Blockchain AcademicsBlockchain Academics
A High-Stakes Breach Rekindles Old Fears as Upbit Faces a $37 Million Solana Heist

A High-Stakes Breach Rekindles Old Fears as Upbit Faces a $37 Million Solana Heist

Upbit faces a $37M Solana hack, reigniting security concerns and prompting a full freeze on transactions.

Blockchain Academics NewsroomNovember 27, 20253 min read
Share

South Korea’s largest digital-asset platform is once again confronting the uncomfortable intersection of crypto innovation and geopolitical tension. Upbit, a dominant force in Asia’s exchange landscape, confirmed that roughly $37 million in Solana-linked assets vanished in an unauthorized transfer early Thursday morning, prompting the company to freeze all deposits and withdrawals as investigators worked to contain the damage.

The breach unfolded around 4:42 a.m., when assets amounting to about 44.5 billion Korean won were shifted into a wallet not controlled by the exchange. Oh Kyoung-suk, the CEO of Dunamu, Upbit’s parent company, acknowledged the incident almost immediately, emphasizing that the platform had launched a full-scale internal inquiry to prevent further losses and to safeguard customer holdings. He noted that Upbit would absorb the financial hit itself, ensuring users remain economically unharmed.

Although unauthorized transactions are not unusual in the global crypto market, the scope and timing of this attack have raised particular alarm. According to early reports, 24 tokens were affected, including Solana and Official Trump–branded assets. Upbit responded by rapidly migrating all remaining funds into cold storage, a move designed to isolate vulnerable assets from online exposure. The company also notified state regulators and the Korea Internet & Security Agency, signaling a coordinated response that goes beyond routine security protocol.

For Upbit, the incident reopens a chapter the exchange had worked hard to put behind it. Not since late 2019 had the platform faced a breach of comparable scale. That earlier attack—on the same calendar date six years prior—resulted in the theft of 342,000 Ethereum and was attributed to North Korean–linked cyber groups, including the notorious Lazarus Group. This year’s intrusion, arriving on the anniversary of that episode and coinciding with Dunamu’s merger ceremony with Naver Financial, has fueled speculation that a similarly sophisticated actor may be involved. Local cybersecurity analysts argue that Upbit’s defenses already surpass those of most financial institutions in the country, a fact that underscores the precision and advanced capabilities required to penetrate its systems.

Despite the magnitude of the breach, Solana’s market reaction was mild. SOL dipped only about 1.2 percent in the hours following the incident and continued trading near $142.6, maintaining a broader 24-hour gain. Tokens across the Solana ecosystem, from RENDER to BONK, saw slightly sharper intraday declines, but none indicated a crisis of confidence.

What the episode does expose, however, is the persistent vulnerability of hot-wallet infrastructure even in the industry’s most well-funded exchanges. As institutional capital flows deeper into crypto markets, the event serves as a reminder that robust security frameworks and proactive regulatory supervision remain indispensable pillars of digital-asset stability. For Upbit, the coming days may determine whether this incident becomes a temporary setback or a catalyst for structural change in how major platforms guard the digital wealth entrusted to them.

Discussion

Loading comments...