Upbit, one of South Korea’s largest crypto exchanges, reported a major loss after a Solana-network hot wallet was emptied early on November 27, 2025.
According to reports, about 54 billion Korean won — roughly $36–37 million — was taken in what the company called an “abnormal withdrawal” detected at 04:42 KST.
Upbit Suspends Solana Services
According to the exchange, deposits and withdrawals for assets on the Solana chain were halted immediately after the breach was found.
Company engineers moved remaining Solana holdings into cold storage to limit further access. Some tokens were later frozen on-chain while investigators traced transfers.
Reports have disclosed that about 12 billion won (around $8–9 million) in LAYER tokens has been frozen so far.
NEW: UPBIT DISCLOSES ~$37M HACK ON SOLANA NETWORK – “TO PREVENT ANY DAMAGE TO MEMBER ASSETS, THE ENTIRE AMOUNT WILL BE COVERED BY UPBIT’S HOLDINGS. WE WOULD LIKE TO REITERATE THAT THIS WILL NOT AFFECT MEMBER ASSETS”
SOURCE: https://t.co/LaGePSDOj4 pic.twitter.com/JRQzOFX2ot
— DEGEN NEWS (@DegenerateNews) November 27, 2025
A Broad Range Of Tokens Appears Affected
Based on reports from blockchain trackers and media outlets, the stolen assets included SOL and USDC along with many Solana-ecosystem tokens.
Stolen tickers reportedly include ACS, BONK, RAY, JUP, PYTH, ORCA, JTO, LAYER, RENDER, MOODENG, and TRUMP, among others.
The list is long, and tracking continues as some tokens move through multiple wallets. At this stage, several of the addresses holding the funds are under active monitoring.
Upbit(@Official_Upbit) has been hacked — 54B KRW (~36.8M USD) in assets on #Solana have been transferred to unknown wallets.https://t.co/plbmBz2G4Nhttps://t.co/YOHoqDVfqa pic.twitter.com/DM5BxSTtXA
— Lookonchain (@lookonchain) November 27, 2025
Exchange Operator Pledges Coverage
Dunamu, Upbit’s parent company, has said the exchange will cover the full loss from its own reserves so that customer balances will not be reduced.
According to the company, this decision was made to protect users while the technical and forensic reviews are under way.
A security review of the deposit and withdrawal systems has been launched, and outside experts are reported to be assisting with the investigation.
Past Incidents And Timing Raise Questions
Reports note the timing was awkward: the breach came just after a high-profile corporate announcement involving Naver Financial on November 26, 2025.
Upbit is not new to major hacks; a 2019 attack cost the platform a large amount of ETH. Hot wallets, which are connected to the internet, remain a known weak point for centralized exchanges. That risk was exposed again here.
On-Chain Tracking And Recovery Hopes
Blockchain analysts are following the trail of transfers and identifying the wallets that received funds. Some tokens can be frozen if their issuers or governing authorities cooperate, which is how the reported LAYER freeze was achieved.
Still, many assets may be hard to recover, and legal routes can be slow. It was reported that the exchange attempted to freeze what it could while moving other assets offline.
What This Means For Users And Market Confidence
For now, Upbit users have been assured their funds are safe because the operator pledged to absorb the loss.
Market reaction could include temporary liquidity issues for certain Solana tokens listed on the platform while services remain limited.
Featured image from Pixabay, chart from TradingView






