TLDR Upbit, South Korea’s largest crypto exchange, suspended deposits and withdrawals after detecting unauthorized transactions on November 27, 2025 Approximately $37 million worth of Solana network tokens were transferred to unauthorized wallets through a compromised hot wallet Affected tokens include BONK, JTO, USDC, ACS, DRIFT, and other Solana-based assets Upbit will fully reimburse all customers [...] The post South Korea’s Largest Crypto Exchange Upbit Halts Services After $37 Million Solana Token Breach appeared first on CoinCentral.TLDR Upbit, South Korea’s largest crypto exchange, suspended deposits and withdrawals after detecting unauthorized transactions on November 27, 2025 Approximately $37 million worth of Solana network tokens were transferred to unauthorized wallets through a compromised hot wallet Affected tokens include BONK, JTO, USDC, ACS, DRIFT, and other Solana-based assets Upbit will fully reimburse all customers [...] The post South Korea’s Largest Crypto Exchange Upbit Halts Services After $37 Million Solana Token Breach appeared first on CoinCentral.

South Korea’s Largest Crypto Exchange Upbit Halts Services After $37 Million Solana Token Breach

2025/11/27 15:40

TLDR

  • Upbit, South Korea’s largest crypto exchange, suspended deposits and withdrawals after detecting unauthorized transactions on November 27, 2025
  • Approximately $37 million worth of Solana network tokens were transferred to unauthorized wallets through a compromised hot wallet
  • Affected tokens include BONK, JTO, USDC, ACS, DRIFT, and other Solana-based assets
  • Upbit will fully reimburse all customers using the exchange’s own assets to cover losses
  • The exchange moved remaining funds to cold storage and froze about $8 million worth of Solayer tokens with law enforcement help

Upbit suspended all digital asset deposits and withdrawals on Thursday morning after detecting irregular activity on its Solana network wallets. The South Korean exchange identified unauthorized transfers totaling approximately 54 billion won, or $37 million.

The breach occurred around 4:42 AM local time on November 27, 2025. Exchange operators detected the irregular withdrawals from a compromised hot wallet address early in the incident.

Dunamu CEO Oh Kyung-seok confirmed the security breach in a public notice. He apologized to users for the service disruption and assured customers that the exchange would handle all losses.

The affected tokens span multiple categories on the Solana network. Meme coins including BONK, MOODENG, and Official Trump were among the compromised assets. Decentralized finance tokens such as Sonic SVM, Access Protocol, JTO, SOL, and Raydium were also transferred.

Other affected assets include DoubleZero, DOOD, Drift, HUMA, Ionet, JUP, LAYER, ME, Pudgy Penguin, and Circle’s USDC stablecoin. The unauthorized transfers moved these tokens to external wallet addresses not designated by Upbit’s internal systems.

Exchange Response and Asset Recovery

Upbit took immediate action after detecting the breach. The exchange transferred all remaining digital assets to cold storage to prevent further unauthorized transactions. Cold storage keeps cryptocurrency offline and away from potential network vulnerabilities.

The exchange worked with law enforcement to initiate on-chain freezing measures. These efforts successfully froze approximately 12 billion won, or $8 million, worth of Solayer tokens related to the incident. Upbit is coordinating with other token projects to attempt additional asset freezes.

Upbit launched a complete security audit of all digital asset transfer systems. The exchange stated it will gradually resume withdrawal services only after confirming system security. Deposit and withdrawal functions remain suspended while the investigation continues.

The exchange emphasized that customers will not bear any financial burden from the breach. Upbit committed to fully reimbursing all affected users using the company’s own assets. This compensation policy aims to protect user funds completely.

The timing of this security incident comes as Upbit’s parent company Dunamu navigates a major corporate change. Naver Financial agreed to absorb Dunamu in a $10.29 billion all-stock deal announced November 26, 2025. The transaction requires regulatory approval and would issue 2.54 new Naver shares for each Dunamu share.

The post South Korea’s Largest Crypto Exchange Upbit Halts Services After $37 Million Solana Token Breach appeared first on CoinCentral.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

OFAC Designates Two Iranian Finance Facilitators For Crypto Shadow Banking

OFAC Designates Two Iranian Finance Facilitators For Crypto Shadow Banking

The Department of the Treasury’s Office of Foreign Assets Control (OFAC) sanctioned two Iranian financial facilitators for coordinating over $100 million worth of cryptocurrency in oil sales for the Iranian government, a September 16 press release shows. OFAC Sanctions Iranian Nationals According to the Tuesday press release, Iranian nationals Alireza Derakhshan and Arash Estaki Alivand “used a network of front companies in multiple foreign jurisdictions” to transfer the digital assets. OFAC alleges that Alivand and Derakhshan’s transfers also involved the sale of Iranian oil that benefited Iran’s Islamic Revolutionary Guard Corps-Qods Force (IRGC-QF) and the Ministry of Defense and Armed Forces Logistics (MODAFL). IRGC-QF and MODAFL then used the proceeds to support regional proxy terrorist organizations and strengthen their advanced weapons systems, including ballistic missiles. U.S. officials say the move targets shadow banking in the region, where illicit financial actors use overseas money laundering and digital assets to evade sanctions. “Iranian entities rely on shadow banking networks to evade sanctions and move millions through the international financial system,” said Under Secretary of the Treasury for Terrorism and Financial Intelligence John K. Hurley. “Under President Trump’s leadership, we will continue to disrupt these key financial streams that fund Iran’s weapons programs and malign activities in the Middle East and beyond,” he continued. Dozens Designated In Shadow Banking Scandal Both Alivand and Derakhshan have been designated “for having materially assisted, sponsored, or provided financial, material, or technological support for, or goods or services to or in support of the IRGC-QF.” In addition to Alivand and Derakhshan, OFAC has sanctioned more than a dozen Hong Kong and United Arab Emirates-based entities and individuals tied to the network. According to the press release, the sanctioned entities may face civil or criminal penalties imposed as a result
Share
CryptoNews2025/09/18 11:18