South Korean regulators and analysts are dissecting Binance reaction to the Upbit hack as they hunt for better global protections against fast-moving crypto theftsSouth Korean regulators and analysts are dissecting Binance reaction to the Upbit hack as they hunt for better global protections against fast-moving crypto thefts

Korean scrutiny intensifies over Binance role in the Upbit hack fund freeze

2025/12/12 15:59
upbit hack

South Korean regulators and analysts are dissecting Binance reaction to the Upbit hack as they hunt for better global protections against fast-moving crypto thefts.

Binance froze only a fraction of Upbit hack funds

According to investigators, only 17% of the assets flagged for freezing by Upbit and police were actually locked down, local media reported on Friday. Moreover, security analysts said the hacking group executed an elaborate laundering strategy on the morning of November 27, rapidly scattering the stolen assets through more than a thousand wallets.

The attackers repeatedly broke the funds into smaller portions and moved them through multiple chains. They also relied on token bridges and swaps to obscure their on-chain trail. However, authorities said most of the laundered assets eventually landed in service wallets on Binance, underscoring the pivotal role of large centralized exchanges in incident response.

Upbit and police requested an immediate freeze on roughly 470 million won (about $370,000) worth of Solana confirmed to have reached the exchange. That said, Binance froze only 80 million won (about $75,000), saying it required additional verification before imposing wider restrictions on the funds.

The limited action was confirmed around midnight on the day of the incident, approximately 15 hours after the original request. When questioned by Korean broadcaster KBS about the narrow scope and delay in the freeze, Binance declined to address specifics, citing its policy on active investigations. The company said only that it “continues to cooperate with the relevant authorities and partners in accordance with appropriate procedures,” a statement that left many details unanswered.

Binance Experts call for faster, coordinated global freeze mechanisms

That explanation has not satisfied several experts in South Korea. Cho Jae-woo, director of Hansung University‘s Blockchain Research Institute, argued that rapid intervention is essential to minimize user losses in attacks of this scale. To prevent damage from hacking, he said, a swift initial freeze is vital, yet exchanges often cite litigation risks as a reason for hesitating.

Moreover, Cho suggested that the industry should explore establishing a global emergency hotline between exchanges or a coordinated body empowered to impose immediate freezes in crisis situations. In this context, he said a more standardized binance freeze response and similar protocols at other platforms could significantly limit the damage from future cross-chain exploits.

Investigators say most of the stolen assets have since been converted from Solana to Ethereum. According to their analysis, this shift was likely aimed at improving liquidity, given Ethereum’s deeper markets and the broader availability of trading venues for the asset.

Railgun privacy tools and laundering across chains

On-chain analysts tracking the upbit hack have highlighted the use of Railgun, a privacy-focused smart contract system. One widely shared post noted that “The Upbit hacker is laundering funds through Railgun and has passed their ‘ZK proof of innocence'” and described the mechanism as an automated system that checks whether an address belongs to a good actor using multiple forensic data providers.

However, the same commentary added that users can rely on Railgun’s explorer to verify addresses, illustrating how privacy tools, zero-knowledge proofs and compliance layers can coexist in a complex way. That said, the incident also underscores how railgun zk laundering and similar tools can complicate enforcement when funds move rapidly between chains and mixers.

Security researchers say the hackers’ tactics, including laundering across chains, token swaps, and bridge hops, made timely freezing even more critical. Moreover, they argue that without better coordination among major exchanges, tracing Solana stolen funds tracking after they hit high-liquidity hubs like Binance or other venues will remain challenging.

Upbit’s cold storage overhaul after 44.5 billion won theft

As previously reported, Upbit is shifting nearly all customer assets into cold storage after hackers stole 44.5 billion won (about $30 million) from its Solana hot wallet. The breach prompted one of the strongest security responses yet by a major exchange, with operator Dunamu accelerating a comprehensive custody overhaul.

Dunamu said the platform will raise its cold wallet ratio to 99% and reduce hot wallet exposure to effectively zero. Moreover, this goes far beyond South Korea‘s legal requirement that 80% of user funds be stored offline, positioning Upbit’s model as one of the most conservative in the domestic market.

The exchange already held 98.33% of assets in cold storage at the end of October, the highest among local platforms. However, the breach pushed management to move even closer to a fully cold-based system. In practical terms, this large upbit cold storage move is designed to sharply limit the amount of crypto accessible to online attackers at any given time.

Upbit hack investigations, Binance, and Lazarus Group suspicions

Meanwhile, South Korean authorities have launched a formal investigation into the upbit exchange hack. Local reports have cited early intelligence assessments that allegedly connect the intrusion to North Korea‘s Lazarus Group, a cybercrime organization already linked to several major crypto thefts in recent years.

However, officials have not yet released definitive public evidence supporting the lazarus group allegations. Investigators are continuing to track fund flows on Solana and Ethereum, including transfers through privacy tools, as they attempt to build a more complete picture of the operation and its ultimate beneficiaries.

In summary, the Upbit incident has exposed critical gaps in global exchange coordination, from delayed freezes to limited cross-chain monitoring. As regulators, exchanges and researchers study the fallout, pressure is mounting for more agile international mechanisms that can halt stolen funds in minutes, not hours, when the next large-scale crypto attack occurs.

