Key Highlights:
  • South Korean officials suspect North Korea’s Lazarus Group carried out the Upbit hack

  • Upbit revised losses from $36.8 million down to $30.4 million

  • Attack methods resemble Lazarus incidents from past years

  • Hackers likely compromised administrator access rather than servers

  • Stolen funds are being swapped and bridged onchain, investigators say

Authorities Link Upbit Hack to Lazarus Group

South Korean authorities believe Lazarus, the North Korean state-backed hacking group, is behind the recent $30.4 million theft from Upbit. The assessment was reported by Yonhap, citing government and industry sources preparing for an on-site inspection.

Upbit initially reported larger losses but revised the figure as it further analyzed the incident.

Attack Mirrors Lazarus Techniques

Officials said the method resembles Lazarus’ 2019 attack on Upbit, where 342,000 ETH was stolen. Instead of breaching servers directly, the group likely compromised admin accounts or impersonated administrators to approve transfers.

Hackers Move Funds Across Chains

Onchain data shows the attacker wallet converting Solana assets into USDC and bridging funds to Ethereum. The hack occurred shortly after Naver Financial confirmed its plan to acquire Dunamu, Upbit’s parent company.

Read the full article on theblock.