TLDR
South Koreas Upbit suffered the Solana wallet hack, involving unauthorized outflows from a hot wallet on the Solana network as confirmed by the exchange and media reports (Upbit hack overview).
- Loss size was about $36$38 million across Solana-linked tokens (Finance summary).
- Upbit halted deposits/withdrawals, moved assets to cold storage, and pledged full reimbursement (exchange response).
- Investigators suspect North Korealinked Lazarus Group involvement; probe is ongoing (investigation update).
Deep Dive
1. What Happened
An early-morning breach on 27 Nov moved Solana network assets from Upbits hot wallet to an external address without authorization. Affected tokens included SOL, BONK, USDC, RAY, JUP and others (incident details).
- The exchange reported abnormal withdrawals totaling roughly 54 billion KRW (~$36$37 million) and published addresses linked to the outflow (incident recap).
- Coverage emphasized this was confined to Solana-linked assets and occurred around 4:42 am local time (market coverage).
If you hold Solana ecosystem assets on centralized venues, monitor exchange notices and consider custody diversification to reduce hot?wallet exposure risk.
2. Exchange Response
Upbit suspended deposits and withdrawals for affected Solana assets, shifted funds to cold storage, and coordinated on-chain freezes of some tokens (for example, LAYER) while promising to fully compensate customers from reserve assets (response and reimbursement).
- The exchange shared that user balances will not be reduced, and services would resume after security inspections (customer assurance).
- Reports noted successful freezing of a portion of stolen tokens and ongoing collaboration with projects and authorities (freezing update).
Operationally, expect staged resumption of services; users should watch official updates and confirm any asset?freeze statuses before making transfers.
3. Attribution And Risks
Authorities are investigating and suspect Lazarus Group involvement, echoing tactics from past Korean exchange incidents; timing coincided with Upbits corporate announcements, drawing further scrutiny (probe context).
- Separate coverage highlighted a broader pattern of hot?wallet exploitation and the ongoing risk central to connected wallets on exchanges (broader risk context).
Hot wallets remain a primary attack surface. Using hardware wallets for long?term holdings and minimizing exchange balances during maintenance windows can reduce exposure.
Conclusion
The exchange involved was Upbit, with an estimated $36$38 million in Solana?linked assets siphoned before services were halted and security checks began. Reimbursement commitments and freezing efforts limit user impact, but the incident underscores hot?wallet risk and the value of diversified custody. Confidence: high given multiple independent reports and the exchanges public statements.
