South Korea Targets Dunamu Over $30M Upbit Hack
Eight months after Upbit lost $30M to thieves, the FSS finally moved, but Korean crypto law carries no direct sanction clause for hacks, leaving the actual penalty still undefined.
Eight months after Upbit lost $30M to thieves, the FSS finally moved, but Korean crypto law carries no direct sanction clause for hacks, leaving the actual penalty still undefined.
The blast radius is upstream of any exploit: a compromised developer laptop at a subcontractor can inject tainted code into a wallet used by tens of millions before the next release ships.
The campaign weaponises USB shortcuts, clipboard monitoring, and Tor to drain wallets, with an Uber Eats delivery breadcrumb hinting at how far the operators are willing to mass-pollute endpoints.
The 21-year-old allegedly hid credential and wallet-draining malware inside five Steam titles, infecting about 8,000 machines and draining roughly $220,000 before agents traced crypto payouts to Uber…
No assets or data were compromised and no malicious code shipped, but the incident lands as a fresh reminder that DPRK IT-worker infiltration of Western crypto firms is structural, not anecdotal.
The collapse lands just as MiCA's transitional deadline forces roughly three in four registered EU crypto firms off the market, turning a single venue failure into a continent-wide test of…
The compromise was unusual: the thread promoted tokenization arguments rather than a token sale, making it less obvious than a typical crypto account takeover.
The alleged 2020-era breach dwarfs prior state-actor election incidents and lands days before a US-China leader call, raising fresh questions over data-resilience and retaliation posture.
The DeFi lending protocol Morpho and sister project YEET both lost their public frontends for roughly three hours after an AWS CloudFront disruption, with user funds untouched.
The argument reframes the threat: Bybit lost $1.5B and Radiant $50M not because keys leaked, but because valid signatures authorized the wrong thing, a gap ERC-7730 and policy wallets are now trying…
The first Bank of Korea hike in over three years is the macro anchor, while a $2.4M LayerZero wallet breach and Summer.fi shutdown put DeFi risk back on the table.
The attacker converted the full haul into 12,084 ETH at ~$1,966 and routed most of it through Tornado Cash, the laundering pattern that keeps drawing OFAC's attention.
Three catalysts stack into a single US session: June CPI at 8:30 ET, Fed Chair Warsh's testimony at 10 ET, and US blockade enforcement at 4 PM. Oil already closed 9% higher Monday.
The X accounts for SpaceX-linked AI and satellite-internet brands were hijacked to promote a memecoin that the operator minted and dumped in minutes for roughly $125K.
The wallet acquired the stash at $6,513 per BTC in 2018 and hadn't touched it since, making this one of the larger long-dormant profit-taking events of the cycle.
The flight ranks Gate second among CEXs for outflows over the same window, while Binance pulled $308M of net inflows, evidence users are rotating venues rather than exiting crypto entirely.
The exploit is already six weeks old, but the wallet's swelling ETH balance turns the case into a live tracking exercise for every researcher watching the funds.
On-chain investigator zachxbt traced the haul through an immediate dump, a bridge to Ethereum, and a swap into 7,918 ETH, a textbook private-key compromise playbook.
The two risks are real but on very different clocks: quantum is a slow-moving cryptographic threat, while the fee-market gap shows up the moment the next halving cuts the block reward in half again.
The Hong Kong SFC is forcing licensed exchanges to replace one-time passwords with cryptographic 2FA, and the liability shift is the part exchanges are reading closely.