, enabling withdrawals without attacking servers directly.The method mirrors a well-documented 2019 incident in which the same state-linked hacking organization stole 58 billion won in ETH. Rather than celebrating technical sophistication, analysts called the method “practical, predictable, and consistent with financially motivated cybercrime.” Political and financial backdrop The attack lands at a moment when North Korea is widely believed to be relying on cyber-enabled revenue for foreign currency. Intelligence groups tracking the Lazarus group say the operation aligns with an ongoing strategy: steal crypto, move assets between exchanges quickly, and launder through networks engineered to sever transaction trails from original sources. The exchange’s operator, Dunamu, said affected users will be fully compensated using corporate reserves, guaranteeing no losses for retail account holders. The timing raises questions, not coincidences The breach occurred one day after Naver Corp. announced a full share-swap agreement to acquire Dunamu. Cybersecurity analysts argue that Lazarus has a habit of targeting moments when attention is heightened around a company — not only for financial gain but…

North Korean Lazarus Group Suspected in Major Upbit Security Incident

For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com
Crime

South Korean regulators are preparing an on-site investigation at the Upbit exchange after a sudden outflow of digital assets triggered nationwide alerts.

Key Takeaways:

  • Upbit lost roughly 45 billion won in crypto after unauthorized transfers traced to external wallets.
  • Investigators believe attackers abused high-level administrative access, consistent with previous Lazarus-linked breaches.
  • Dunamu will reimburse all affected users while authorities conduct an on-site probe at the exchange.

The transfers — now calculated at roughly 45 billion won — were traced to external wallets shortly before authorities flagged abnormal administrative activity.

Why investigators immediately traced it to Lazarus

Officials reviewing early telemetry say the pattern of the breach looked familiar before the destination of the funds was even identified. Rather than exploiting backend infrastructure, the attackers appear to have gained high-level account authority, enabling withdrawals without attacking servers directly.
The method mirrors a well-documented 2019 incident in which the same state-linked hacking organization stole 58 billion won in ETH.

Rather than celebrating technical sophistication, analysts called the method “practical, predictable, and consistent with financially motivated cybercrime.”

Political and financial backdrop

The attack lands at a moment when North Korea is widely believed to be relying on cyber-enabled revenue for foreign currency. Intelligence groups tracking the Lazarus group say the operation aligns with an ongoing strategy: steal crypto, move assets between exchanges quickly, and launder through networks engineered to sever transaction trails from original sources.

The exchange’s operator, Dunamu, said affected users will be fully compensated using corporate reserves, guaranteeing no losses for retail account holders.

The timing raises questions, not coincidences

The breach occurred one day after Naver Corp. announced a full share-swap agreement to acquire Dunamu.

Cybersecurity analysts argue that Lazarus has a habit of targeting moments when attention is heightened around a company — not only for financial gain but also to maximize visibility.

Government officials noted that psychological elements often accompany the group’s operations, including a pattern of selecting moments that ensure the cyberattack dominates headlines.

What happens next

The Financial Supervisory Service and local investigative bodies will begin their review directly at Upbit facilities to determine how administrator-level access was obtained and whether internal processes were manipulated.

Until then, investigators are treating the breach as part of a larger campaign rather than an isolated cyber incident.


The information provided in this article is for educational purposes only and does not constitute financial, investment, or trading advice. Coindoo.com does not endorse or recommend any specific investment strategy or cryptocurrency. Always conduct your own research and consult with a licensed financial advisor before making any investment decisions.

Author

Alexander Zdravkov is a person who always looks for the logic behind things. He has more than 3 years of experience in the crypto space, where he skillfully identifies new trends in the world of digital currencies. Whether providing in-depth analysis or daily reports on all topics, his deep understanding and enthusiasm for what he does make him a valuable member of the team.

Related stories

Next article

Source: https://coindoo.com/north-korean-lazarus-group-suspected-in-major-upbit-security-incident/

Market Opportunity
Major Logo
Major Price(MAJOR)
$0.06591
$0.06591$0.06591
+3.43%
USD
Major (MAJOR) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

The Channel Factories We’ve Been Waiting For

The Channel Factories We’ve Been Waiting For

The post The Channel Factories We’ve Been Waiting For appeared on BitcoinEthereumNews.com. Visions of future technology are often prescient about the broad strokes while flubbing the details. The tablets in “2001: A Space Odyssey” do indeed look like iPads, but you never see the astronauts paying for subscriptions or wasting hours on Candy Crush.  Channel factories are one vision that arose early in the history of the Lightning Network to address some challenges that Lightning has faced from the beginning. Despite having grown to become Bitcoin’s most successful layer-2 scaling solution, with instant and low-fee payments, Lightning’s scale is limited by its reliance on payment channels. Although Lightning shifts most transactions off-chain, each payment channel still requires an on-chain transaction to open and (usually) another to close. As adoption grows, pressure on the blockchain grows with it. The need for a more scalable approach to managing channels is clear. Channel factories were supposed to meet this need, but where are they? In 2025, subnetworks are emerging that revive the impetus of channel factories with some new details that vastly increase their potential. They are natively interoperable with Lightning and achieve greater scale by allowing a group of participants to open a shared multisig UTXO and create multiple bilateral channels, which reduces the number of on-chain transactions and improves capital efficiency. Achieving greater scale by reducing complexity, Ark and Spark perform the same function as traditional channel factories with new designs and additional capabilities based on shared UTXOs.  Channel Factories 101 Channel factories have been around since the inception of Lightning. A factory is a multiparty contract where multiple users (not just two, as in a Dryja-Poon channel) cooperatively lock funds in a single multisig UTXO. They can open, close and update channels off-chain without updating the blockchain for each operation. Only when participants leave or the factory dissolves is an on-chain transaction…
Share
BitcoinEthereumNews2025/09/18 00:09
Stabull’s Expansive Role in the DeFi Ecosystem

Stabull’s Expansive Role in the DeFi Ecosystem

The post Stabull’s Expansive Role in the DeFi Ecosystem appeared on BitcoinEthereumNews.com. A detailed examination of the Stabull protocol reveals its reach extends
Share
BitcoinEthereumNews2026/03/24 07:28
Stablecoin yield in crypto Clarity Act won’t allow rewards on balances, latest text says

Stablecoin yield in crypto Clarity Act won’t allow rewards on balances, latest text says

The post Stablecoin yield in crypto Clarity Act won’t allow rewards on balances, latest text says appeared on BitcoinEthereumNews.com. Crypto industry insiders
Share
BitcoinEthereumNews2026/03/24 06:58