Top

Upbit suffers $30M breach, overshadowing Dunamu’s major merger announcement

Markets·November 28, 2025, 2:27 AM

South Korea’s largest crypto exchange, Upbit, suffered a security breach on Nov. 27 that resulted in the theft of 44.5 billion won ($30.4 million) in digital assets, all taken from the exchange’s hot wallets. The stolen tokens were all Solana-based, and Upbit CEO Oh Kyoung-suk said in a statement that no users will incur losses, as the company will cover the full amount with its own reserves.

https://asset.coinness.com/en/news/070b84bbeb9f3292d29e545818df0769.webp
Photo by FlyD on Unsplash

Hot-wallet breach hits 24 tokens

The exchange said in a statement that the compromised tokens were transferred to an unknown external wallet at around 7:42 p.m. UTC on Nov. 26. In total, 24 cryptocurrencies were affected, all within the Solana ecosystem. The stolen assets ranged from infrastructure tokens such as Solana (SOL) to staking-related assets like Jito (JTO), along with the stablecoin USD Coin (USDC) and memecoins including Bonk (BONK), Moodeng (MOODENG), and Official Trump (TRUMP).

 

According to Oh, the breach was followed by an emergency security review of the affected networks and wallets. He added that all remaining assets were moved to cold storage to prevent further unauthorized transfers. Oh also said the exchange is working to trace the stolen assets and block on-chain movements wherever possible, noting that Solayer (LAYER) tokens worth 2.3 billion won ($1.6 million) have already been frozen. Upbit is also reaching out to relevant projects and institutions for assistance.

 

This marks Upbit’s second theft case. The first took place on Nov. 27, 2019, exactly six years ago to the day, according to News1.

 

Authorities focus on Lazarus’ involvement

Financial authorities are investigating the incident, and North Korea’s Lazarus Group is being treated as the leading suspect, the Maeil Business Newspaper reported.

 

Lazarus is also believed to have been behind the 58 billion won ($40 million) worth of Ethereum (ETH) stolen from Upbit in 2019. A government official told the paper that the latest breach did not appear to stem from a server intrusion but may have involved a stolen administrator account, allowing the attackers to impersonate internal staff and move assets—similar to the method used in the 2019 case.

 

Security analysts echoed that assessment. One investigator said the stolen funds moved through exchange wallets before being mixed, a pattern often linked to Lazarus. He added that mixers, which are prohibited in Financial Action Task Force (FATF)-member jurisdictions, make tracing difficult and that attackers typically route assets through countries outside that framework, further pointing to North Korea.

 

Following the incident, Upbit suspended deposits and withdrawals for all assets and said services will resume once security is fully verified. The halt has also affected trading dynamics on the exchange, with CryptoQuant CEO Ki Young Ju noting that retail investors are fueling altcoin spikes as arbitrage bots remain offline.

 

Dunamu, Naver set $6.8B growth plan

The security crisis struck at a particularly sensitive moment for Upbit’s operator, Dunamu, overshadowing what was intended to be a celebratory corporate milestone. On that same day, Dunamu, Naver, and Naver Financial held a joint press conference to outline their global expansion strategy. Dunamu brings its blockchain and crypto infrastructure, Naver contributes its position as Korea’s dominant search engine, and Naver Financial adds its payment platform serving 34 million users.

 

The event came after reports that Naver Financial and Dunamu had approved a merger plan through a comprehensive share swap, with the ratio set at 1 to 2.54. The three companies said they will combine their respective strengths to invest 10 trillion won ($6.8 billion) over the next five years in building an ecosystem centered on Web3 and artificial intelligence (AI).


During the press conference, Naver CEO Choi Soo-yeon said no decisions have been made on a Nasdaq listing for the newly combined Naver Financial–Dunamu entity or on whether it might eventually merge with Naver, according to TechM. She said dual listings remain a matter requiring national consensus. Choi also noted that while Naver Financial is a Naver subsidiary, Dunamu is the larger partner, and a later merger between the combined entity and Naver is unlikely.

