🔥 Trade with Pros on Discord → 21 Days Free (No Card)JOIN FREE

Upbit wipes old deposit addresses to boost wallet security

In this post:

  • Upbit deleted old deposit addresses and required users to generate new ones for safety.
  • The exchange suspended services after hackers withdrew around 54 billion Korean won ($36.8 million) in Solana-based assets on November 27.
  • Investigators linked the breach to North Korea’s Lazarus Group, which has been responsible for numerous major hacks.

Today, South Korean crypto exchange Upbit announced that it has deleted old deposit addresses as part of wallet maintenance and security improvements. Upbit revealed that users must create new addresses before making a deposit. 

The exchange warned that if users use the existing addresses, it might take longer for the deposits to be reflected.

Upbit announced that, starting on December 5 at 17:00 KST, deposits and withdrawals for 33 assets across 21 networks will be progressively resumed. The exchange emphasized that deposits and withdrawals will be made sequentially following the reinstatement of deposit and withdrawal services, beginning with network digital assets whose security has been verified.

Upbit implements new measures after Solana exploit

Upbit claimed that new deposit addresses are needed for all digital assets due to security vulnerability improvements. Deposits and withdrawals of digital assets that were suspended for various reasons prior to the inspection may remain suspended until the issue is resolved.

The exchange stated that once the target service’s stability has been verified, any staking requests, NFT deposits, and withdrawals supported by the network or digital asset will be resumed.

As previously reported by Cryptopolitan, the platform initially suspended all its services on November 27 due to a security breach that resulted in the unauthorized withdrawal of approximately 54 billion Korean won ($36.8 million). The attackers stole SOL, USDC, and more than 20 other Solana-based tokens like BONK, JUP, RAY, ORCA, RENDER, PYTH, and TRUMP.

See also  This small Kansas town lost millions to a crypto scam, still can't recover

The incident took place the day after Naver Financial announced that it would acquire Dunamu, the parent company of Upbit, for 15.1 trillion won ($10.3 billion) in an all-stock merger that was scheduled to be finalized in June 2026.

To prevent any losses, Upbit promptly suspended all deposits and withdrawals on its platform and transferred any remaining assets to cold storage. In addition to successfully freezing $8.18 million worth of LAYER tokens, the exchange continues to collaborate with authorities and projects to freeze further stolen funds.

Oh Kyung-seok, CEO of Upbit, stated that the exchange will use its own reserves to cover the whole sum, guaranteeing that no customer would suffer personal losses.

North Korean Lazarus group linked to Upbit hacks

Upbit has been hacked before. In 2019, the Lazarus Group was suspected of stealing 58 billion won worth of Ethereum from Upbit. A further inquiry came to the tentative conclusion that the Lazarus Group and other North Korean state-backed units were responsible for the attack.

Notably, the recent breach happened on November 27, the same day as the 2019 hack. 

According to South Korean government officials, the hackers either gained access to administrator accounts or impersonated administrators to approve the transfers. Blockchain analysis reveals that the hacker’s wallet converted Solana to USDC before bridging the cash to the Ethereum network, in what appears to be an effort to conceal the trail.

See also  Polkadot price analysis: DOT heads towards $32 resistance with 8 percent surge

Immunefi, a blockchain security platform, revealed that Lazarus was responsible for more than $300 million in losses from cryptocurrency hacking incidents in 2023, accounting for 17.6% of all losses.

Over the past decade, the Lazarus Group has been responsible for some of the largest hacks, particularly in the rapidly growing cryptocurrency sector. According to Immunefi, Lazarus began focusing on cryptocurrency protocols after initially gaining notoriety for its 2014 cyberattack on Sony Pictures. 

In March 2023, the Lazarus hacked Ronin Network, a bridge utilized by the well-known Web3 game Axie Infinity, and stole around  $600 million. Lazarus also conducted the cyber heist on the Central Bank of Bangladesh in 2016, resulting in $81 million in losses.

According to blockchain analysis company Elliptic, hackers employed by the North Korean government have taken over $2 billion in cryptocurrency so far this year.

On October 7, Elliptic published a blog post with new forecasts, stating that the firm’s data “shows the largest annual total on record, with three months still to go,” and is based on more than 30 hacks in 2025.

Sharpen your strategy with mentorship + daily ideas - 30 days free access to our trading program

Share link:

Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

Most read

Loading Most Read articles...

Stay on top of crypto news, get daily updates in your inbox

Editor's choice

Loading Editor's Choice articles...

- The Crypto newsletter that keeps you ahead -

Markets move fast.

We move faster.

Subscribe to Cryptopolitan Daily and get timely, sharp, and relevant crypto insights straight to your inbox.

Join now and
never miss a move.

Get in. Get the facts.
Get ahead.

Subscribe to CryptoPolitan