TLDR A Korean expert says nonce bias in Solana signatures exposed Upbit private keys. Attackers reviewed millions of Upbit transactions to detect cryptographic flaws. The breach hit both Upbit’s hot wallets and user deposit wallets, records show. Upbit froze withdrawals and moved funds to cold wallets after detecting the attack. A South Korean expert has [...] The post Upbit Hack Tied To Nonce Bias In Solana Transactions Says Korean Expert appeared first on CoinCentral.TLDR A Korean expert says nonce bias in Solana signatures exposed Upbit private keys. Attackers reviewed millions of Upbit transactions to detect cryptographic flaws. The breach hit both Upbit’s hot wallets and user deposit wallets, records show. Upbit froze withdrawals and moved funds to cold wallets after detecting the attack. A South Korean expert has [...] The post Upbit Hack Tied To Nonce Bias In Solana Transactions Says Korean Expert appeared first on CoinCentral.

Upbit Hack Tied To Nonce Bias In Solana Transactions Says Korean Expert

2025/11/29 17:07
3 min read
For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

TLDR

  • A Korean expert says nonce bias in Solana signatures exposed Upbit private keys.
  • Attackers reviewed millions of Upbit transactions to detect cryptographic flaws.
  • The breach hit both Upbit’s hot wallets and user deposit wallets, records show.
  • Upbit froze withdrawals and moved funds to cold wallets after detecting the attack.

A South Korean expert has claimed that the recent Upbit security breach was caused by a sophisticated cryptographic flaw, not a basic system vulnerability. The exploit reportedly targeted weaknesses in the generation of nonces used to sign Solana blockchain transactions, allowing attackers to deduce private keys.

Professor Jaewoo Cho from Hansung University said the breach stemmed from predictable patterns in Upbit’s signing process. Instead of a simple compromise of wallet keys, attackers likely used advanced statistical analysis across millions of blockchain signatures.

Security Flaw Traced to Biased Nonce Patterns

Upbit’s parent company, Dunamu, confirmed the presence of a vulnerability that allowed private keys to be exposed through blockchain data. CEO Kyoungsuk Oh publicly apologized and said the company had acted quickly to contain the threat.

Professor Cho explained that the attackers likely exploited biased or insufficiently random nonces—values used in each digital signature—to uncover private keys. “This is not about simple reuse,” he said, referring to common ECDSA flaws. “It’s about slight statistical biases detectable at scale.”

Cryptographic research published in 2025 shows that when attackers find related or affine nonces in ECDSA, even minimal patterns can lead to key recovery. In Upbit’s case, Solana’s signature structure was used in a way that exposed such vulnerabilities.

Attackers Gained Access to Multiple Wallet Types

Blockchain analysis suggests that both hot wallets and individual deposit wallets were affected by the attack. These wallets use different security systems, but compromised signing processes may have allowed access to all of them.

Some researchers believe the sweep-authority keys were also affected, meaning attackers could move funds from multiple deposit addresses. Upbit responded by halting deposits and withdrawals and transferring remaining funds to cold wallets.

According to internal reports, the company will cover user losses from its reserves. Investigators have not confirmed if any state-sponsored groups were involved, although the complexity of the attack suggests a highly organized team.

Industry Risks and Internal System Review

Following the breach, Upbit began reviewing its internal wallet infrastructure, including hardware security modules (HSMs) and multi-party computation (MPC) systems. Experts say the attackers required extensive resources to analyze millions of transaction signatures, suggesting strong planning and technical skills.

Some cybersecurity researchers have pointed out that similar patterns were seen in the 2019 Upbit breach, which was linked to North Korean groups. This new incident occurred on the sixth anniversary of that attack, raising questions among online users about possible coordination or internal lapses.

Community concerns grew as some speculated about insider involvement, especially as the hack took place during a major corporate merger involving Dunamu and Naver Financial.

Nonce Bias Presents New Challenge for Crypto Exchanges

The Upbit breach underlines a growing challenge for exchanges using ECDSA-based signatures. While the cryptographic system itself is secure, weak or predictable nonce generation can compromise it.

