Criptor

An RSS reader for cryptocurrency news

About
BeInCryptoBeInCryptoBitcoin MagazineBitcoin MagazineCrypto PotatoCrypto PotatoCrypto SlateCrypto SlateThe DefiantThe DefiantForkastForkastProtosProtos
Browse all

Criptor

Your comprehensive RSS reader for all things cryptocurrency. Stay updated with the latest news from around the globe.

Quick Links

  • About
  • Privacy Policy
  • Terms of Service
  • Cookie Policy

Resources

  • Disclaimer
  • Blog
  • Help Center
  • Contact

© 2025 Criptor. All rights reserved.

Built with ♥ for crypto enthusiasts

Home›Protos›Upbit uncovers private key vulnerability after $30M hack
Protos

Protos

Original publisher

Share:

Upbit uncovers private key vulnerability after $30M hack

November 28, 2025
3 min read
Upbit uncovers private key vulnerability after $30M hack

South Korean crypto exchange Upbit says that there is “no excuse” for the “inadequate security management” that has led to a serious private key vulnerability on its platform.

Oh Kyung-seok, the CEO of Upbit’s parent company, Dunamu, issued a statement today that claimed the vulnerability, which could allow would-be hackers to guess another user’s private keys, was discovered during its analysis of public Upbit wallet transactions on the blockchain.

Translated from Korean using DeepL, Oh apologized for the 44.5 billion Won ($30 million) theft from the firm’s Solana hot wallet, saying, “This intrusion incident resulted from inadequate security management at Upbit, and there is no excuse for this.”

Upbit says attackers might have inferred private keys by analyzing user wallet address patterns. If true, I doubt anyone other than North Korean hackers (Lazarus) could do this. pic.twitter.com/cS4I8okrVb

— Ki Young Ju (@ki_young_ju) November 28, 2025
CryptoQuant CEO Ki Young Ju thinks Lazarus might be the culprit of Upbit’s hack.

Read more: The solution to crypto’s Lazarus problem could be simpler than expected

The CEO revealed that 38.6 billion Won ($26.2 million) consisted of “member losses” and that 2.3 billion Won was frozen. Oh also claimed that the other 5.9 billion Won ($4 million) was made up of company losses. 

Oh’s statement claims that Upbit was able to address the private key estimation vulnerability and also fully reimburse user losses with Upbit’s remaining reserves.

“To protect member assets, Upbit has suspended digital asset deposits and withdrawals, is tracking digital assets moved outside of Upbit, and is taking freezing measures,” it claimed. 

Lazarus suspected of private key exploit

South Korean news outlet Yonhap News reported that authorities suspect the hack was the result of North Korea’s Lazarus Group, and that an on-site investigation at Upbit is underway. 

Upbit was previosuly targeted by the group six years ago when it stole $50 million worth of ether in 2019. 

The crypto exchange said today that “Upbit has consistently strived to safeguard member assets, but this incident has once again made us realize that there is no such thing as perfect security preparedness.”

Upbit suffers ‘abnormal withdrawals’ of $30M on 6th anniversary of Lazarus hack

Read more: OpenAI, CoinTracker user data leaked after third-party hacked via SMS

Crypto security firm CertiK has warned in a report this year about the potential for hackers to predict, or even reconstruct, the private keys of crypto wallets. 

It highlights how the private key generator Profanity could be exploited via a brute force attack, and was likely the source of a private key leak that led to the $160 million hack of the market maker Wintermute.  

Because Profanity’s address generator only has “2^32 possible initial key pairs and each iteration is reversible, attackers could recover any Profanity-generated private key from its corresponding public key,” CertiK claimed.

Got a tip? Send us an email securely via Protos Leaks. For more informed news, follow us on X, Bluesky, and Google News, or subscribe to our YouTube channel.

The post Upbit uncovers private key vulnerability after $30M hack appeared first on Protos.

RELATED TOPICS

exchange upbitupbit excusesecurityvulnerabilityhackkey vulnerabilitycrypto exchangekeynewshack readsouth koreanlazaruscryptoprotoskoreankorean cryptocriptorprivateupbitsecurity managementprivate keyinadequate security

More From Protos

Cathie Wood falls for AI slop despite heavy OpenAI, Tempus bets

Cathie Wood falls for AI slop despite heavy OpenAI, Tempus bets

12 hours ago

The family affairs shaping Tether’s $180B empire

The family affairs shaping Tether’s $180B empire

3 days ago

Active Solana DEX traders down 79% year-to-date

Active Solana DEX traders down 79% year-to-date

2 days ago

View All Articles

Market Overview

BitcoinBitcoin
85,645.60.151%
EthereumEthereum
2,835.980.262%
Binance CoinBinance Coin
826.7-0.407%
RippleRipple
1.7945-0.725%
SolanaSolana
118.97-0.527%

You May Also Like

Is an AI hacker targeting old DeFi projects in $5M spree?
Protos

Is an AI hacker targeting old DeFi projects in $5M spree?

8 hours ago
Tons of tax docs awaiting Visa card issuers settling in USDC
Protos

Tons of tax docs awaiting Visa card issuers settling in USDC

2 days ago
Ex-Alameda CEO Caroline Ellison leaves federal prison after 11 months
Protos

Ex-Alameda CEO Caroline Ellison leaves federal prison after 11 months

1 day ago
The three people who could really get Samourai devs pardoned
Protos

The three people who could really get Samourai devs pardoned

2 days ago