South Korea’s largest cryptocurrency exchange, Upbit, suffered a $30 million hack on November 27, with authorities pointing to a North Korean state-backed group. The attack targeted a Solana hot wallet, moving SOL, USDC, and other tokens to an external wallet outside Upbit’s control.
Yonhap reported that investigators see “North Korean fingerprints” in the breach, drawing parallels to the 2019 Upbit hack, when Ethereum worth 58 billion won disappeared in a case linked to North Korea’s Lazarus Group. South Korean police, financial regulators, and intelligence agencies are inspecting Upbit, tracing around 44.5 billion won in stolen crypto, and checking if compromised administrator credentials were exploited rather than a direct server breach.
Upbit has reimbursed all affected users from its own reserves, absorbing a corporate loss of roughly 5.9 billion won. A portion of the stolen funds has been frozen with help from blockchain analytics teams, while remaining Solana holdings were moved to cold storage. Blockchain tracking shows the assets were moved across 185 wallets and bridged into Ethereum, a pattern consistent with Lazarus-style laundering.
In response, South Korea’s Financial Intelligence Unit is reviewing Korbit, Gopax, Bithumb, and Coinone for weak AML practices and poor customer verification, signaling that further penalties could follow. The move highlights ongoing efforts to strengthen security and compliance across South Korea’s crypto market after repeated North Korea-linked hacks.
Disclaimer: This content does not constitute trading or investment recommendations. It’s essential to conduct your own research before purchasing any cryptocurrency or investing in any services.















