Meet the Top 101 in Crypto
Security
Complexity Icon Easy
11 min read

Upbit Hack Timeline: From the $50M Ethereum Heist in 2019 to the $36M Solana Breach in 2025

Published 27 November 2025
Onkar Singh
Authors

Key Takeaways

  • Upbit suffered major breaches in 2019 and 2025, losing over US$80 million in crypto.
  • Both Upbit attacks exploited online wallet exposure, the biggest weakness for exchanges.
  • Upbit covered all losses, but its own reserves and reputation took the hit.
  • Cold wallets, strong authentication, and cautious habits remain the best protection.

Cryptocurrency was built on the promise of financial freedom, but with that freedom comes responsibility.

As global crypto adoption surpasses 500 million users, hackers have followed the money. Exchange breaches, wallet compromises, and social-engineering scams now cost investors billions of dollars every year.

The latest Upbit hot-wallet breach, reported on November 27, 2025, landed exactly six years to the day after the exchange’s 2019 Ethereum heist, where 342,000 ETH were stolen from its hot wallet. The coincidence has not gone unnoticed in the crypto community, prompting debate over how much progress exchanges have really made in safeguarding customer assets.

Industry analysts point out that the recurrence of a major hack on the same date is a chilling reminder that no exchange, regardless of regulation or reputation, is fully immune from sophisticated, well-funded attackers.

Whether you hold $100 or $1 million in digital assets, security must now be a habit, not an afterthought. As one blockchain researcher observed on social media, the Upbit anniversary hack shows that “history doesn’t repeat, it rhymes, especially in crypto.”

This guide breaks down how the 2025 Upbit breach unfolded, which assets were stolen, and the most effective ways to stay ahead of emerging crypto threats in 2025 and beyond.

2019 Ethereum Hot-Wallet Compromise

In late November 2019, Upbit’s internal monitoring flagged an unauthorized withdrawal of 342,000 ETH, worth about $50 million then, from its main operational wallet. Within minutes, the exchange suspended all deposits and withdrawals, moved remaining assets into cold storage, and launched a full-scale forensic audit.

Investigators later tied the theft to North Korean state-linked hacker groups, including Lazarus and Andariel. Authorities concluded that more than half the stolen ETH had been laundered through exchange accounts created with false identities.

Cybersecurity specialists familiar with that investigation said Upbit’s quick shutdown prevented a larger loss. “Most exchanges need hours to detect anomalies in transaction flows,” one expert said. “Upbit caught it within minutes, which shows they had monitoring in place, just not enough isolation for their hot wallet.”

After reimbursing all affected users from corporate reserves, Upbit began a complete overhaul of its infrastructure:

  • Over 90% of assets were moved to cold storage.
  • A new multi-signature system was deployed for all withdrawals.
  • A dedicated incident-response division was established.

Those steps became standard practice across several Korean exchanges in the years that followed.

2025 Solana Hot-Wallet Breach

Exactly six years after the first incident, on November 27, 2025, Upbit reported “irregular transactions” involving several Solana-based tokens, including USDC, BONK, JTO, and SONIC.

Preliminary estimates suggest losses of around ₩54 billion (approximately $36 million), making it one of the largest Solana-network breaches of the year.

Upbit’s Response

In an official statement, Upbit confirmed that:

  • All deposits and withdrawals on the Solana network were suspended pending a full audit.
  • Remaining digital assets were moved to cold storage.
  • The exchange is collaborating with token issuers and on-chain analytics firms to trace the compromised funds.
  • Customers will not bear any losses.

As of late November 2025, authorities and industry experts continue to investigate the method of compromise. No official attribution has been announced.

Which Crypto Assets Were Lost or Affected in Upbit Hacks

2025 Solana-Network Breach (₩54 B / US$ 36–38 Million)

  • Upbit’s latest security incident, reported on November 27, 2025, involved unauthorized withdrawals from its Solana hot wallet. 
  • The total value of the stolen assets is estimated between ₩ 54 billion and ₩ 57 billion, equivalent to roughly US$ 36–38 million based on prevailing token prices.
  • The drained funds included a mix of Solana-based tokens, notably USDC, BONK, JTO, and SONIC, Raydium (RAY), Render (RENDER), Orca (ORCA), and Pyth Network (PYTH).
  • Once the breach was detected, Upbit halted all Solana-network deposits and withdrawals, relocated unaffected tokens to cold storage, and coordinated with token issuers to freeze traceable assets.

Company officials stated that all user balances will be fully reimbursed, with the loss absorbed by the exchange’s operational reserves. While this ensures customers are protected, it represents a significant direct financial hit to Upbit and highlights the persistent exposure of hot wallets to sophisticated attackers.

