Categories: Crypto/NFTs

North Korea’s Lazarus Suspected In Upbit Breach


Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure

South Korea’s largest cryptocurrency exchange, Upbit, is facing a second major security crisis after 44.5 billion won (around $30–32 million) in digital assets were drained from a hot wallet, with authorities “strongly” suspecting North Korea’s Lazarus Group.

According to ICT industry sources and government officials cited by Yonhap News on November 28, investigators are focusing on Lazarus, a hacking unit under North Korea’s Reconnaissance General Bureau, as the likely perpetrator. The group was also suspected in Upbit’s 2019 breach, when approximately 58 billion won in Ethereum was stolen.

North Korean Crypto Hackers Strike Again

The latest incident again centers on a hot wallet — an internet-connected operational wallet — replicating the core vulnerability of 2019. A government official quoted by Yonhap said the attack likely did not involve a deep server exploit but instead an administrative compromise: “Rather than a server attack, it’s possible they compromised an administrator account or impersonated an administrator to transfer funds,” adding that because the earlier hack used this method, “we consider this approach the most likely.”

Security experts point to the post-hack on-chain behavior as key circumstantial evidence. After the theft, the funds were rapidly “hopped” through other exchange wallets and then subjected to “mixing,” a laundering technique designed to break traceability.

One expert noted that “funds were hopped to other exchange wallets before mixing occurred. This can be seen as the modus operandi of the Lazarus Group,” adding that “once mixing occurs, transactions become untraceable.” Because FATF member countries cannot legally operate mixing services, the expert argued it is “highly likely North Korea was responsible.”

The timing has raised additional suspicion. The hack occurred on November 27, the same day Naver and Upbit operator Dunamu held a high-profile joint press conference at Naver’s “1784” headquarters to present their group-integration and AI/Web3 expansion strategy.

A security expert suggested the date may have been intentionally chosen: “Hackers often have a strong desire to show off. It’s possible they chose the 27th as the hacking date to flaunt their timing, selecting the very day of the merger announcement.” The attack also lands almost exactly six years after Upbit’s 2019 hack, which occurred on November 27.

Regulatory and supervisory bodies have moved quickly. Following a December interpretation by the Financial Services Commission that virtual asset exchanges’ user transaction data falls under the Credit Information Act, the Financial Supervisory Service and the Korea Financial Security Institute have launched an on-site inspection of Upbit. The Korea Internet & Security Agency has joined to provide technical support.

At press time, the total crypto market cap stood at $3.07 trillion.

Total crypto market cap holds above the 100-week EMA, 1-week chart | Source: TOTAL on TradingView.com

Featured image created with DALL.E, chart from TradingView.com

Editorial Process for bitcoinist is centered on delivering thoroughly researched, accurate, and unbiased content. We uphold strict sourcing standards, and each page undergoes diligent review by our team of top technology experts and seasoned editors. This process ensures the integrity, relevance, and value of our content for our readers.



Source link

admin2

Share
Published by
admin2

Recent Posts

Treasury Yields Snapshot: May 15, 2026

The yield on the 10-year note finished May 15, 2026 at 4.59% while the 2-year…

3 hours ago

West Kelowna pizza shop owner says viral ‘prank’ crossed the line – Okanagan

A West Kelowna, B.C., business owner is speaking out about a frightening confrontation inside his…

3 hours ago

US charges alleged Iran-backed ⁠Kataib Hezbollah suspect – What we know | News

EXPLAINERA criminal complaint unsealed on Friday in a Manhattan federal court accuses Mohammad Baqer Saad…

3 hours ago

Najlepšie zahraničné online kasína Zábava bez hraníc

V dnešnej dobe je online hazardovanie čoraz populárnejšie a môže sa stať skutočne vzrušujúcim spôsobom,…

3 hours ago

Hundreds rally in Red Deer to support teenage girl recovering from violent assault

Descrease article font size Increase article font size Rylin Brinston, 14, is battered and bruised…

6 hours ago

Seven-Week Win Streak Survives Friday Slump

The S&P 500 secured multiple record highs this week but faltered on Friday, retreating 1.2%…

8 hours ago