TLDR
Upbit replaced all deposit addresses and now requires every user to generate new ones before depositing.
- Deposits and withdrawals restarted Dec 1 at 1:00 pm KST in phases as systems cleared security checks (update).
- Crypto sent to old addresses may be lost or significantly delayed, so remove outdated addresses from your wallets (guidance).
- The reset follows a late Nov hack focused on Solana assets, with North Koreas Lazarus group suspected (report).
Deep Dive
1. New Addresses
Every previously issued Upbit deposit address was deleted, and new addresses are required across all assets and networks. This is a platform-wide reset, not limited to a single chain (announcement summary).
before sending funds again, issue a fresh deposit address inside Upbit and update it anywhere you had the old one stored.
2. Phased Resumption and Risks
Upbit resumed deposits and withdrawals on Dec 1 at 1:00 pm KST, progressively re-enabling assets as each network passed upgraded wallet security checks (timeline). Upbit warned that transfers to old addresses can be permanently lost or require manual recovery, causing significant delays. Users were told to delete outdated addresses in external wallets to avoid misdirected deposits (exchange guidance).
3. Why It Changed
The overhaul followed an unauthorized outflow on Nov 27 that targeted Solana ecosystem tokens. Upbit paused all movements, moved funds to cold storage, worked with issuers to freeze assets on-chain, and pledged full reimbursement from corporate reserves. Investigators suspect Lazarus involvement, echoing a prior 2019 incident, and Upbit has implemented deeper audits and stricter access controls (incident recap).
Conclusion
Upbits deposit flow changed from reuse your address to regenerate a new address for every asset and network after a security breach. The phased reopen aims to restore normal operations while reducing repeat risk. The practical takeaway is simple: only use newly generated Upbit addresses and confirm that a given assets network has been re-enabled before sending.
