OAK — OnChain Attack Knowledge

Worked example · 2019-11

Upbit exchange hack — Ethereum — 2019-11-27

Loss
approximately $49M (342,000 ETH) from South Korean exchange Upbit. Hot-wallet compromise executed as a single-block drain of 342,000 ETH from Upbit's Ethereum hot wallet to an attacker-controlled address, followed by rapid laundering across multiple exchange deposit addresses.
OAK Techniques observed
OAK-T11.001 (Third-Party Signing-Vendor UI / Signing-Flow Compromise — broadly construed; the exchange's hot-wallet signing infrastructure was compromised, enabling the single-transaction 342,000 ETH drain). OAK-T7.001 (Mixer-Routed Laundering — the attacker immediately routed the drained ETH through a network of exchange deposit addresses and mixing infrastructure characteristic of DPRK OAK-G01 laundering tradecraft).
OAK-Gnn
OAK-G01 Lazarus Group / DPRK-attributed.
Attribution
inferred-strong In November 2024, the South Korean National Police Agency (NPA) Cyber Bureau formally confirmed DPRK Lazarus Group (OAK-G01) attribution for the 2019 Upbit hack, citing wallet-cluster analysis, laundering-route tracing, and multi-year cross-incident attribution work.
Key teaching point
The Upbit November 2019 hack is the canonical 342,000 ETH single-block drain case and the structural bridge between the pre-2019 Asian-exchange DPRK targeting wave (Yapizon 2017, Bithumb 2018) and the post-2020 multi-chain, multi-venue OAK-G01 extraction playbook (KuCoin 2020, CoinEx 2023, DMM Bitcoin 2024). The five-year gap between the incident (2019) and formal DPRK attribution (2024) illustrates the extended forensic timeline required for state-aligned threat-actor attribution at national-law-enforcement evidentiary standards.

Summary

Upbit, one of South Korea's largest cryptocurrency exchanges (operated by Dunamu, Inc.), suffered a hot-wallet compromise on 2019-11-27. The attacker drained 342,000 ETH (~$49M at the time) from Upbit's Ethereum hot wallet in a single transaction to an attacker-controlled address.

Upbit's operator, Dunamu, publicly disclosed the breach within hours and committed to covering the full loss from company reserves, meaning no user funds were affected. The exchange suspended deposits and withdrawals, migrated remaining hot-wallet assets to cold storage, and underwent a comprehensive security audit before resuming operations.

The stolen ETH was rapidly distributed across multiple exchange deposit addresses and laundering infrastructure in a pattern characteristic of DPRK OAK-G01 tradecraft. The laundering route — a fan-out across dozens of exchange deposit addresses within hours of extraction, followed by conversion to BTC and routing through mixing services — is the same structural signature observed at CoinEx (2023) and other OAK-G01-attributed exchange breaches.

In November 2024, the South Korean NPA Cyber Bureau formally confirmed DPRK Lazarus Group attribution, making Upbit the case with the longest publicly documented gap (5 years) between incident and formal attribution in OAK v0.1.

Timeline (UTC)

When Event OAK ref
2019-11-27 Attacker compromises Upbit Ethereum hot-wallet signing infrastructure; 342,000 ETH (~$49M) drained in a single transaction T11.001 (signing-flow compromise)
2019-11-27 T+hours Upbit (Dunamu) discloses breach; commits to covering full loss from company reserves; suspends deposits/withdrawals (defender response)
2019-11-27 to 2019-12 Stolen ETH fanned out across dozens of exchange deposit addresses; laundering chain matches OAK-G01 tradecraft T7.001 (exchange-routed + mixer laundering)
2019-12 to 2020-01 Upbit completes security audit; resumes full operations (operational recovery)
2024-11 South Korean NPA Cyber Bureau formally confirms DPRK Lazarus Group attribution for the 2019 hack (attribution confirmation — 5-year forensic timeline)

Realised extraction

342,000 ETH (~$49M at 2019-11 prices, ~$170M+ at 2024 ETH prices). Attributed to OAK-G01. No confirmed recovery of the stolen assets; Dunamu covered the loss from company reserves.

Attribution timeline

The 5-year gap between incident (2019) and formal state attribution (2024) is a structural feature of OAK-G01 cases: the wallet-cluster attribution (Chainalysis, Elliptic, TRM) typically firms within months, but formal attribution at the national-law-enforcement evidentiary standard (required for UN Panel of Experts reporting and INTERPOL notice issuance) takes years. The Upbit case anchors the extended-attribution-timeline pattern in OAK v0.1 and is the reference for investigators evaluating the maturity stage of DPRK-attribution claims.

Public references

  • Dunamu / Upbit official breach disclosure and user-reimbursement announcement, November 2019
  • South Korean National Police Agency (NPA) Cyber Bureau DPRK attribution confirmation, November 2024
  • UN Panel of Experts reports on DPRK cyber operations and cryptocurrency exchange targeting, 2020-2024 cycle
  • Chainalysis, Elliptic, and TRM DPRK-campaign wallet-cluster attribution reports, 2019-2024

Techniques demonstrated (2)