“Even minor randomness issues can leak critical information,” said Professor Cho. Research shows that only two signatures with related nonces may expose a private key. Exchanges must now reassess how they handle key signing to avoid similar issues.

Upbit has not shared the total amount stolen, but blockchain data suggests millions of dollars in digital assets may have been affected.

The post Upbit Hack Tied To Nonce Bias In Solana Transactions Says Korean Expert appeared first on CoinCentral.

Market Opportunity
Holo Token Logo
Holo Token Price(HOT)
$0.0003884
$0.0003884$0.0003884
-1.64%
USD
Holo Token (HOT) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Solana Price Prediction Stuck at $85 While Pepeto Presale Delivers What Solana Holders Have Been Waiting For

Solana Price Prediction Stuck at $85 While Pepeto Presale Delivers What Solana Holders Have Been Waiting For

The solana price prediction for March 2026 hinges on whether the $80 support holds or breaks, and the data suggests that solana is compressing into the tightest
Share
Techbullion2026/03/08 10:39
Apple (AAPL) Stock Gets $350 Price Target From Wedbush While One Pre-IPO Asset Targets 267x Returns

Apple (AAPL) Stock Gets $350 Price Target From Wedbush While One Pre-IPO Asset Targets 267x Returns

Key Takeaways: In this article, we highlight essential information about Apple (AAPL) Stock. – Wedbush raised Apple (AAPL) stock to a Street high $350 target with
Share
Techbullion2026/03/08 10:03
Shiba Inu Leader Breaks Silence on $2.4M Shibarium Exploit, Confirms Active Recovery

Shiba Inu Leader Breaks Silence on $2.4M Shibarium Exploit, Confirms Active Recovery

The lead developer of Shiba Inu, Shytoshi Kusama, has publicly addressed the Shibarium bridge exploit that occurred recently, draining $2.4 million from the network. After days of speculation about his involvement in managing the crisis, the project leader broke his silence.Kusama emphasized that a special ”war room” has been set up to restore stolen finances and enhance network security. The statement is his first official words since the bridge compromise occurred.”Although I am focusing on AI initiatives to benefit all our tokens, I remain with the developers and leadership in the war room,” Kusama posted on social media platform X. He dismissed claims that he had distanced himself from the project as ”utterly preposterous.”The developer said that the reason behind his silence at first was strategic. Before he could make any statements publicly, he must have taken time to evaluate what he termed a complex and deep situation properly. Kusama also vowed to provide further updates in the official Shiba Inu channels as the team comes up with long-term solutions.Attack Details and Immediate ResponseAs highlighted in our previous article, targeted Shibarium's bridge infrastructure through a sophisticated attack vector. Hackers gained unauthorized access to validator signing keys, compromising the network's security framework.The hackers executed a flash loan to acquire 4.6 million BONE ShibaSwap tokens. The validator power on the network was majority held by them after this purchase. They were able to transfer assets out of Shibarium with this control.The response of Shibarium developers was timely to limit the breach. They instantly halted all validator functions in order to avoid additional exploitation. The team proceeded to deposit the assets under staking in a multisig hardware wallet that is secure.External security companies were involved in the investigation effort. Hexens, Seal 911, and PeckShield are collaborating with internal developers to examine the attack and discover vulnerabilities.The project's key concerns are network stability and the protection of user funds, as underlined by the lead developer, Dhairya. The team is working around the clock to restore normal operations.In an effort to recover the funds, Shiba Inu has offered a bounty worth 5 Ether ($23,000) to the hackers. The bounty offer includes a 30-day deadline with decreasing rewards after seven days.Market Impact and Recovery IncentivesThe exploit caused serious volatility in the marketplace of Shiba Inu ecosystem tokens. SHIB dropped about 6% after the news of the attack. However, The token has bounced back and is currently trading at around $0.00001298 at the time of writing.SHIB Price Source CoinMarketCap
Share
Coinstats2025/09/18 02:25