Upbit said it discovered a vulnerability that could have allowed attackers to infer private keys from onchain wallet data.Upbit said it discovered a vulnerability that could have allowed attackers to infer private keys from onchain wallet data.

Upbit says emergency audit of $30M hack uncovered internal wallet flaw that could let attackers derive private keys

2025/11/28 19:29
3 min read
For feedback or concerns regarding this content, please contact us at [email protected]

Upbit said it uncovered and patched a serious vulnerability in its internal wallet system while conducting an emergency investigation into the $30 million theft that hit the South Korean exchange earlier this week — but it remains unclear if the flaw was connected to the hack.

According to a translation of a company statement on Friday, CEO Oh Kyung-seok said the exchange identified "a security vulnerability in our system that could have allowed someone analyzing publicly visible Upbit wallet transactions on the blockchain to infer private keys," referring to the cryptographic credentials that control access to funds.

While normal blockchain data does not reveal private keys, it appears Upbit's own wallet software had a flaw that produced weak or predictable signature data, meaning an attacker analyzing the crypto exchange's past onchain transactions could mathematically reconstruct certain wallet private keys due to a serious implementation bug on Upbit's end.

The exchange did not link the vulnerability to the breach directly and said the issue was discovered only after Upbit began a systemwide review following irregular withdrawals from its Solana-related wallets on Nov. 27.

"We identified and addressed the vulnerability during a comprehensive inspection of all related networks and wallet systems," Oh said, adding that the company had activated an emergency response system and suspended all deposits and withdrawals until its infrastructure is fully verified as secure.

According to the notice, Upbit confirmed the hack resulted in losses totaling approximately 44.5 billion KRW or roughly $30 million, including 38.6 billion KRW worth an estimated $26 million in customer assets. About 2.3 billion KRW ($1.5 million) of stolen funds have already been frozen, the firm added.

Upbit is now conducting a broader security review across its infrastructure, noting the incident serves as a reminder that "no security system can ever be considered perfect," pledging deeper upgrades to prevent future breaches.

The crypto exchange said it will provide ongoing public updates and will resume deposits and withdrawals once its wallet systems complete final security checks. The platform has committed to covering all customer losses using its own reserves.

Authorities investigating Lazarus Group involvement

On Nov. 26, the crypto exchange halted withdrawals immediately after detecting abnormal Solana-based outflows, including tokens such as SOL, ORCA, RAY, and JUP, among others.

It subsequently moved remaining assets to cold storage and began a full wallet overhaul.

Upbit is South Korea's largest exchange by trading volume, operating under parent company Dunamu, which is currently preparing for a merger with internet conglomerate Naver ahead of a potential public market listing.

South Korean authorities have also opened an investigation into the incident.

As The Block reported Thursday, local media outlets have cited early intelligence assessments suggesting North Korea's Lazarus Group may be a suspect. However, Upbit and regulators have not publicly confirmed attribution.

Upbit said it continues to coordinate with law enforcement and blockchain projects to freeze and recover stolen assets where possible.


Disclaimer: The Block is an independent media outlet that delivers news, research, and data. As of November 2023, Foresight Ventures is a majority investor of The Block. Foresight Ventures invests in other companies in the crypto space. Crypto exchange Bitget is an anchor LP for Foresight Ventures. The Block continues to operate independently to deliver objective, impactful, and timely information about the crypto industry. Here are our current financial disclosures.

© 2025 The Block. All Rights Reserved. This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.

Market Opportunity
Ambire Wallet Logo
Ambire Wallet Price(WALLET)
$0.00999
$0.00999$0.00999
0.00%
USD
Ambire Wallet (WALLET) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Pundit: Every XRP Holder Needs to Understand What’s Happening Right Now

Pundit: Every XRP Holder Needs to Understand What’s Happening Right Now

Rising geopolitical tension often exposes the hidden cracks in global finance, and few regions demonstrate this more clearly than the Strait of Hormuz. As a critical
Share
Timestabloid2026/03/24 04:05
US Dollar and Oil fall as Trump signals Iran de-escalation

US Dollar and Oil fall as Trump signals Iran de-escalation

The post US Dollar and Oil fall as Trump signals Iran de-escalation appeared on BitcoinEthereumNews.com. Here is what you need to know for Tuesday, March 24: The
Share
BitcoinEthereumNews2026/03/24 04:06
Adoption Leads Traders to Snorter Token

Adoption Leads Traders to Snorter Token

The post Adoption Leads Traders to Snorter Token appeared on BitcoinEthereumNews.com. Largest Bank in Spain Launches Crypto Service: Adoption Leads Traders to Snorter Token Sign Up for Our Newsletter! For updates and exclusive offers enter your email. Leah is a British journalist with a BA in Journalism, Media, and Communications and nearly a decade of content writing experience. Over the last four years, her focus has primarily been on Web3 technologies, driven by her genuine enthusiasm for decentralization and the latest technological advancements. She has contributed to leading crypto and NFT publications – Cointelegraph, Coinbound, Crypto News, NFT Plazas, Bitcolumnist, Techreport, and NFT Lately – which has elevated her to a senior role in crypto journalism. Whether crafting breaking news or in-depth reviews, she strives to engage her readers with the latest insights and information. Her articles often span the hottest cryptos, exchanges, and evolving regulations. As part of her ploy to attract crypto newbies into Web3, she explains even the most complex topics in an easily understandable and engaging way. Further underscoring her dynamic journalism background, she has written for various sectors, including software testing (TEST Magazine), travel (Travel Off Path), and music (Mixmag). When she’s not deep into a crypto rabbit hole, she’s probably island-hopping (with the Galapagos and Hainan being her go-to’s). Or perhaps sketching chalk pencil drawings while listening to the Pixies, her all-time favorite band. This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy Center or Cookie Policy. I Agree Source: https://bitcoinist.com/banco-santander-and-snorter-token-crypto-services/
Share
BitcoinEthereumNews2025/09/17 23:45