The post Binance Under Fire After Freezing Just 17% of Upbit Hack Funds appeared on BitcoinEthereumNews.com. The 15-hour delay and minimal freeze attracted a lotThe post Binance Under Fire After Freezing Just 17% of Upbit Hack Funds appeared on BitcoinEthereumNews.com. The 15-hour delay and minimal freeze attracted a lot

Binance Under Fire After Freezing Just 17% of Upbit Hack Funds

2025/12/12 21:03

The 15-hour delay and minimal freeze attracted a lot of criticism from security experts who say quick intervention is crucial in active exploits. Upbit has since shifted 99% of customer assets to cold storage as investigators probe links to North Korea’s Lazarus Group. At the same time, Binance faced another security issue when newly appointed co-CEO Yi He had her long-abandoned WeChat account hijacked and used to promote a scam token. The takeover was very similar to a  recent breach involving Justin Sun.

Investigators Question Binance Response in Upbit Hack

Korean investigators say Binance froze only a small fraction of the crypto that was stolen in last month’s Upbit hack. According to local reports, authorities urgently requested that Binance halt the movement of roughly 470 million won (about $370,000) worth of Solana traced to the hackers. However, the exchange ultimately froze just 80 million won (about $75,000), or around 17% of the assets flagged for action. 

The freeze was confirmed roughly 15 hours after the initial request. This delay attracted a lot of criticism from security experts and people in the crypto industry.

Analysts monitoring the breach say the attackers used a complex laundering pattern immediately after the Nov. 27 exploit against Upbit’s systems, and quickly dispersed the stolen crypto across more than a thousand wallets. The funds were broken into smaller units, moved through multiple blockchains, and routed via token bridges and swaps to obscure their origin. 

Despite these evasive maneuvers, investigators say the majority of the laundered tokens eventually flowed into service wallets on Binance. That funneling of funds made Binance’s intervention critically important, which only heightened the scrutiny of why the platform acted on only a small portion of the assets identified by police and Upbit.

When questioned by Korean broadcaster KBS, Binance declined to share details about why the freeze was limited or delayed. The exchange said only that it continues to cooperate with authorities “in accordance with appropriate procedures.” That explanation did not ease concerns in South Korea at all. 

Cho Jae-woo, director of Hansung University’s Blockchain Research Institute, said rapid and decisive freezes are essential when it comes to preventing large-scale losses and argued that exchanges sometimes hesitate due to litigation risks. He suggested that the industry should explore the creation of a global emergency hotline or coordinated authority with the power to impose immediate freezes during crisis situations.

The breach also pushed Upbit to implement some of the strictest security measures in the industry. After the hackers stole 44.5 billion won (about $30 million) from the exchange’s Solana hot wallet, operator Dunamu announced that 99% of all customer assets will now be held in cold storage, up from an already high 98.33% at the end of October. Hot wallet exposure is being reduced to nearly zero, which is well beyond South Korea’s legal requirement of 80% cold storage.

Authorities are continuing to investigate the hack, and early intelligence assessments suggest the attack may be linked to North Korea’s Lazarus Group.

New Binance Co-CEO WeChat Account Hijacked

Interestingly, Binance’s newly appointed co-CEO and co-founder Yi He revealed on X that her WeChat account was hijacked after an old mobile number connected to the account was reassigned. She said the account had been abandoned for years and could not initially be recovered, but Binance later confirmed it regained access by working with WeChat’s security team. Blockchain analytics platform Lookonchain reported that the attackers used the compromised account to promote a token called Mubarakah, inflated its price and profited an estimated $55,000.

X post from Yi He

The incident took place just days after Yi He’s elevation to co-CEO, following an announcement by Binance CEO Richard Teng at Binance Blockchain Week in Dubai. It also comes after Tron founder Justin Sun experienced a similar WeChat compromise in November. 

After the latest hack, SlowMist founder Yu Xuan resurfaced a detailed explanation of how WeChat account takeovers can occur, and pointed out that attackers with leaked credentials can seize an account by contacting only two “frequent contacts.” These contacts may include people who were never directly messaged but were added as friends or briefly interacted with in groups. China’s practice of reissuing unused mobile numbers after three months also increases the risk by enabling SIM-linked recovery exploits and social engineering opportunities.

X post from Changpeng Zhao

Xuan advised high-profile crypto figures to avoid adding unknown contacts, rotate passwords regularly, and respond immediately to login alerts. Binance co-founder Changpeng Zhao also reminded users that he has not used WeChat in a long time and warned that he would never promote meme coin contracts there. The warning comes months after BNB Chain’s official X account was hacked and used to post phishing links.

Source: https://coinpaper.com/13074/binance-under-fire-after-freezing-just-17-of-upbit-hack-funds

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

IP Hits $11.75, HYPE Climbs to $55, BlockDAG Surpasses Both with $407M Presale Surge!

IP Hits $11.75, HYPE Climbs to $55, BlockDAG Surpasses Both with $407M Presale Surge!

The post IP Hits $11.75, HYPE Climbs to $55, BlockDAG Surpasses Both with $407M Presale Surge! appeared on BitcoinEthereumNews.com. Crypto News 17 September 2025 | 18:00 Discover why BlockDAG’s upcoming Awakening Testnet launch makes it the best crypto to buy today as Story (IP) price jumps to $11.75 and Hyperliquid hits new highs. Recent crypto market numbers show strength but also some limits. The Story (IP) price jump has been sharp, fueled by big buybacks and speculation, yet critics point out that revenue still lags far behind its valuation. The Hyperliquid (HYPE) price looks solid around the mid-$50s after a new all-time high, but questions remain about sustainability once the hype around USDH proposals cools down. So the obvious question is: why chase coins that are either stretched thin or at risk of retracing when you could back a network that’s already proving itself on the ground? That’s where BlockDAG comes in. While other chains are stuck dealing with validator congestion or outages, BlockDAG’s upcoming Awakening Testnet will be stress-testing its EVM-compatible smart chain with real miners before listing. For anyone looking for the best crypto coin to buy, the choice between waiting on fixes or joining live progress feels like an easy one. BlockDAG: Smart Chain Running Before Launch Ethereum continues to wrestle with gas congestion, and Solana is still known for network freezes, yet BlockDAG is already showing a different picture. Its upcoming Awakening Testnet, set to launch on September 25, isn’t just a demo; it’s a live rollout where the chain’s base protocols are being stress-tested with miners connected globally. EVM compatibility is active, account abstraction is built in, and tools like updated vesting contracts and Stratum integration are already functional. Instead of waiting for fixes like other networks, BlockDAG is proving its infrastructure in real time. What makes this even more important is that the technology is operational before the coin even hits exchanges. That…
Share
BitcoinEthereumNews2025/09/18 00:32