2019 Ethereum Hot-Wallet Heist (342,000 ETH ≈ ₩ 58 B / US$ 50 Million)

  • The earlier major breach occurred on November 27, 2019, when Upbit confirmed that 342,000 ETH, worth about ₩ 58 billion (US$ 50 million) at the time, was transferred from one of its Ethereum hot wallets to an unauthorized address.
  • Investigators later attributed the theft to North Korea-linked hacker groups, including Lazarus and Andariel, who laundered the funds through numerous wallet chains and exchanges. 
  • Although most of the stolen ETH remains unrecovered, the exchange reimbursed all affected users in full, using corporate reserves to preserve customer trust.

Hot Wallets as a Persistent Weak Point

Every centralized exchange faces the same dilemma: hot wallets enable instant withdrawals but create permanent exposure.

They remain online, connected to blockchain networks, and thus vulnerable to intrusions, leaked credentials, or compromised signing infrastructure.

By contrast, cold wallets, kept offline and often protected by hardware security modules (HSMs) or multi-party computation (MPC), are much harder to attack remotely.

A veteran incident responder based in Seoul said that “hot-wallet management isn’t just about firewalls or key encryption. It’s about minimizing exposure time and maintaining strict operational separation. Most breaches happen because convenience wins over security.”

Why Users Should Care About Crypto Exchange Hacks

Even though crypto exchanges like Upbit have pledged to cover all losses, these repeated breaches highlight a truth every crypto investor must face: exchange convenience comes at the cost of custody control.

When users deposit funds into centralized platforms, they rely entirely on the exchange’s internal security. No matter how reputable or regulated the platform, once private keys sit on its servers, they are no longer yours.

This is why cybersecurity professionals urge retail and institutional traders alike to:

  • Hold long-term assets in self-custody wallets, preferably hardware-based.
  • Enable withdrawal address whitelisting and two-factor authentication on exchange accounts.
  • Keep only trading capital on exchanges and move profits out regularly.
  • Monitor exchange status updates and react quickly to deposit freezes or maintenance notices.

A former security advisor to Korean exchanges summarized it simply: “Exchanges are like banks without deposit insurance. You trust their firewalls instead of federal guarantees. That’s why self-custody isn’t just a preference, it’s risk management.”

Other Major South Korean Exchange Hacks

South Korea’s crypto industry has endured a turbulent history of security breaches long before and after Upbit’s incidents.

Several of the country’s largest exchanges have suffered multimillion-dollar losses, revealing systemic weaknesses in exchange custody and risk management practices.

Bithumb: Repeated High-Value Breaches

Bithumb, once the largest exchange in South Korea by trading volume, has faced multiple cyberattacks over the years, underscoring persistent vulnerabilities even in well-established platforms.

  • July 2017: Attackers compromised the personal data of more than 30,000 users, leading to unauthorized withdrawals from client accounts. The total losses were estimated in the billions of Korean Won, and the breach prompted regulators to tighten oversight of data protection and custodial transparency.
  • June 2018: Bithumb reported another major intrusion resulting in the theft of about US$ 31 million, with XRP making up the bulk of stolen funds. Trading and deposits were temporarily halted while the company strengthened wallet security and network monitoring systems.
  • March 2019: A further attack drained an estimated US$ 20 million in EOS and XRP, which investigators later suggested might have involved internal collusion or compromised insider credentials. The exchange reimbursed affected users and implemented stricter internal-access controls.

Each breach forced Bithumb to rebuild confidence through compensation programs, audits, and new security certifications. Despite these setbacks, it continues to operate under Korea’s Virtual Asset Service Provider (VASP) licensing framework, though with increased scrutiny from the Financial Intelligence Unit.

Coinrail: Mid-Tier Exchange Breach in 2018

In June 2018, Coinrail, a smaller Korean exchange, lost roughly US$ 40 million in various tokens after hackers infiltrated its online wallets.

The attack shook local markets and temporarily drove down cryptocurrency prices globally.

Although Coinrail cooperated with law enforcement and attempted to recover funds, the incident underscored that size and reputation offer little immunity when core wallet systems remain exposed.

Youbit: Collapse After Successive Hacks

Youbit, formerly known as Yapizon, suffered two separate hacks within a year.

The second, in December 2017, proved fatal — resulting in losses so severe that the company filed for bankruptcy. Investigators linked the breaches to suspected North Korean hacking groups, highlighting the geopolitical dimension of crypto thefts in the region.

Youbit’s collapse served as a turning point for South Korean regulators, prompting early discussions about mandatory cold-storage ratios, insurance coverage, and cybersecurity certification for licensed exchanges.

Industry Lessons from South Korean Breaches

Across Bithumb, Coinrail, Youbit, and Upbit, a clear pattern emerges:

  • Hot-wallet exposure remains the most exploited weakness.
  • Insider threats and credential compromise play roles equal to or greater than purely external hacks.
  • Rapid reimbursement and transparency are critical to maintaining public trust after an incident.

