Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnSquareMore
Ethereum Updates: Lazarus Group's Cross-Chain Theft Reveals Vulnerabilities in Crypto Exchanges

Ethereum Updates: Lazarus Group's Cross-Chain Theft Reveals Vulnerabilities in Crypto Exchanges

Bitget-RWA2025/11/28 08:36
By:Bitget-RWA

- South Korean authorities attribute Upbit's $30M hack to North Korea's Lazarus Group, using multi-chain laundering via Solana and Ethereum . - Attack mirrored 2019 incident, targeting admin accounts, intensifying scrutiny of Dunamu’s $35.2B fine and merger with Naver. - Hack occurred during Dunamu-Naver merger announcement, raising suspicions of disruption intent, aligning with Lazarus’s geopolitical tactics. - North Korea’s sanctions-driven cyberattacks highlight global risks as Lazarus evolves tactics,

Upbit Crypto Exchange Hack Attributed to North Korea’s Lazarus Group

South Korean officials have traced the recent $30 million cyberattack on the cryptocurrency platform Upbit to the Lazarus Group, a notorious hacking collective associated with North Korea’s intelligence services. The incident, which took place on November 27, involved sophisticated laundering strategies that spanned multiple blockchains.

Attackers utilized both Solana and Ethereum networks to move the stolen funds, quickly distributing assets across 185 different wallets and converting them into ETH within a matter of hours. This approach closely resembled tactics seen in a 2019 Upbit breach, where 342,000 ETH were stolen, further reinforcing suspicions about Lazarus’s involvement. Authorities believe the hackers likely gained access by compromising or impersonating administrator accounts, rather than breaching the servers directly—a method consistent with previous Lazarus operations.

The breach has led to increased regulatory pressure on Dunamu, Upbit’s parent company, which is now facing a record penalty of 35.2 billion won due to delayed incident reporting and issues with data management. The hack also casts uncertainty over Dunamu’s $10.3 billion merger with Naver, announced on the same day as the attack. Regulatory bodies have suspended license renewals for major Korean exchanges for over a year, adding to Dunamu’s challenges. In response, Upbit has promised to fully reimburse affected customers, temporarily halted Solana network transactions, and transferred 70% of its assets to cold storage to enhance security.

Blockchain analysis has highlighted the complexity of the operation. The perpetrators bridged stolen assets from Solana to Ethereum using tokens and liquidity pools on platforms such as Allbridge. While the rapid movement of funds left some traces, the cross-chain mixing made tracking the assets more difficult. The Financial Services Commission has now designated user transaction data as sensitive under the Credit Information Act, intensifying its investigation into Upbit’s security protocols.

Upbit Hack Investigation

Merger Disruption and Strategic Timing

The timing of the hack has drawn attention, coinciding with the announcement of the Dunamu-Naver merger—a move intended to strengthen South Korea’s cryptocurrency sector. Some analysts suggest the attack was deliberately timed to undermine the merger, with the hackers possibly aiming to make a statement during a major industry event. This theory aligns with the Lazarus Group’s history of targeting vital economic infrastructure, especially during periods of heightened geopolitical tension.

Broader Implications and Ongoing Investigations

North Korea’s dependence on cybercrime to generate foreign currency provides further context for the breach. Facing stringent international sanctions, the country’s hacking units have increasingly targeted digital assets, with Lazarus previously implicated in significant thefts both in South Korea and worldwide. In response to the Upbit incident, the Korea Internet & Security Agency (KISA) and financial regulators have launched urgent inspections, highlighting the seriousness of the situation.

As the investigation unfolds, the breach exposes ongoing vulnerabilities in the security and oversight of cryptocurrency exchanges. Upbit’s repeated security failures—in both 2019 and 2025—raise concerns about the effectiveness of protections for hot wallets and cross-chain transactions. Meanwhile, the Lazarus Group’s evolving techniques, particularly their rapid multi-chain laundering, continue to pose a significant risk to the global digital asset ecosystem.

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

Silver Soars Amid Ideal Conditions of Policy Shifts and Tightening Supply

- Silver surged to $52.37/oz as Fed rate cut expectations (80% probability) and falling U.S. Treasury yields boosted demand for non-yielding assets. - China's record 660-ton silver exports and 2015-low Shanghai warehouse inventories intensified global supply constraints, pushing the market into backwardation. - Geopolitical risks (Ukraine war) and potential U.S. silver tariffs added volatility, while improved U.S.-China relations eased short-term trade concerns. - Prices face critical $52.50 resistance; Fe

Bitget-RWA2025/11/28 20:32

XRP News Today: As XRP Declines, Retail Investors Turn to GeeFi's Practical Uses

- GeeFi's presale hits 80% of Phase 1 goal with $350K raised, targeting 3,900% price growth as XRP declines 20% monthly. - GEE's utility-driven features like crypto cards, multi-chain support, and 55% staking returns contrast with XRP's institutional dependency and shrinking retail base. - Deflationary tokenomics and 5% referral bonuses drive FOMO, positioning GeeFi as a 2026 crypto disruptor amid XRP's regulatory and adoption challenges.

Bitget-RWA2025/11/28 20:32
XRP News Today: As XRP Declines, Retail Investors Turn to GeeFi's Practical Uses

Sloppy implementation derails MegaETH's billion-dollar stablecoin aspirations

- MegaETH abandoned its $1B USDm stablecoin pre-deposit plan after technical failures disrupted the launch, freezing deposits at $500M and issuing refunds. - A misconfigured Safe multisig transaction allowed early deposits, causing $400M inflows before the team scrapped the target, citing "sloppy execution" and operational misalignment. - Critics highlighted governance flaws, uneven access (79 wallets >$1M vs. 2,643 <$5K deposits), and 259 duplicate addresses, raising concerns about transparency and bot ac

Bitget-RWA2025/11/28 20:32
Sloppy implementation derails MegaETH's billion-dollar stablecoin aspirations

XRP News Today: Institutional ETFs Drive XRP's Phase 4 Surge, Targeting a Break Above $2.60

- XRP enters Phase 4 of its multi-year cycle, mirroring 2014–2017 patterns with $2.00 retest and $6.618 target potential. - Six new XRP ETFs (Franklin Templeton, Grayscale) boost institutional demand, though performance varies significantly between products. - Technical analysis highlights $2.05–$2.07 support and $2.20 resistance, with $2.60 breakout critical for confirming Phase 4 bullish thesis. - Macroeconomic factors like Fed rate cuts and improved U.S.-China relations could reduce risk aversion, ampli

Bitget-RWA2025/11/28 20:32
XRP News Today: Institutional ETFs Drive XRP's Phase 4 Surge, Targeting a Break Above $2.60