Upbit Hot-Wallet Theft (November 27, 2019)

On November 27, 2019, 342,000 ETH - roughly 58 billion won, or about $50M at the time - was transferred out of the Ethereum hot wallet of Upbit, South Korea's largest cryptocurrency exchange, to an unknown external address in a single transaction. Upbit disclosed the incident the same day, pledged to cover the entire loss from corporate assets, suspended deposits and withdrawals, and moved all remaining assets to cold storage; no customers lost funds. For five years the theft remained formally unattributed, though analysts had long suspected North Korea. On November 21, 2024, South Korea's National Office of Investigation (National Investigation Headquarters, Korean National Police Agency) ended the ambiguity: after a joint investigation with the FBI, it formally attributed the theft to the Lazarus Group and Andariel, hacking units tied to North Korea's Reconnaissance General Bureau - the first time a South Korean state investigative body had officially blamed the DPRK for a cryptocurrency exchange hack. The attribution rested on North Korean IP addresses, the flow of the stolen assets, distinctively North Korean vocabulary recovered from attacker systems, and FBI-shared intelligence. The stolen ETH, worth about $50M when taken, was worth over $1 billion at the time of the attribution - a stark illustration of how DPRK crypto theft compounds.

Timeline of events

At approximately 1:06 PM KST on November 27, 2019, a single transaction moved 342,000 ETH from Upbit's Ethereum hot wallet to an address outside the exchange's control. Upbit - operated by Dunamu - detected the anomalous transfer, halted all deposits and withdrawals, and published a disclosure the same afternoon under the name of Dunamu CEO Lee Seok-woo, confirming the amount, stating that the 342,000 ETH would be covered entirely by corporate assets, and announcing that all remaining hot-wallet holdings were being moved to cold storage. The disclosure was notable for its speed and bluntness at a time when exchanges routinely delayed or euphemized breach announcements. Services remained suspended while Upbit rebuilt its wallet infrastructure, and the exchange subsequently completed a security overhaul of its deposit and withdrawal systems. The stolen ETH, meanwhile, began moving within days: it was split across an expanding tree of addresses and pushed toward conversion venues. The investigation proceeded quietly for five years, spanning South Korean police, the FBI and, eventually, Swiss authorities. In October 2024, 4.8 BTC in traced proceeds was recovered from a Swiss exchange and returned to Upbit. On November 21, 2024, the National Office of Investigation announced its formal conclusion: the theft was the work of Lazarus and Andariel.

Attack mechanism

The theft was executed as a single authorized-looking transfer from Upbit's Ethereum hot wallet - there was no smart-contract exploit, no bridge flaw, and no on-chain trickery. Neither Upbit nor South Korean police have published a complete forensic account of the intrusion path, but investigators' findings indicate the attackers obtained the ability to authorize transfers from the hot wallet - consistent with compromise of the systems or credentials controlling it rather than any external protocol weakness. The incident occurred while Upbit was reportedly moving assets between storage tiers, and the attackers' timing suggests internal visibility into the exchange's wallet operations. What is firmly established is the DPRK tradecraft pattern around the theft. Lazarus and Andariel - the latter a subordinate unit under the Reconnaissance General Bureau with a history of targeting South Korean institutions - had by 2019 already been sanctioned by the U.S. Treasury (September 2019) for funding the North Korean regime through cyber operations. The Upbit operation fits the model documented across the DPRK exchange-hack series from 2017 onward: gain internal access to a custodial platform, move the largest liquid asset in a minimal number of transactions, and begin structured laundering immediately. The single-transaction extraction of 342,000 ETH remains one of the largest unitary transfers of stolen cryptocurrency ever executed.

Root cause analysis

As with every custodial hot-wallet theft, the root cause reduces to concentration and authorization: 342,000 ETH - a nine-figure sum even at 2019 prices in won terms - was accessible to a signing process that an external attacker was able to invoke. A hot wallet holding that share of an exchange's ETH float exceeded any defensible liquidity requirement; the post-incident response (moving everything to cold storage and rebuilding the wallet system) is itself the clearest statement of what the architecture should have been beforehand. The absence of a published forensic root cause is itself a lesson: South Korean exchanges in 2019 operated under the Act on Promotion of Information and Communications Network Utilization, with crypto-specific custody regulation still years away (the Virtual Asset User Protection Act came into force in 2024), and no rule compelled detailed breach disclosure. What can be said with confidence is that the controls that failed were off-chain: transfer authorization for the hot wallet was compromisable from outside, there was no effective withdrawal ceiling or human-in-the-loop review capable of stopping a single 342,000 ETH transfer, and wallet-tier segregation left far too much value hot. Upbit's saving control was balance-sheet strength - Dunamu could absorb a $50M loss outright - which is a form of user protection, but not a substitute for custody architecture.

