TLDR
Upbit responded to the late?November hack by moving about 99% of user assets to cold wallets, cutting hot wallet exposure to near zero, upgrading its wallet system, and launching on?chain recovery efforts after the incident.
- Cold storage raised to 99%, exceeding Koreas 80% minimum, with hot wallet use effectively 0% per the update.
- Deposits/withdrawals were paused, the wallet system rebuilt, and an OTS tracker froze $1.77 million; users were reimbursed from corporate reserves as reported.
- Compliance moves followed, including a temporary suspension of a KYC verification method while regulators push stricter liability rules per a report.
Deep Dive
1. Wallet Architecture
Upbit shifted nearly all customer funds to offline custody, raising its cold wallet ratio to 99% and driving hot wallet exposure toward 0%, a posture well above the local 80% requirement and aimed at minimizing online attack surface confirmed in the notice.
This followed the Solana?linked hot wallet breach of around $3036 million and included a broader wallet infrastructure review to tighten procedures before resuming normal service as detailed.
Security first. Expect stronger protection against online compromises, with a trade?off of potentially slower withdrawals during stress if nearly all funds sit offline.
2. Recovery Actions
Operationally, Upbit paused deposits and withdrawals, rebuilt wallet systems, and committed to cover user losses from corporate reserves. It deployed an On?chain Tracking Service (OTS) to trace flows and blacklist compromised addresses, freezing $1.77 million with help from partner exchanges documented here.
Upbit also launched a 10% recovery bounty to incentivize exchanges and investigators to help track and freeze stolen assets, with services restored after security upgrades outlined in this update.
Fast containment and reimbursement reduce user impact. The bounty and OTS coordination can accelerate asset freezing across venues, limiting attacker options.
3. Compliance Moves
Separately from the hack fix, Upbit temporarily suspended a resident?card KYC verification method under regulatory scrutiny, while broader policy changes are advancing (including proposed no?fault liability and fines up to 3% of revenue) that could further shape exchange practices reported here and in a policy summary here.
These measures signal a tightening compliance posture and a regulatory push to bank?level standards for consumer protection following repeated exchange incidents in Korea.
Expect stricter onboarding and liability frameworks. Exchanges may hold more capital, increase offline ratios, and harden custody and reporting to meet rules.
Conclusion
Upbits post?hack changes center on defense in depth: near?total cold storage, rebuilt wallets, coordinated on?chain recovery, and user reimbursement. The immediate effect is lower online risk; the trade?off is potential withdrawal friction in stress. With regulators pressing no?fault compensation and higher penalties, operational and compliance standards in Korea are likely to rise, pushing exchanges toward bank?level security and liability practices.
