Lcx Dunamu Faces Sanctions After $30 Million Upbit Hack Linked to Lazarus Group
Article Content
- •Dunamu is facing sanctions after a $30 million hack of Upbit's Solana wallet.
- •The hack occurred on November 27, 2025, and involved the theft of 44.5 billion won.
- •Authorities suspect North Korea's Lazarus Group was behind the attack.
South Korea's Financial Supervisory Service (FSS) has initiated sanction procedures against Dunamu, the operator of Upbit, following a $30 million hack that occurred on November 27, 2025. The breach involved the theft of approximately 44.5 billion won in Solana-based assets, which were drained to an external wallet over 54 minutes. Dunamu has since frozen 2.6 billion won ($1.7 million) of the stolen funds and compensated affected users using its own reserves. The FSS's investigation, which lasted seven months, is examining potential violations of the Virtual Asset User Protection Act, although current regulations lack specific provisions for sanctions related to hacking incidents. Authorities suspect that the North Korean hacking group, Lazarus, may be behind the attack. The FSS plans to notify Dunamu of the proposed sanctions after a clarification process, with final decisions pending review by multiple financial authorities. This incident marks the second significant breach of Upbit's hot wallet in six years, raising concerns about the exchange's security measures.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track Lazarus Group and Bithumb in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Mirage Kitten Targets Aviation and FinTech with New Cross-Platform Malware The Iranian cyberespionage group Mirage Kitten has launched a campaign targeting technology professionals in the aviation and FinTech sectors across the Middle East and Africa. This operation involves the use of two newly discovered malware families, NodeRabbit and PollCat, both of which are cross-platform remote…
Social Engineering Campaign Hijacks Microsoft 365 Accounts via Passkey Alerts A social engineering campaign impersonating IT support staff is actively hijacking Microsoft 365 accounts. The attackers use passkey-themed lures to trick users into providing credentials, leading to unauthorized access and data exfiltration. Microsoft Security Research has tracked these intrusions since May 2026…