South Korean authorities now suspect that North Korea's Lazarus Group executed the recent hacker attack on Upbit.South Korean authorities now suspect that North Korea's Lazarus Group executed the recent hacker attack on Upbit.

South Korean investigators deepen Upbit hack probe as Lazarus Group link strengthens

upbit hack

South Korean regulators are intensifying scrutiny of the Upbit hack as investigators connect the incident to a broader pattern of North Korean cyber operations, well-known as Lazarus Group.

What do South Korean authorities say about the Upbit incident?

South Korean authorities now suspect that North Korea’s Lazarus Group executed the recent attack on Upbit, one of the country’s largest cryptocurrency exchanges. According to a report by YONHAP NEWS AGENCY, the breach resulted in the theft of approximately 44.5 billion won ($30.4 million). The incident surfaced after the platform detected suspicious activity affecting customer assets.

Officials noted that confidence in Lazarus’s involvement has grown as the investigation progressed. Moreover, they emphasized that the scale and sophistication of the theft resemble earlier operations linked to North Korean actors. Authorities are coordinating with domestic cybersecurity teams and international partners to verify the attribution and recover as many funds as possible.

How did Upbit detect the abnormal activity?

On Thursday, Upbit identified unusual withdrawals involving Solana-based crypto assets. In response, the exchange halted all deposit and withdrawal services, aiming to contain any further outflows. The platform quickly launched an internal review to trace the origin of the transfers, which involved substantial sums across several wallets.

Initially, the company reported losses of 54 billion won ($36.8 million). However, after further reconciliation, that figure was revised down to 44.5 billion won ($30.4 million). Upbit’s rapid suspension of services helped limit additional damage. That said, the incident triggered renewed concerns about cryptocurrency exchange security in South Korea’s fast-growing digital asset market.

Why is Lazarus Group suspected in the Upbit exchange hack?

Investigators highlight clear similarities between this latest theft and a major incident that struck Upbit in 2019. That earlier attack, which South Korean police also attributed to Lazarus, led to the loss of 342,000 ETH. Moreover, both operations involved large-scale crypto outflows executed in a short time frame.

Authorities believe the hackers may have compromised administrator accounts or impersonated internal staff to authorize withdrawals. These intrusion techniques align with previously documented lazarus group attribution patterns. “We are closely inspecting the situation to confirm whether Lazarus is involved,” a government official stated, underscoring that the inquiry remains active.

How is blockchain analysis tracing the stolen funds?

Investigators are focusing heavily on blockchain analysis tracing to follow the movement of the stolen assets. On-chain data shows that the hacker’s wallet swapped Solana tokens for USDC, a leading stablecoin. The funds were then moved via an USDC bridge to the Ethereum network, a typical tactic used to obscure transaction trails.

Blockchain analytics provider Dethective flagged a series of addresses and transaction patterns matching the timeline of the attack. Furthermore, the routing and conversion behavior mirrors strategies seen in previous Lazarus-linked campaigns. This overlap has reinforced investigators’ working theory that the same state-backed group is behind the new Upbit incident.

What are the implications of the Upbit security breach for users?

The latest upbit security breach has raised hard questions about how crypto platforms protect customer assets amid escalating cyber threats. While Upbit’s swift response limited the overall loss, users remain concerned about potential future incidents. Moreover, the recurrence of an attack resembling the 2019 theft has intensified calls for stronger oversight and technical standards.

Regulators are expected to review internal control requirements for trading venues, especially around admin account management and real-time monitoring of large transfers. Exchanges may face pressure to increase cold storage ratios, upgrade multi-signature schemes, and enhance incident disclosure practices to rebuild user confidence.

How does the Naver Financial merger affect the fallout from the hack?

The recent Upbit hack coincided with a strategic announcement from Naver Financial. The company confirmed its plan to merge with Dunamu, the operator of Upbit, and integrate it as a subsidiary. This move aims to strengthen Naver Financial’s position in the digital asset and fintech sectors, despite the ongoing investigation.

Market observers note that the naver financial merger could provide Upbit with greater resources to bolster its security stack. However, it also increases scrutiny on both entities to demonstrate robust risk management. In particular, investors will watch how the combined group addresses vulnerabilities exposed by the attack.

What is next for Upbit after the hack?

Despite the turmoil, Upbit is pressing ahead with its long-term growth strategy alongside Naver Financial. The integration is expected to expand Upbit’s technical capacity, liquidity access, and compliance infrastructure. That said, the platform must now prove it can prevent another high-profile breach while operating at larger scale.

