T
iTokenly

Upbit hack — November 2025

Verified — 4 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Target typeCentralised exchange
Loss$36,000,000Published estimates range $30,000,000 to $37,000,000Price at time of incident
MethodAccess control flawUnauthorised transfers from a Solana hot wallet, reportedly via hijacked or impersonated administrator credentials; root cause never disclosed
ChainsSolana
Attributed toLazarus GroupSuspected
OutcomeUsers reimbursed

What happened

Upbit, South Korea's largest cryptocurrency exchange, detected unauthorised transfers out of a Solana hot wallet at about 04:42 on 27 November 2025 Korean time, which is 19:42 UTC on 26 November. Operator Dunamu said assets worth roughly 54 billion won had been moved to an address that was not one of its designated internal wallets. Dollar equivalents in reporting diverge: Decrypt, CoinDesk and Halborn put the loss at roughly $36 million to $37 million, while The Record reported about $30 million.

The assets taken were Solana-network tokens rather than a single coin. Decrypt listed SOL and USDC alongside BONK, MOODENG, TRUMP, SONIC, ACS, JTO, RAY and PENGU; other outlets referred only to Solana-network tokens generally.

Upbit has not published a technical root cause. It suspended Solana deposits and withdrawals, moved remaining hot-wallet balances to cold storage and began an emergency review of its other networks and wallets. It also coordinated with token issuers to freeze what could still be frozen, and a portion of Solayer's LAYER token was successfully frozen. Dunamu chief executive Oh Kyung-seok said the entire amount would be covered by Upbit's own holdings, with no impact on customer assets.

South Korean government officials told the Yonhap news agency that North Korea's Lazarus Group was likely responsible, pointing to the intrusion methods and the way the proceeds were laundered, and investigators were reported to believe the attacker hijacked or impersonated administrator credentials to authorise the transfers. Halborn has suggested that weak or predictable signing data could have allowed private keys to be derived from historical transactions, but states that this has not been proven to be the cause. That attribution has not been formalised in a charge or a designation. The breach fell six years to the day after Upbit's 2019 hot-wallet theft.

Law enforcement

South Korean authorities opened an investigation and were reported to be preparing an on-site inspection of the exchange. Government officials told the Yonhap news agency that Lazarus Group was the likely perpetrator, based on the intrusion methods and the laundering pattern. No charges, arrests or sanctions designations tied to this incident have been reported.

Sources

  1. DecryptSecondary · retrieved 2026-08-01
  2. The Record (Recorded Future News)Secondary · retrieved 2026-08-01
  3. CoinDeskSecondary · retrieved 2026-08-01
  4. HalbornSecondary · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Upbit hack — November 2025", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/upbit-2025
https://itokenly.com/hacks/upbit-2025

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.