More to Read
View All
Policy & Regulation·

Feb 13, 2024

Philippines to move forward with CBDC without blockchain

The Philippines' central bank has confirmed it has no plans to issue a retail version of a central bank digital currency (CBDC) but that it has definite plans to introduce a wholesale-level CBDC, albeit without using blockchain as the underlying technology. Avoiding retail-level bank run riskThe bank expressed concerns that a retail CBDC could potentially trigger bank runs, given the velocity at which digital currency can be transacted. However, in an interview with local media outlet, the Inquirer, the central bank governor Eli Remolona clarified that within the next two years, the country has definite plans to roll out a wholesale CBDC. CBDCs come in retail and wholesale forms, with the former accessible to the general public and the latter exclusively for institutional use. While the Philippines central bank initiated an exploratory study previously relative to CBDC use, concerns have been raised by the Bank for International Settlements (BIS) about the readiness of institutions to handle the risks associated with CBDCs.Photo by Krisia on PexelsDismissing blockchainDespite this move, the bank does not intend to utilize blockchain or digital ledger technology, which are fundamental to many virtual assets. Remolona stated: "Other central banks have tried blockchain, but it didn’t go well." Instead, the CBDC will operate on a payment and settlement system owned by the central bank, with a focus on wholesale transactions mediated by banks. This marks a shift in the central bank's approach to underlying technology where a CBDC is concerned. The Bangko Sentral ng Pilipinas (BSP) initially embarked on an exploratory study regarding CBDCs in 2022, known as Project CBDCPh. Upon completion of that study, it followed up with a pilot project called Project Agila, concentrating on a wholesale CBDC. Project Agila leaned on the use of the Hyperledger Fabric blockchain, considering it for use on the first wholesale CBDC.  Hyperledger Fabric is an open-source blockchain framework hosted by the Linux Foundation. Companies like IBM, SAP and Intel have all contributed to the development of the enterprise-grade permissioned blockchain network. However, it appears that the BSP is shying away from using any type of blockchain-based solution in establishing its CBDC. Regional steps towards CBDC useThe central bank of the Philippines is among several in the Asia-Pacific (APAC) region that are working towards the introduction of a CBDC. Earlier this month an official from the Reserve Bank of India (RBI) outlined that the central bank will move forward with CBDC development while working towards addressing privacy concerns that citizens may have with a digital rupee. Towards the end of last month, the Japanese government, in collaboration with the Bank of Japan, appeared to be gearing up for the rollout of a CBDC. In a recent meeting between both parties, several legislative matters were identified as key to ensuring a smooth path to the unobstructed launch of a digital currency. There has also been a lot of activity relative to attempts to utilize CBDCs for cross-border trade over the course of the past year. In the United Arab Emirates (UAE), the country announced the first-ever use of its CBDC or digital dirham in a trade deal with China using mBridge, a multi-CBDC platform that supports peer-to-peer, cross-border payments in real time.

news
Policy & Regulation·

Jul 13, 2023

Kaspersky Says Crypto Phishing on the Rise in the Philippines

Kaspersky Says Crypto Phishing on the Rise in the PhilippinesThe Philippines witnessed a significant increase in detected cryptocurrency-related attacks last year while Vietnam recorded the highest level in Southeast Asia, according to cybersecurity firm Kaspersky.Photo by Markus Spiske on UnsplashEase of crypto accessVietnam topped the list with over 64,000 detections. Meanwhile, the Philippines recorded 24,737 cases of crypto-phishing attacks in 2022, up from 9,164 cases in 2021, making it the second-highest number in Southeast Asia.Adrian Hia, Managing Director for Asia Pacific at Kaspersky, attributed the rise to the ease of accessing cryptocurrency in the Philippines. He explained that as users increasingly turn to mobile devices, they are inadvertently exposing themselves to potential breaches, as malware can be installed through various touch points.Research published by Malaysian crypto data aggregator, CoinGecko, earlier this month, also points to the Philippines as having the second highest level of interest in crypto in Southeast Asia, after Singapore.Targeting popular platformsCybercriminals commonly target accounts of popular online gaming platforms and crypto wallets using advanced stealers or “stalkerware” that allow them to spy on individuals through their mobile devices, Kaspersky stated. The firm’s monitoring data revealed that malware is spreading through legitimate channels such as official marketplaces and advertisements in popular apps.Across Southeast Asia, the total number of crypto-phishing detections decreased to 147,649 in 2022 from 164,330 in 2021, according to Kaspersky. However, only Singapore (down 74%), Thailand (down 51%), and Vietnam (down 15%) observed declines in detections. Besides the Philippines, crypto-related attacks also increased in Indonesia (from 19,584 in 2021 to 24,642 in 2022) and Malaysia (from 16,071 to 16,767).Kaspersky discovered an average of 400,003 new malicious files per day in 2022, representing an increase of 20,000 files per day compared to the previous year. Hia emphasized that scammers are relentless in their efforts to steal cryptocurrency due to its increasing popularity and adoption, particularly in Southeast Asia. He urged cryptocurrency adopters in the region to stay informed about the latest tricks used by crypto phishers to protect their digital assets.Email-based attacksRoman Dedenok, a spam analysis expert at Kaspersky, revealed that crypto phishers often employ email-based attacks to target crypto users. He explained that scammers entice victims with the prospect of participating in a cryptocurrency giveaway, offering popular digital assets such as Bitcoin, Ethereum, Litecoin, Tron, or Ripple.The scammers provide a three-point guide to claim the free cryptocurrency along with a link to the “promotion” website. Clicking on the link leads users to a phishing site where they are prompted to specify the wallet to which they want the funds transferred.In response to the growing cybersecurity concerns, Kaspersky is engaging in discussions with government institutions worldwide. In the Philippines, while the central bank does not directly regulate cryptocurrency, it has established guidelines for virtual asset service providers. The Chairman of the Securities and Exchange Commission (SEC) in the Philippines, Emilio Aquino, recently delayed publication of a regulatory framework for crypto, on the basis of having “to make sure people don’t get burned.”Entities involved with virtual assets are required to obtain a license from the Bangko Sentral ng Pilipinas, the central bank of the Philippines, to comply with regulations.

