Earlier this year, one of South Korea’s largest cryptocurrency exchanges suffered a major security breach that drained hundreds of hot wallets in just 15 minutes. According to a Chainalysis report, the attackers stole roughly ₩44.5 billion KRW, equivalent to $33–35 million, before the exchange could halt withdrawals. Assets taken included USDC, BONK, SOL, ORCA, RAY, […]Earlier this year, one of South Korea’s largest cryptocurrency exchanges suffered a major security breach that drained hundreds of hot wallets in just 15 minutes. According to a Chainalysis report, the attackers stole roughly ₩44.5 billion KRW, equivalent to $33–35 million, before the exchange could halt withdrawals. Assets taken included USDC, BONK, SOL, ORCA, RAY, […]

South Korean Crypto Exchange Loses $35 Million in 15-Minute Hot Wallet Hack

2025/12/04 14:00
3 min read
  • A South Korean exchange lost $35 million in 15 minutes after attackers drained hundreds of hot wallets.
  • Multi-chain withdrawal systems and complex cloud setups make CEXs increasingly vulnerable.
  • Real-time detection tools like Hexagate and GateSigner can limit losses during wallet breaches.

Earlier this year, one of South Korea’s largest cryptocurrency exchanges suffered a major security breach that drained hundreds of hot wallets in just 15 minutes.

According to a Chainalysis report, the attackers stole roughly ₩44.5 billion KRW, equivalent to $33–35 million, before the exchange could halt withdrawals. Assets taken included USDC, BONK, SOL, ORCA, RAY, PYTH, and JUP.

The exchange was able to freeze over half of the stolen funds, including ₩23 billion KRW worth of LAYER tokens, but the remaining amount was unrecoverable.

Analysis of the attack shows that it was not caused by a smart contract bug or a user error. Instead, the breach targeted the hot-wallet signing flow, a critical step in approving outgoing transactions.

The attackers executed hundreds of transfers in a highly automated and rapid manner, highlighting a pattern common in sophisticated CEX breaches.

Also Read: Retail Traders’ Interest in Crypto Fades, Signaling a Potential Market Bottom

Hackers Target Multi-Chain Crypto Withdrawal Systems

This particular incident reveals another trend: centralized exchanges and custodians are being impacted by breaches that are happening more frequently and are more costly.

Observers of hackers like the Lazarus Group report that hackers are interested in platforms with complicated multi-chain withdrawal systems because only one vulnerability can result in losses totaling millions of dollars.

Similar examples of previous hacks include Bybit, BTCTurk, SwissBorg, and Phemex.

The reasons are many, from social engineering and malware threats, and in many cases, from internal threats too, but in the end, the common result has always been significant losses in terms of money due to the delayed detection of the issue.

According to analysts, in this world, there are no absolute ways of being secure. The exploit demonstrates the difficulty in tracing the balances in multiple blockchains.

For example, the balances in the Solana wallets also behaved in the usual manner for quite a number of weeks until they went to zero when the attack happened.

There were 80 major transactions recorded in 15 minutes by the exchange, a drastic increase from the single $100,000 transaction recorded in the preceding week.

Real-Time Monitoring Reduces Financial Losses

Real-time tracking and automatic detection technologies can help minimize losses in such situations. The Wallet Compromise Detection Kit in Chainalysis Hexagate’s tool identifies possible wallet compromise.

Examples of this include sudden balances of zero, many large withdrawals, and transactions going to unknown addresses.

Machine-learning algorithms are trained based on past breaches to alert such systems to anomalies in behavior in the first few malicious transactions.

Moreover, there are pre-signing protection solutions, such as GateSigner, that screen transactions before they get approved. Once there are suspicious transactions, alerts are raised, or the transaction is halted before the funds are drained from the platform.


Also Read: U.S. Justice Department Seizes Crypto Scam Domain Linked to Southeast Asia

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.
Tags:

You May Also Like

STX Technical Analysis Feb 10

STX Technical Analysis Feb 10

The post STX Technical Analysis Feb 10 appeared on BitcoinEthereumNews.com. STX shows neutral momentum at RSI 40.77 level, confirming short-term bearish pressure
Share
BitcoinEthereumNews2026/02/10 14:10
Omdia: Mainland China’s cloud infrastructure market accelerates to 24% growth in Q3 2025

Omdia: Mainland China’s cloud infrastructure market accelerates to 24% growth in Q3 2025

LONDON–(BUSINESS WIRE)–#China–According to Omdia, Mainland China’s cloud infrastructure services market reached $13.4 billion in Q3 2025, growing 24% year on year
Share
AI Journal2026/02/10 14:15
Canada Canadian Portfolio Investment in Foreign Securities rose from previous $9.04B to $17.41B in July

Canada Canadian Portfolio Investment in Foreign Securities rose from previous $9.04B to $17.41B in July

The post Canada Canadian Portfolio Investment in Foreign Securities rose from previous $9.04B to $17.41B in July appeared on BitcoinEthereumNews.com. Information on these pages contains forward-looking statements that involve risks and uncertainties. Markets and instruments profiled on this page are for informational purposes only and should not in any way come across as a recommendation to buy or sell in these assets. You should do your own thorough research before making any investment decisions. FXStreet does not in any way guarantee that this information is free from mistakes, errors, or material misstatements. It also does not guarantee that this information is of a timely nature. Investing in Open Markets involves a great deal of risk, including the loss of all or a portion of your investment, as well as emotional distress. All risks, losses and costs associated with investing, including total loss of principal, are your responsibility. The views and opinions expressed in this article are those of the authors and do not necessarily reflect the official policy or position of FXStreet nor its advertisers. The author will not be held responsible for information that is found at the end of links posted on this page. If not otherwise explicitly mentioned in the body of the article, at the time of writing, the author has no position in any stock mentioned in this article and no business relationship with any company mentioned. The author has not received compensation for writing this article, other than from FXStreet. FXStreet and the author do not provide personalized recommendations. The author makes no representations as to the accuracy, completeness, or suitability of this information. FXStreet and the author will not be liable for any errors, omissions or any losses, injuries or damages arising from this information and its display or use. Errors and omissions excepted. The author and FXStreet are not registered investment advisors and nothing in this article is intended…
Share
BitcoinEthereumNews2025/09/18 02:38