The post Lazarus Group Suspected in $36M Upbit Cryptocurrency Heist appeared on BitcoinEthereumNews.com. South Korea’s Upbit exchange suspended operations on Thursday after hackers stole $36 million worth of crypto. Authorities suspect North Korea’s Lazarus Group used credential hijacking tactics similar to their 2019 Upbit breach to access the exchange’s systems. South​‍​‌‍​‍‌​‍​‌‍​‍‌ Korean law enforcers are investigating out if North Korea’s notorious Lazarus Group was behind the $36 million cyberattack that targeted Upbit, the biggest cryptocurrency exchange in the country. In the incident that caused a freeze in all transactions after hackers got access to a hot wallet with Solana network tokens by the platform, hackers had compromised a hot wallet containing tokens on the Solana network, hence all transactions were suspended. This is the second time that the security of the platform has been ​‍​‌‍​‍‌​‍​‌‍​‍‌breached. Major Security Breach Rocks Upbit Exchange On​‍​‌‍​‍‌​‍​‌‍​‍‌ Thursday, Upbit decided to stop all crypto trading temporarily because it found some strange and suspicious activities related to Solana network tokens on its platform, thus causing a wave of security concerns among users and regulators.  The exchange made it clear that the attackers took about 54 billion Korean won, which is approximately $36 million to $37 million, from a single one of their hot wallets.  It’s the second time in six years that Upbit’s hot wallet has been seriously compromised; thus, the problem of weak security measures for the crypto exchange industry’s tech infrastructure has been around for quite a while ​‍​‌‍​‍‌​‍​‌‍​‍‌now. An investigation by the authorities in South Korea revealed that the attackers most likely forcibly took over the administration account or impersonated it to gain unauthorised access. They used the same kind of tactics that the Lazarus Group had used in the past.  Security analysts have compared this case with the 2019 Upbit hacking incident and found very similar patterns in both cases. Based on their analysis, the… The post Lazarus Group Suspected in $36M Upbit Cryptocurrency Heist appeared on BitcoinEthereumNews.com. South Korea’s Upbit exchange suspended operations on Thursday after hackers stole $36 million worth of crypto. Authorities suspect North Korea’s Lazarus Group used credential hijacking tactics similar to their 2019 Upbit breach to access the exchange’s systems. South​‍​‌‍​‍‌​‍​‌‍​‍‌ Korean law enforcers are investigating out if North Korea’s notorious Lazarus Group was behind the $36 million cyberattack that targeted Upbit, the biggest cryptocurrency exchange in the country. In the incident that caused a freeze in all transactions after hackers got access to a hot wallet with Solana network tokens by the platform, hackers had compromised a hot wallet containing tokens on the Solana network, hence all transactions were suspended. This is the second time that the security of the platform has been ​‍​‌‍​‍‌​‍​‌‍​‍‌breached. Major Security Breach Rocks Upbit Exchange On​‍​‌‍​‍‌​‍​‌‍​‍‌ Thursday, Upbit decided to stop all crypto trading temporarily because it found some strange and suspicious activities related to Solana network tokens on its platform, thus causing a wave of security concerns among users and regulators.  The exchange made it clear that the attackers took about 54 billion Korean won, which is approximately $36 million to $37 million, from a single one of their hot wallets.  It’s the second time in six years that Upbit’s hot wallet has been seriously compromised; thus, the problem of weak security measures for the crypto exchange industry’s tech infrastructure has been around for quite a while ​‍​‌‍​‍‌​‍​‌‍​‍‌now. An investigation by the authorities in South Korea revealed that the attackers most likely forcibly took over the administration account or impersonated it to gain unauthorised access. They used the same kind of tactics that the Lazarus Group had used in the past.  Security analysts have compared this case with the 2019 Upbit hacking incident and found very similar patterns in both cases. Based on their analysis, the…

Lazarus Group Suspected in $36M Upbit Cryptocurrency Heist

For feedback or concerns regarding this content, please contact us at [email protected]
  • South Korea’s Upbit exchange suspended operations on Thursday after hackers stole $36 million worth of crypto.
  • Authorities suspect North Korea’s Lazarus Group used credential hijacking tactics similar to their 2019 Upbit breach to access the exchange’s systems.

South​‍​‌‍​‍‌​‍​‌‍​‍‌ Korean law enforcers are investigating out if North Korea’s notorious Lazarus Group was behind the $36 million cyberattack that targeted Upbit, the biggest cryptocurrency exchange in the country. In the incident that caused a freeze in all transactions after hackers got access to a hot wallet with Solana network tokens by the platform, hackers had compromised a hot wallet containing tokens on the Solana network, hence all transactions were suspended. This is the second time that the security of the platform has been ​‍​‌‍​‍‌​‍​‌‍​‍‌breached.

Major Security Breach Rocks Upbit Exchange

On​‍​‌‍​‍‌​‍​‌‍​‍‌ Thursday, Upbit decided to stop all crypto trading temporarily because it found some strange and suspicious activities related to Solana network tokens on its platform, thus causing a wave of security concerns among users and regulators. 

The exchange made it clear that the attackers took about 54 billion Korean won, which is approximately $36 million to $37 million, from a single one of their hot wallets. 

