Worked example · 2019-11
Upbit exchange hack — Ethereum — 2019-11-27
Summary
Upbit, one of South Korea's largest cryptocurrency exchanges (operated by Dunamu, Inc.), suffered a hot-wallet compromise on 2019-11-27. The attacker drained 342,000 ETH (~$49M at the time) from Upbit's Ethereum hot wallet in a single transaction to an attacker-controlled address.
Upbit's operator, Dunamu, publicly disclosed the breach within hours and committed to covering the full loss from company reserves, meaning no user funds were affected. The exchange suspended deposits and withdrawals, migrated remaining hot-wallet assets to cold storage, and underwent a comprehensive security audit before resuming operations.
The stolen ETH was rapidly distributed across multiple exchange deposit addresses and laundering infrastructure in a pattern characteristic of DPRK OAK-G01 tradecraft. The laundering route — a fan-out across dozens of exchange deposit addresses within hours of extraction, followed by conversion to BTC and routing through mixing services — is the same structural signature observed at CoinEx (2023) and other OAK-G01-attributed exchange breaches.
In November 2024, the South Korean NPA Cyber Bureau formally confirmed DPRK Lazarus Group attribution, making Upbit the case with the longest publicly documented gap (5 years) between incident and formal attribution in OAK v0.1.
Timeline (UTC)
| When | Event | OAK ref |
|---|---|---|
| 2019-11-27 | Attacker compromises Upbit Ethereum hot-wallet signing infrastructure; 342,000 ETH (~$49M) drained in a single transaction | T11.001 (signing-flow compromise) |
| 2019-11-27 T+hours | Upbit (Dunamu) discloses breach; commits to covering full loss from company reserves; suspends deposits/withdrawals | (defender response) |
| 2019-11-27 to 2019-12 | Stolen ETH fanned out across dozens of exchange deposit addresses; laundering chain matches OAK-G01 tradecraft | T7.001 (exchange-routed + mixer laundering) |
| 2019-12 to 2020-01 | Upbit completes security audit; resumes full operations | (operational recovery) |
| 2024-11 | South Korean NPA Cyber Bureau formally confirms DPRK Lazarus Group attribution for the 2019 hack | (attribution confirmation — 5-year forensic timeline) |
Realised extraction
342,000 ETH (~$49M at 2019-11 prices, ~$170M+ at 2024 ETH prices). Attributed to OAK-G01. No confirmed recovery of the stolen assets; Dunamu covered the loss from company reserves.
Attribution timeline
The 5-year gap between incident (2019) and formal state attribution (2024) is a structural feature of OAK-G01 cases: the wallet-cluster attribution (Chainalysis, Elliptic, TRM) typically firms within months, but formal attribution at the national-law-enforcement evidentiary standard (required for UN Panel of Experts reporting and INTERPOL notice issuance) takes years. The Upbit case anchors the extended-attribution-timeline pattern in OAK v0.1 and is the reference for investigators evaluating the maturity stage of DPRK-attribution claims.
Public references
- Dunamu / Upbit official breach disclosure and user-reimbursement announcement, November 2019
- South Korean National Police Agency (NPA) Cyber Bureau DPRK attribution confirmation, November 2024
- UN Panel of Experts reports on DPRK cyber operations and cryptocurrency exchange targeting, 2020-2024 cycle
- Chainalysis, Elliptic, and TRM DPRK-campaign wallet-cluster attribution reports, 2019-2024