In summary, South Korean authorities are tightening their probe into the Upbit hack, using detailed on-chain forensics and historical patterns to support a likely connection to Lazarus Group. The outcome of this investigation, combined with the merger’s completion, will shape how users and regulators view the exchange’s resilience in an increasingly hostile cyber environment.

Market Opportunity
Chainlink Logo
Chainlink Price(LINK)
$14.1
$14.1$14.1
-0.98%
USD
Chainlink (LINK) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Ethereum Price Prediction: ETH Targets $10,000 In 2026 But Layer Brett Could Reach $1 From $0.0058

Ethereum Price Prediction: ETH Targets $10,000 In 2026 But Layer Brett Could Reach $1 From $0.0058

Ethereum price predictions are turning heads, with analysts suggesting ETH could climb to $10,000 by 2026 as institutional demand and network upgrades drive growth. While Ethereum remains a blue-chip asset, investors looking for sharper multiples are eyeing Layer Brett (LBRETT). Currently in presale at just $0.0058, the Ethereum Layer 2 meme coin is drawing huge [...] The post Ethereum Price Prediction: ETH Targets $10,000 In 2026 But Layer Brett Could Reach $1 From $0.0058 appeared first on Blockonomi.
Share
Blockonomi2025/09/17 23:45
‘Primal’ Creator Genndy Tartakovsky Talks Zombified Season 3

‘Primal’ Creator Genndy Tartakovsky Talks Zombified Season 3

The post ‘Primal’ Creator Genndy Tartakovsky Talks Zombified Season 3 appeared on BitcoinEthereumNews.com. A zombified Spear appears in Season 3 of Adult Swim’s
Share
BitcoinEthereumNews2026/01/15 06:04
‘Dr. Quinn’ Co-Stars Jane Seymour And Joe Lando Reuniting In New Season Of ‘Harry Wild’

‘Dr. Quinn’ Co-Stars Jane Seymour And Joe Lando Reuniting In New Season Of ‘Harry Wild’

The post ‘Dr. Quinn’ Co-Stars Jane Seymour And Joe Lando Reuniting In New Season Of ‘Harry Wild’ appeared on BitcoinEthereumNews.com. Joe Lando and Janey Seymour in “Harry Wild.” Courtesy: AMC / Acorn Jane Seymour is getting her favorite frontier friend to join her in her latest series. In the mid-90s Seymour spent six seasons as Dr. Micheala Quinn on Dr. Quinn, Medicine Woman. During the run of the series, Dr. Quinn met, married, and started a family with local frontiersman Byron Sully, also known simply as Sully, played by Joe Lando. Now, the duo will once again be partnering up, but this time to solve crimes in Seymour’s latest show, Harry Wild. In the series, literature professor Harriet ‘Harry’ Wild found herself at crossroads, having difficulty adjusting to retirement. After a stint staying with her police detective son, Charlie, Harry begins to investigate crimes herself, now finding an unlikely new sleuthing partner, a teen who had mugged Harry. In the upcoming fifth season, now in production in Dublin, Ireland, Lando will join the cast, playing Pierce Kennedy, the new State Pathologist, who becomes a charming and handsome natural ally for Harry. Promotional portrait of British actress Jane Seymour (born Joyce Penelope Wilhelmina Frankenberg), as Dr. Michaela ‘Mike’ Quinn, and American actor Joe Lando, as Byron Sully, as they pose with horses for the made-for-tv movie ‘Dr. Quinn, Medicine Woman: the Movie,’ 1999. (Photo by Spike Nannarello/CBS Photo Archive/Getty Images) Getty Images Emmy-Award Winner Seymour also serves as executive producer on the series. The new season finds Harry and Fergus delving into the worlds of whiskey-making, theatre and musical-tattoos, chasing a gang of middle-aged lady burglars and working to deal with a murder close to home. Debuting in 2026, Harry Wild Season 5 will consist of six episodes. Ahead of the new season, a 2-part Harry Wild Special will debut exclusively on Acorn TV on Monday, November 24th. Source: https://www.forbes.com/sites/anneeaston/2025/09/17/dr-quinn-co-stars-jane-seymour-and-joe-lando-reuniting-in-new-season-of-harry-wild/
Share
BitcoinEthereumNews2025/09/18 07:05