Initial response and recovery

Upbit's user-facing response was immediate and complete: the same-day disclosure committed to covering the full 342,000 ETH from corporate assets, and Upbit made good on it - no customer lost funds. Deposits and withdrawals were suspended while the exchange moved all assets to cold storage and rebuilt its wallet infrastructure, and Upbit later confirmed completion of the security overhaul. Recovery of the stolen assets themselves, by contrast, was minimal, in sharp contrast to the KuCoin hack ten months later. ETH is a native bearer asset: no issuer could redeploy a contract to invalidate the thief's balance, and by the time exchange-level freezes could propagate, the funds were already fragmenting through attacker-controlled conversion channels. The one concrete clawback came five years later: South Korean police, working with Swiss prosecutors, traced a portion of the proceeds to a Swiss cryptocurrency exchange, and in October 2024 recovered 4.8 BTC - roughly 600 million won - which was returned to Upbit. Set against 342,000 ETH, the recovery is a rounding error; its significance is procedural, demonstrating that multi-year, multi-jurisdiction tracing of DPRK proceeds can produce seizures even long after the fact.

Funds tracking and laundering

The laundering of the Upbit ETH became one of the best-documented DPRK washing operations of its era. According to the South Korean police findings announced in November 2024, roughly 57% of the stolen ETH was converted into Bitcoin at a 2.5% discount to market price through three exchange platforms that investigators assess were set up by the North Koreans themselves - captive conversion venues built to swallow the stolen flow without questions. The remaining 43% was dispersed through 51 overseas exchanges across 13 countries and progressively laundered. The 2.5%-discount captive-exchange detail is significant for tracing methodology: selling below market in bulk is a signature of launderers prioritizing speed and volume over price, and the discount became a fingerprint investigators could follow across venues. The five-year investigation combined this on-chain fund-flow analysis with off-chain evidence: North Korean IP addresses recovered in the investigation, and the presence of distinctively North Korean vocabulary in attacker-linked material, alongside intelligence shared by the FBI through the agencies' long-term cooperation. The Swiss thread - the trace that produced the 4.8 BTC recovery - required South Korean police to present their evidence package to Swiss authorities to obtain the seizure and repatriation, completed in October 2024.

Legal and regulatory aftermath

The November 21, 2024 attribution was itself the landmark legal event: it was the first time a South Korean state investigative body formally and publicly attributed a cryptocurrency exchange hack to North Korea, converting years of private-sector and UN Panel of Experts assessments into an official state finding. The attribution named both Lazarus and Andariel - the latter already sanctioned by the U.S. Treasury in September 2019 as an RGB-subordinate unit - and cited the combined evidentiary base of IP addresses, fund flows, linguistic evidence and FBI cooperation. No individual has been charged, and none plausibly will be while the operators remain in the DPRK. For Upbit and the South Korean market, the incident fed directly into the tightening of domestic crypto regulation over the following years: the March 2020 amendment of the Act on Reporting and Using Specified Financial Transaction Information brought exchanges under AML registration requirements with mandatory ISMS certification and real-name banking, and the Virtual Asset User Protection Act (in force July 2024) imposed statutory custody segregation, cold-storage ratios and insurance obligations of exactly the kind whose absence the 2019 theft had exposed. The Upbit case is routinely cited in Korean regulatory discourse as a foundational justification for those custody rules.

Industry implications

Upbit 2019 sits at a hinge point in the DPRK crypto-theft series. It closed out the first generation of North Korean exchange hacks - custodial hot-wallet thefts against Asian exchanges (Youbit, Bithumb-adjacent incidents, Coincheck-era operations) - and prefigured the far larger operations of 2022-2025. Three implications proved durable. First, native-asset theft is effectively final: the contrast between Upbit's ~0% on-chain recovery and KuCoin's 84% a year later demonstrated that recovery outcomes are determined by asset composition, not investigative effort, and pushed exchanges toward minimizing native-asset hot float specifically. Second, captive laundering infrastructure: the finding that the attackers built their own exchange platforms to convert 57% of the haul at a discount showed that DPRK laundering was industrializing - a precursor to the mixer-and-OTC pipelines documented after Ronin. Third, attribution timelines: the five-year gap between theft and formal attribution, bridged by sustained South Korean-FBI cooperation, established that state attribution of crypto theft is achievable but slow, and the 2024 announcement provided a procedural template that South Korea can now reuse. The theft's appreciating value - $50M taken, over $1 billion at attribution - also sharpened industry understanding that DPRK holdings of stolen crypto function as an appreciating sanctions-evasion treasury.

