South Korea Points to North Korea-Linked Lazarus Group in $36M Upbit Hack

South Korea’s largest digital asset exchange, Upbit, temporarily suspended deposits and withdrawals on Thursday after detecting unusual activity in Solana network tokens. The exchange later confirmed that a hot wallet had been compromised, resulting in unauthorized withdrawals of roughly 54 billion Korean won (around $36–$37 million). This marks Upbit’s second major hot wallet hack in six years.

According to Yonhap, South Korean authorities are investigating the breach and considering the North Korea-linked Lazarus Group as a possible culprit. Officials suspect the attack may have involved hijacked or impersonated admin credentials, echoing tactics used by Lazarus during Upbit’s 2019 breach. Analysts noted that North Korea, facing foreign currency shortages, has a history of orchestrating such thefts, often laundering funds through mixing services—a method consistent with Lazarus operations.

The hack occurred on November 27, coinciding with a major corporate merger involving Upbit’s parent company, Dunamu, and Korean tech giant Naver. Security experts suggested the timing may have been deliberate. “Hackers tend to have a strong desire to show off,” one expert told Yonhap. “It is possible they chose the 27th to maximize attention by aligning with the merger announcement.”

  • Related Posts

    Bitcoin’s downside may be limited if gold comparison signals a bottom, analyst notes

    Bitcoin’s correction could extend into late 2026 in dollar terms, but its valuation against gold suggests the market may be closer to a turning point, according to research from Mercado…

    Continue reading
    SpaceX’s once-$780M bitcoin treasury now valued near $545M as IPO filing looms

    SpaceX holds roughly 8,285 bitcoin in custody with Coinbase Prime, a position now worth about $545 million after losing approximately $235 million in value over the past three months. For…

    Continue reading