It’s the second time in six years that Upbit’s hot wallet has been seriously compromised; thus, the problem of weak security measures for the crypto exchange industry’s tech infrastructure has been around for quite a while ​‍​‌‍​‍‌​‍​‌‍​‍‌now.

An investigation by the authorities in South Korea revealed that the attackers most likely forcibly took over the administration account or impersonated it to gain unauthorised access. They used the same kind of tactics that the Lazarus Group had used in the past. 

Security analysts have compared this case with the 2019 Upbit hacking incident and found very similar patterns in both cases. Based on their analysis, the hackers behind the 2019 Upbit attack were part of the same North Korean hacking collective as in this case. 

Experts pointed out that the probability of a North Korean involvement is extremely high, especially in light of the fact that North Korea is suffering from a severe shortage of foreign currency and has a past record of cryptocurrency theft. 

The stolen money, as per the reports, was passed through a series of complex mixing operations as part of a plan to cover the tracks, a signature technique that is frequently used by the Lazarus Group in their previous cryptocurrency ​‍​‌‍​‍‌​‍​‌‍​‍‌thefts.

The​‍​‌‍​‍‌​‍​‌‍​‍‌ attack’s timing has led to further theories regarding the attackers’ aims and possible links to cyber warfare units of North Korea that are sponsored by the state. The intrusion took place on the 27th of November, which is also the day when Upbit’s parent company, Dunamu, made public a major corporate merger with Korean technology giant Naver. 

Security experts commented that the attackers might have intentionally selected this date in order to create a stir and show off their abilities during a low-profile corporate ​‍​‌‍​‍‌​‍​‌‍​‍‌announcement.

“Hackers tend to have a strong desire to show off,” a cybersecurity expert said, pointing out how the timing of the attacks is often the most impressive part that the hackers want to be recognized symbolically.” 

The situation highlights the anxiety that has been growing due to the increase in the number of crypto-theft operations attributed to North Korea, through which, as it is said, the regime’s weapons programs get funded, and the regime is facilitated in getting around international sanctions. 

The South Korean police are still on the trail of Upbit hackers, while the exchange is committed to returning to regular operations and upgrading its security measures so that the attack will not be ​‍​‌‍​‍‌​‍​‌‍​‍‌repeated.

Highlighted Crypto News Today: 

43% Price Rally and 677% Volume Boom: Will TURBO Bulls Break Into Uncharted Territory?

Source: https://thenewscrypto.com/lazarus-group-suspected-in-36m-upbit-cryptocurrency-heist/

Market Opportunity
Holo Token Logo
Holo Token Price(HOT)
$0,0004459
$0,0004459$0,0004459
-0,24%
USD
Holo Token (HOT) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

The Channel Factories We’ve Been Waiting For

The Channel Factories We’ve Been Waiting For

The post The Channel Factories We’ve Been Waiting For appeared on BitcoinEthereumNews.com. Visions of future technology are often prescient about the broad strokes while flubbing the details. The tablets in “2001: A Space Odyssey” do indeed look like iPads, but you never see the astronauts paying for subscriptions or wasting hours on Candy Crush.  Channel factories are one vision that arose early in the history of the Lightning Network to address some challenges that Lightning has faced from the beginning. Despite having grown to become Bitcoin’s most successful layer-2 scaling solution, with instant and low-fee payments, Lightning’s scale is limited by its reliance on payment channels. Although Lightning shifts most transactions off-chain, each payment channel still requires an on-chain transaction to open and (usually) another to close. As adoption grows, pressure on the blockchain grows with it. The need for a more scalable approach to managing channels is clear. Channel factories were supposed to meet this need, but where are they? In 2025, subnetworks are emerging that revive the impetus of channel factories with some new details that vastly increase their potential. They are natively interoperable with Lightning and achieve greater scale by allowing a group of participants to open a shared multisig UTXO and create multiple bilateral channels, which reduces the number of on-chain transactions and improves capital efficiency. Achieving greater scale by reducing complexity, Ark and Spark perform the same function as traditional channel factories with new designs and additional capabilities based on shared UTXOs.  Channel Factories 101 Channel factories have been around since the inception of Lightning. A factory is a multiparty contract where multiple users (not just two, as in a Dryja-Poon channel) cooperatively lock funds in a single multisig UTXO. They can open, close and update channels off-chain without updating the blockchain for each operation. Only when participants leave or the factory dissolves is an on-chain transaction…
Share
BitcoinEthereumNews2025/09/18 00:09
Stabull’s Expansive Role in the DeFi Ecosystem

Stabull’s Expansive Role in the DeFi Ecosystem

The post Stabull’s Expansive Role in the DeFi Ecosystem appeared on BitcoinEthereumNews.com. A detailed examination of the Stabull protocol reveals its reach extends
Share
BitcoinEthereumNews2026/03/24 07:28
Stablecoin yield in crypto Clarity Act won’t allow rewards on balances, latest text says

Stablecoin yield in crypto Clarity Act won’t allow rewards on balances, latest text says

The post Stablecoin yield in crypto Clarity Act won’t allow rewards on balances, latest text says appeared on BitcoinEthereumNews.com. Crypto industry insiders
Share
BitcoinEthereumNews2026/03/24 06:58