These cumulative events spurred the South Korean government to enact tighter Know-Your-Customer (KYC) standards and real-name trading laws, while pushing exchanges toward stronger cold-storage requirements and independent security audits.

Dunamu–Naver Merger Overshadowed by Upbit Hack

The Upbit breach unfolded just as Dunamu, the exchange’s operator, and Naver Financial were preparing to unveil a landmark merger that could reshape South Korea’s fintech landscape.

Both companies plan to merge through a stock-swap deal valued around ₩20 trillion, combining Naver Financial’s dominant payment platform with Dunamu’s leading digital asset exchange. Once finalized, Dunamu will become a subsidiary of Naver Financial, with Naver’s overall stake expected to fall to roughly 17%, while maintaining operational control.

Executives aim to invest ₩10 trillion over five years to strengthen the country’s AI and Web3 ecosystem, positioning the new entity as a global player bridging traditional finance and digital assets.

However, the timing of the ₩54 billion ($36 million) Upbit hack cast a shadow over what was meant to be a milestone announcement. Regulators are now expected to scrutinize the merger closely, focusing on financial stability, shareholder protection, and market concentration risks.

If approved, the deal could become South Korea’s most significant fintech consolidation to date, merging the nation’s largest crypto exchange and top payment platform under one powerful, tech-driven umbrella.

Why Crypto Security Awareness Matters More Than Ever

Blockchain ecosystems are expanding faster than regulators can react. With decentralized apps, NFTs, and new blockchains launching daily, scammers thrive on confusion.

In other words, crypto safety depends less on code and more on behavior. Caution, discipline, and skepticism are your best defenses.

Crypto Security Best Practices

No single security tool can protect against every type of crypto threat. The strongest defense comes from layered security, combining technical safeguards with disciplined personal habits. 

Whether you trade daily or hold long-term, following structured safety protocols can drastically reduce your exposure to theft, scams, and accidental loss:

  • Use hardware or cold wallets for long-term storage – keep private keys completely offline.
  • Enable two-factor authentication (2FA) or hardware security keys for all exchange logins.
  • Whitelist withdrawal addresses so assets can only be sent to preapproved wallets.
  • Never share seed phrases or private keys, even with people claiming to be “support staff.”
  • Download wallets and apps only from verified official sources, not third-party links or ads.
  • Double-check URLs and sender identities before entering any credentials – phishing remains the #1 attack vector.
  • Keep software, firmware, and antivirus tools updated to patch vulnerabilities.
  • Use strong, unique passwords managed through a reputable password manager.
  • Avoid connecting wallets to unknown dApps or signing random smart-contract transactions.
  • Split funds across multiple wallets – separate trading, long-term, and testing balances.
  • Back up recovery phrases securely and offline, ideally in multiple physical locations.
  • Monitor exchange notices and on-chain alerts for any suspicious or paused withdrawals.
  • Reassess security quarterly, adjusting to new threats and technology updates.

Good security in crypto isn’t about paranoia, it’s about preparation.

The more barriers you place between your funds and potential attackers, the less likely you’ll become another victim headline.

FAQs

What’s the safest way to store cryptocurrency?

Hardware wallets or cold storage are considered the safest. They keep private keys offline, where hackers can’t reach them remotely.

Can centralized exchanges be trusted?

Yes, but only for short-term trading. Even regulated exchanges can be hacked. Always withdraw profits to your personal wallet after trading.

How can I spot a crypto scam?

Watch for unsolicited messages, fake investment opportunities, or anyone asking for your private key or seed phrase. No legitimate project or exchange will ever request this.

Is it possible to recover stolen crypto?

Recovery is extremely difficult once assets move across chains or mixers. Immediate reporting to the exchange and blockchain investigators increases the odds, but prevention is far more effective.

Disclaimer: The information provided in this article is for informational purposes only. It is not intended to be, nor should it be construed as, financial advice. We do not make any warranties regarding the completeness, reliability, or accuracy of this information. All investments involve risk, and past performance does not guarantee future results. We recommend consulting a financial advisor before making any investment decisions.
Onkar Singh

Onkar Singh has three years of experience as a digital finance content creator. Throughout his career, he has collaborated with various DeFi projects and crypto media outlets. In his leisure time, he enjoys fitness activities at the gym and watching movies across different genres. Balancing his professional and personal interests, Onkar continues to contribute to the digital finance landscape while pursuing his hobbies.

Survey Icon
Help us improve
1 of 4
Is this your first time here?
What brought you here today?
What are you most interested in?
Would you be interested in:
Thank you icon
Thank you for your feedback!
DMCA.com Protection Status