Upbit replaced all stolen user funds while investigators track a Lazarus-style laundering trail. South Korea’s FIU targets Korbit, Gopax, Bithumb, and Coinone with penalties after compliance failures. South Korean authorities say a North Korean state-backed hacking group likely stole about 44.5 billion won, roughly 30 million dollars, from the country’s largest crypto exchange, Upbit. The [...]]]>Upbit replaced all stolen user funds while investigators track a Lazarus-style laundering trail. South Korea’s FIU targets Korbit, Gopax, Bithumb, and Coinone with penalties after compliance failures. South Korean authorities say a North Korean state-backed hacking group likely stole about 44.5 billion won, roughly 30 million dollars, from the country’s largest crypto exchange, Upbit. The [...]]]>

Report Claims North Korean Group Orchestrated $30M Crypto Hack in South Korea

For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com
  • Upbit replaced all stolen user funds while investigators track a Lazarus-style laundering trail.
  • South Korea’s FIU targets Korbit, Gopax, Bithumb, and Coinone with penalties after compliance failures.

South Korean authorities say a North Korean state-backed hacking group likely stole about 44.5 billion won, roughly 30 million dollars, from the country’s largest crypto exchange, Upbit. The breach hit a Solana hot wallet on Nov. 27, according to Upbit’s operator Dunamu.

Around 4:42 a.m. local time, the exchange detected abnormal withdrawals of Solana-based tokens and quickly suspended deposits and withdrawals on the network. The stolen assets included SOL, USDC, and a basket of other Solana ecosystem tokens that were sent to an external wallet not controlled by the exchange.

Source: LookonchainSource: Lookonchain on X

Soon after the incident, Yonhap and other local outlets reported that investigators see “North Korean fingerprints” on the attack. Officials said the operation bears similarities to the 2019 Upbit hack, as featured in our coverage, when 58 billion won worth of Ethereum disappeared in a case later tied to North Korea’s Lazarus Group.

South Korea’s police cyber unit, financial regulators, and intelligence agencies are conducting on-site inspections at Dunamu. They are tracing flows linked to about 44.5 billion won in stolen crypto and reviewing whether compromised or impersonated administrator credentials opened the door, rather than a direct break of Upbit’s core servers.

Upbit Pays Back $30M Losses as Suspected North Korean Trail Appears

Upbit said it has already reimbursed all affected member assets from its own reserves and absorbed a corporate loss of about 5.9 billion won. It also reported freezing a portion of the stolen funds with help from project teams and blockchain analytics firms, while shifting remaining Solana holdings into cold storage.

As the investigation unfolds, blockchain traces show the attacker quickly swapped multiple Solana tokens into wrapped Solana and SOL, then moved the proceeds across roughly 185 wallets before bridging into Ethereum. That pattern, according to analysts, matches earlier Lazarus-linked laundering routes.

South Korea Targets Four More Exchanges After Upbit Case

Meanwhile, South Korea’s Financial Intelligence Unit is now turning to Korbit, Gopax, Bithumb, and Coinone after the Upbit incident. Regulators plan penalties for these four platforms following a 35.2 billion won fine against Dunamu, as previously mentioned in our report, the operator of Upbit, for weak anti–money laundering and customer checks.

Inspectors ran on-site reviews across the exchanges from 2024 into early 2025 and kept finding similar problems. They flagged poor ID verification, slow reports of suspicious activity, and large transfers that slipped past AML controls. As a result, authorities expect further sanctions to land in the first half of next year.

]]>
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

The Channel Factories We’ve Been Waiting For

The Channel Factories We’ve Been Waiting For

The post The Channel Factories We’ve Been Waiting For appeared on BitcoinEthereumNews.com. Visions of future technology are often prescient about the broad strokes while flubbing the details. The tablets in “2001: A Space Odyssey” do indeed look like iPads, but you never see the astronauts paying for subscriptions or wasting hours on Candy Crush.  Channel factories are one vision that arose early in the history of the Lightning Network to address some challenges that Lightning has faced from the beginning. Despite having grown to become Bitcoin’s most successful layer-2 scaling solution, with instant and low-fee payments, Lightning’s scale is limited by its reliance on payment channels. Although Lightning shifts most transactions off-chain, each payment channel still requires an on-chain transaction to open and (usually) another to close. As adoption grows, pressure on the blockchain grows with it. The need for a more scalable approach to managing channels is clear. Channel factories were supposed to meet this need, but where are they? In 2025, subnetworks are emerging that revive the impetus of channel factories with some new details that vastly increase their potential. They are natively interoperable with Lightning and achieve greater scale by allowing a group of participants to open a shared multisig UTXO and create multiple bilateral channels, which reduces the number of on-chain transactions and improves capital efficiency. Achieving greater scale by reducing complexity, Ark and Spark perform the same function as traditional channel factories with new designs and additional capabilities based on shared UTXOs.  Channel Factories 101 Channel factories have been around since the inception of Lightning. A factory is a multiparty contract where multiple users (not just two, as in a Dryja-Poon channel) cooperatively lock funds in a single multisig UTXO. They can open, close and update channels off-chain without updating the blockchain for each operation. Only when participants leave or the factory dissolves is an on-chain transaction…
Share
BitcoinEthereumNews2025/09/18 00:09
Stabull’s Expansive Role in the DeFi Ecosystem

Stabull’s Expansive Role in the DeFi Ecosystem

The post Stabull’s Expansive Role in the DeFi Ecosystem appeared on BitcoinEthereumNews.com. A detailed examination of the Stabull protocol reveals its reach extends
Share
BitcoinEthereumNews2026/03/24 07:28
Stablecoin yield in crypto Clarity Act won’t allow rewards on balances, latest text says

Stablecoin yield in crypto Clarity Act won’t allow rewards on balances, latest text says

The post Stablecoin yield in crypto Clarity Act won’t allow rewards on balances, latest text says appeared on BitcoinEthereumNews.com. Crypto industry insiders
Share
BitcoinEthereumNews2026/03/24 06:58