Upbit halted digital-asset deposits and withdrawals on November 27, 2025 after detecting unauthorized transfers from a Solana-network hot wallet valued at 44.5 billion Korean won at the time of the incident.
The South Korean exchange’s operator, Dunamu, said it identified the transfers at approximately 4:42 a.m. Korea Standard Time. The affected holdings spanned 24 assets associated with the Solana network, including SOL, USDC, BONK, Jupiter, Pyth Network, Raydium and Render.
Dunamu said the transactions sent assets to wallet addresses that Upbit had not designated. It initially estimated the exposure at 54 billion won, then revised the figure to 44.5 billion won after valuing the affected assets at their prices when the withdrawals occurred. The revision was a valuation adjustment, not evidence that the missing tokens had been recovered.
Upbit promised to absorb the loss
Upbit said the abnormal transfers originated from an operational hot wallet and that its cold wallets had not been breached. Hot wallets remain connected to online systems so an exchange can process customer transactions; cold wallets isolate signing material from those routine systems. The distinction limited the company’s reported breach perimeter, but it did not establish how the hot-wallet controls had failed.
The exchange said it would use company assets to cover the entire loss so customers would not bear it. That was a contemporaneous corporate commitment, not an independently audited reimbursement result. Upbit also moved remaining assets into cold storage and began a broader review of its network and wallet infrastructure.
Deposit and withdrawal services were suspended while that inspection proceeded. Trading continuity alone would not have resolved the operational risk: customers could still face uncertainty whenever an exchange pauses the movement of assets, even if account balances remain displayed and the operator promises reimbursement.
Upbit reported that approximately 2.3 billion won of LAYER tokens had been frozen through cooperation with the relevant project. It said it was tracking the remaining assets and working with projects and institutions on additional freezes. The stated frozen amount represented only part of the 44.5 billion won valuation and did not establish final recovery.
What remained unknown on November 27
Upbit had not publicly established the technical cause by the end of November 27. The available notice did not determine whether stolen credentials, compromised signing infrastructure, deceptive approvals, an internal control failure or another mechanism enabled the transfers.
It also did not identify an attacker. Attribution reports that emerged later cannot be treated as established event-day fact. The defensible November 27 record is therefore narrower: Upbit confirmed unauthorized transfers from its Solana hot-wallet environment, quantified the affected assets using incident-time prices and suspended transfers while investigating.
Nothing in the contemporaneous evidence showed that the Solana protocol itself had been compromised. Multiple Solana-based tokens moved because they were held within the affected exchange wallet environment. That is materially different from a consensus failure or a vulnerability proven to exist across the underlying network.
An institutional test for a major exchange
South Korean financial authorities began an on-site inspection on November 27, according to contemporaneous reporting. The incident mattered beyond its immediate monetary size because Upbit was the country’s largest crypto exchange and a central gateway between won-denominated customers and digital-asset markets.
The breach also occurred as Naver Financial and Dunamu publicly presented plans to combine their businesses, following corporate approvals announced on November 26. That timing intensified scrutiny, but it did not demonstrate any connection between the transaction and the security failure.
November 27 also marked exactly six years since Upbit’s November 27, 2019 ether theft. The coincidence underscored the persistence of exchange custody risk. It did not prove that the incidents shared an attacker, method or operational weakness. Those questions required forensic evidence that was not available in Upbit’s event-day disclosure.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

