Search
Close this search box.

North Korean Lazarus Group Linked to $30 Million Crypto Theft from South Korea’s Upbit

Seoul: North Korea's Lazarus hacking group is believed to be responsible for the recent theft of approximately 45 billion won ($30.6 million) in cryptocurrency from Upbit, South Korea's largest crypto exchange. This revelation was reported by South Korean media on Friday.

According to Anadolu Agency, government and industry officials cited by Seoul-based Yonhap News have indicated that authorities are planning to conduct an on-site investigation at Upbit, with Lazarus suspected as the likely perpetrator. The Upbit operator, Dunamu, disclosed on Thursday that it detected the unauthorized transfer of 44.5 billion won in Solana-linked assets to an external wallet and has pledged to fully compensate the losses using its own holdings.

Lazarus has a history with Upbit, having been suspected of stealing 58 billion won in Ethereum from the exchange in 2019. Authorities noted that the techniques employed in the latest breach bear resemblance to those used in the previous attack. "Instead of attacking the server, it is possible that hackers compromised administrators' accounts or posed as administrators to make the transfer," a government official explained.

Experts highlighted that the breach coincides with reports of Pyongyang attempting to raise funds amid a persistent foreign currency shortage. "It is the tactic of Lazarus to transfer crypto to wallets at other exchanges and attempt money laundering," a security official remarked, noting that such strategies render the transactions untraceable.

Some analysts have suggested that the timing of the breach, occurring a day after Naver Corp., South Korea's leading search engine, announced plans to acquire Dunamu as a wholly owned subsidiary of Naver Financial through a share-swap agreement, may have been deliberate. "Hackers have a strong tendency toward self-display," another security official commented.