Upbit Hack
What happened
Upbit detected unauthorized Solana-network hot-wallet withdrawals at 04:42 KST on 27 November 2025, equivalent to 19:42 UTC on 26 November. The exchange revised the estimated loss from ₩54 billion to ₩44.5 billion, approximately $30 million, after adjusting its asset valuation. The incident affected exchange custody rather than the Solana network itself.
Unauthorized hot-wallet withdrawals are established. A potentially key-exposing wallet flaw was reported during the subsequent review, but its causal connection to this incident remains unconfirmed. A specific signature attack, malware infection or attacker attribution should not be presented as proven.
How it happened
- Upbit detected abnormal Solana-network withdrawals and suspended relevant transfers while securing remaining assets.
- Its revised assessment separated approximately ₩38.6 billion in customer assets from the exchange's own exposure. Upbit said it would cover customer losses using its reserves.
- Upbit reported approximately ₩2.3 billion frozen during the response. Frozen assets are not the same as completed recoveries or customer repayments.
- On 28 November, reporting on Upbit's emergency review described a wallet flaw that could expose private keys. Upbit reported fixing the issue, but did not confirm that this was the mechanism used in the theft.
Protocol details
Post-Incident Timeline
-
2025-11-28
Upbit reported approximately ₩2.3 billion in LAYER tokens frozen during the response. Freezing restricts movement; it does not establish that those assets were returned to the exchange.
Evidence
- report @layerggofficial incident report x.com
- report @PeckShieldAlert incident report x.com
- analysis Website reference beincrypto.com
- analysis Website reference upbit.com
- analysis DeFiLlama defillama.com
- analysis Scorechain: Upbit Solana hot-wallet outflows scorechain.com
- analysis The Block: Upbit's emergency wallet review and revised loss theblock.co
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.