news
Web3 & Enterprise·

Jun 12, 2023

SBINFT and JPNFT Collaborate to Establish A Secure NFT Market in Japan

SBINFT and JPNFT Collaborate to Establish A Secure NFT Market in JapanSBINFT, a Japanese company specializing in NFT consulting and marketplace services, has joined forces with JPNFT, a Japanese platform dedicated to establishing a secure NFT market by combating unauthorized NFTs, according to a press release. Together, these entities are working towards the development of a marketplace that ensures users have access to secure and authorized NFTs, with the overarching aim of promoting the distribution of legitimate digital assets.Photo by Choong Deng Xiang on UnsplashRise of NFTsThe advent of blockchain technology has revolutionized the way digital assets are valued and their ownership is determined. This transformative technology has enabled the creation of non-fungible tokens (NFTs), which now serve as digital representations of various creations and are actively traded on dedicated marketplaces.Unauthorized NFTsSince 2021, numerous new players have entered the global NFT landscape. As of March 2023, OpenSea, the world’s largest NFT marketplace, boasts a monthly trading volume of $430 million. While this growth signals promising market development, it also brings forth challenges stemming from the proliferation of pirated and unauthorized NFTs. Considering Japan’s esteemed international reputation in the realms of art and content, the country possesses the potential to emerge as a significant player in the NFT market. However, to realize this potential, appropriate measures must be swiftly implemented to guarantee security and authenticity within the industry.License check & certification markIn order to tackle this challenge, SBINFT and JPNFT have joined forces to establish a safe and sound NFT market that ensures the availability of genuine NFTs for users. As part of this collaboration, content NFTs registered on the NFT disclosure information platform called “jpnft” will undergo a verification process for authenticity when traded on the “SBINFT Market.” This verification process will involve an official license check as well as the inclusion of a JPNFT certification mark.The launch of jpnft content on the SBINFT Market is planned for the summer of 2023. The jpnft platform plays a crucial role in distinguishing between licensed NFTs and unauthorized ones by publishing official information related to NFTs based on Japanese intellectual properties. Licensed NFTs will be either issued directly by rights holders or authorized by them. It’s worth noting that the jpnft platform was developed as a project supported by the subsidy for “Japan content localization and distribution (J-LOD)” in the 2021 Supplementary Budget of the Japanese Ministry of Economy, Trade and Industry.Previously known as nanakusa, the SBINFT Market is built on two public chains (Ethereum and Polygon) and is committed to becoming a global open marketplace and. With a focus on providing a secure trading environment, the SBINFT Market meticulously reviews NFTs to safeguard users from potential risks such as fraud and hacking.Both SBINFT and JPNFT share a common philosophy that emphasizes the security of NFTs and the healthy development of the industry. With this shared vision, the SBINFT Market aims to enhance its content offerings and position itself as an authorized NFT marketplace that handles NFTs on jpnft.Government initiativeLast month, the Working Group for Digital Society Promotion under Japan’s ruling Liberal Democratic Party (LDP) presented a proposal to Prime Minister Kishida Fumio regarding the Web3 industry. This proposal recommended the implementation of measures to safeguard Japanese content and data from unauthorized monetization by foreign entities. This initiative highlights the government’s endeavor to protect and promote the integrity of Japan’s digital assets.

news
Loading