Verdict and lessons

The Upbit theft is the cleanest illustration in the historical record of the custodial hot-wallet failure mode: one wallet, one transaction, 342,000 ETH gone. There was no contract to audit, no oracle to secure, no bridge design to debate - only the oldest question in exchange security, which is how much value sits behind a signing process and who can invoke it. Upbit's handling set a standard that deserves recognition: same-day disclosure, full coverage from corporate assets, immediate migration to cold storage, and cooperation with a five-year international investigation that ultimately produced the first official South Korean attribution of a crypto hack to the DPRK. But the structural lessons are unforgiving. Hot wallets must hold operational float only, with hard withdrawal ceilings and human review above thresholds - a single transaction should never be able to move an exchange's treasury. Native assets, once gone, are gone; balance-sheet coverage protects users but recovers nothing. And attribution, while achievable, arrives in years, not weeks - the 2024 Lazarus/Andariel finding changed the historical record and supported a Swiss seizure of 4.8 BTC, but the DPRK kept the rest, and the ETH it kept appreciated twenty-fold in its hands. The deterrence problem that pattern creates - theft as a compounding sovereign investment - remains unsolved.

Root cause

Attackers gained the ability to authorize transfers from Upbit's Ethereum hot wallet and moved 342,000 ETH (~58 billion won, ~$50M) to an external address in a single transaction on November 27, 2019. No smart-contract flaw was involved; the failure was off-chain custody architecture - excessive hot-wallet concentration and compromisable transfer authorization. Neither Upbit nor investigators have published a full forensic account of the intrusion path. South Korean police formally attributed the operation to Lazarus and Andariel in November 2024.

Recovery and aftermath

Upbit covered the entire loss from corporate assets, so no users were harmed, and rebuilt its wallet system around cold storage. Of the stolen funds, only 4.8 BTC (~600 million won) traced to a Swiss exchange was recovered and returned to Upbit in October 2024. Roughly 57% of the ETH had been converted to Bitcoin at a 2.5% discount via three attacker-built exchange platforms, with the remainder laundered through 51 exchanges across 13 countries. The stolen ETH was worth over $1 billion at late-2024 prices.

Lessons

Precedent

Produced the first formal attribution of a cryptocurrency exchange hack to North Korea by a South Korean state investigative body (November 21, 2024, naming Lazarus and Andariel), and documented the captive-exchange laundering model - attacker-built conversion venues absorbing stolen flow at a discount - later recognized across the DPRK laundering pipeline.

Frequently asked questions

How much was stolen in the Upbit hack?

342,000 ETH was transferred out of Upbit's hot wallet on November 27, 2019 - approximately 58 billion won, or about $50 million at the time. At late-2024 prices the same ETH was worth over $1 billion.

What caused the Upbit hack?

The 342,000 ETH left Upbit's Ethereum hot wallet in a single unauthorized transaction. Upbit has not published a detailed forensic account; investigators indicated the attackers gained the ability to authorize transfers from the hot wallet rather than exploiting any smart-contract flaw.

Who was behind the Upbit hack?

In November 2024, South Korea's National Office of Investigation (National Investigation Headquarters, Korean National Police Agency) formally attributed the theft to North Korea's Lazarus Group and Andariel, citing North Korean IP addresses, fund-flow analysis, North Korean vocabulary usage, and evidence from long-term cooperation with the FBI.

Was the stolen money recovered in the Upbit hack?

Upbit covered the full 342,000 ETH from corporate assets, so no users lost funds. Of the stolen ETH itself, only 4.8 BTC worth of proceeds traced to a Swiss exchange was recovered and returned to Upbit in 2024.

When did the Upbit hack occur?

The theft occurred on November 27, 2019, when 342,000 ETH was moved out of Upbit's hot wallet in the early afternoon Korean time. Upbit disclosed it the same day.

Sources