Sorumluluk Reddi: Bu sitede yeniden yayınlanan makaleler, halka açık platformlardan alınmıştır ve yalnızca bilgilendirme amaçlıdır. MEXC'nin görüşlerini yansıtmayabilir. Tüm hakları telif sahiplerine aittir. Herhangi bir içeriğin üçüncü taraf haklarını ihlal ettiğini düşünüyorsanız, kaldırılması için lütfen [email protected] ile iletişime geçin. MEXC, içeriğin doğruluğu, eksiksizliği veya güncelliği konusunda hiçbir garanti vermez ve sağlanan bilgilere dayalı olarak alınan herhangi bir eylemden sorumlu değildir. İçerik, finansal, yasal veya diğer profesyonel tavsiye niteliğinde değildir ve MEXC tarafından bir tavsiye veya onay olarak değerlendirilmemelidir.

Ayrıca Şunları da Beğenebilirsiniz

U.S. Court Finds Pastor Found Guilty in $3M Crypto Scam

U.S. Court Finds Pastor Found Guilty in $3M Crypto Scam

The post U.S. Court Finds Pastor Found Guilty in $3M Crypto Scam appeared on BitcoinEthereumNews.com. Crime 18 September 2025 | 04:05 A Colorado judge has brought closure to one of the state’s most unusual cryptocurrency scandals, declaring INDXcoin to be a fraudulent operation and ordering its founders, Denver pastor Eli Regalado and his wife Kaitlyn, to repay $3.34 million. The ruling, issued by District Court Judge Heidi L. Kutcher, came nearly two years after the couple persuaded hundreds of people to invest in their token, promising safety and abundance through a Christian-branded platform called the Kingdom Wealth Exchange. The scheme ran between June 2022 and April 2023 and drew in more than 300 participants, many of them members of local church networks. Marketing materials portrayed INDXcoin as a low-risk gateway to prosperity, yet the project unraveled almost immediately. The exchange itself collapsed within 24 hours of launch, wiping out investors’ money. Despite this failure—and despite an auditor’s damning review that gave the system a “0 out of 10” for security—the Regalados kept presenting it as a solid opportunity. Colorado regulators argued that the couple’s faith-based appeal was central to the fraud. Securities Commissioner Tung Chan said the Regalados “dressed an old scam in new technology” and used their standing within the Christian community to convince people who had little knowledge of crypto. For him, the case illustrates how modern digital assets can be exploited to replicate classic Ponzi-style tactics under a different name. Court filings revealed where much of the money ended up: luxury goods, vacations, jewelry, a Range Rover, high-end clothing, and even dental procedures. In a video that drew worldwide attention earlier this year, Eli Regalado admitted the funds had been spent, explaining that a portion went to taxes while the remainder was used for a home renovation he claimed was divinely inspired. The judgment not only confirms that INDXcoin qualifies as a…
Paylaş
BitcoinEthereumNews2025/09/18 09:14
How to earn from cloud mining: IeByte’s upgraded auto-cloud mining platform unlocks genuine passive earnings

How to earn from cloud mining: IeByte’s upgraded auto-cloud mining platform unlocks genuine passive earnings

The post How to earn from cloud mining: IeByte’s upgraded auto-cloud mining platform unlocks genuine passive earnings appeared on BitcoinEthereumNews.com. contributor Posted: September 17, 2025 As digital assets continue to reshape global finance, cloud mining has become one of the most effective ways for investors to generate stable passive income. Addressing the growing demand for simplicity, security, and profitability, IeByte has officially upgraded its fully automated cloud mining platform, empowering both beginners and experienced investors to earn Bitcoin, Dogecoin, and other mainstream cryptocurrencies without the need for hardware or technical expertise. Why cloud mining in 2025? Traditional crypto mining requires expensive hardware, high electricity costs, and constant maintenance. In 2025, with blockchain networks becoming more competitive, these barriers have grown even higher. Cloud mining solves this by allowing users to lease professional mining power remotely, eliminating the upfront costs and complexity. IeByte stands at the forefront of this transformation, offering investors a transparent and seamless path to daily earnings. IeByte’s upgraded auto-cloud mining platform With its latest upgrade, IeByte introduces: Full Automation: Mining contracts can be activated in just one click, with all processes handled by IeByte’s servers. Enhanced Security: Bank-grade encryption, cold wallets, and real-time monitoring protect every transaction. Scalable Options: From starter packages to high-level investment contracts, investors can choose the plan that matches their goals. Global Reach: Already trusted by users in over 100 countries. Mining contracts for 2025 IeByte offers a wide range of contracts tailored for every investor level. From entry-level plans with daily returns to premium high-yield packages, the platform ensures maximum accessibility. Contract Type Duration Price Daily Reward Total Earnings (Principal + Profit) Starter Contract 1 Day $200 $6 $200 + $6 + $10 bonus Bronze Basic Contract 2 Days $500 $13.5 $500 + $27 Bronze Basic Contract 3 Days $1,200 $36 $1,200 + $108 Silver Advanced Contract 1 Day $5,000 $175 $5,000 + $175 Silver Advanced Contract 2 Days $8,000 $320 $8,000 + $640 Silver…
Paylaş
BitcoinEthereumNews2025/09/17 23:48