-
South Korean officials suspect North Korea’s Lazarus Group carried out the Upbit hack
-
Upbit revised losses from $36.8 million down to $30.4 million
-
Attack methods resemble Lazarus incidents from past years
-
Hackers likely compromised administrator access rather than servers
-
Stolen funds are being swapped and bridged onchain, investigators say
Authorities Link Upbit Hack to Lazarus Group
South Korean authorities believe Lazarus, the North Korean state-backed hacking group, is behind the recent $30.4 million theft from Upbit. The assessment was reported by Yonhap, citing government and industry sources preparing for an on-site inspection.
Upbit initially reported larger losses but revised the figure as it further analyzed the incident.
Attack Mirrors Lazarus Techniques
Officials said the method resembles Lazarus’ 2019 attack on Upbit, where 342,000 ETH was stolen. Instead of breaching servers directly, the group likely compromised admin accounts or impersonated administrators to approve transfers.
Hackers Move Funds Across Chains
Onchain data shows the attacker wallet converting Solana assets into USDC and bridging funds to Ethereum. The hack occurred shortly after Naver Financial confirmed its plan to acquire Dunamu, Upbit’s parent company.