Upbit Shifts Nearly All Assets to Cold Storage as Exchange Responds to Security Concerns

bitcoinistPublished on 2025-12-11Last updated on 2025-12-11

Abstract

Following a hack that stole $30 million from a Solana hot wallet, Upbit is shifting nearly all customer assets to cold storage, now holding approximately 99% of funds offline. This move places it among the most conservative exchanges globally in terms of online asset exposure, surpassing cold storage ratios of major competitors like Coinbase and Kraken. The decision follows Upbit's second significant security breach and aligns with stricter regulatory expectations in South Korea. While this enhances security, analysts caution that minimal hot wallet reserves could slow withdrawals during high volatility, potentially exacerbating price discrepancies in Korea’s closed crypto market. Upbit has committed to reimbursing affected users and assures that its rebuilt systems will maintain liquidity under normal conditions.

In the aftermath of a hack that saw attackers steal 44.5 billion won (approximately $30 million) from a Solana hot wallet, Upbit has begun shifting nearly all customer assets into cold storage, a move that now places it among the most conservative platforms globally in terms of online asset exposure.

This transition marks one of the strongest security pivots by a major exchange, signaling a broader industry conversation about balancing rapid withdrawals with the need to reduce attack surfaces.

As digital asset markets continue to expand, Upbit’s response provides a real-time glimpse into how platforms balance operational liquidity against systemic cyber risks.

BTC's price records some small gains on the daily chart. Source: BTCUSD on Tradingview

Upbit Pushes Hot Wallet Usage Toward Zero

Following its internal review and system overhaul, Upbit confirmed that it now stores approximately 99% of user assets in cold wallets, with hot wallet exposure reduced to about 1% and expected to decrease further.

As of late October, the exchange held 98.33% of customer funds offline, a rate already well above the 80% minimum required under South Korea’s Virtual Asset User Protection Act.

This shift follows a pattern of rising caution. The recent breach was Upbit’s second significant attack, occurring on November 27, mirroring a 2019 incident that saw more than 342,000 ETH drained from its systems.

This year’s Solana-based attack resulted in withdrawals across 24 tokens within less than an hour, prompting an immediate shutdown of hot wallet operations and emergency transfers to cold storage. Upbit has pledged to fully reimburse affected users from corporate reserves.

Domestic data suggests that the exchange already leads the market in cold storage usage, maintaining the lowest hot wallet ratio among local competitors, whose cold wallet shares range from 82% to 90%.

Security Benchmark Sets Pressure on Global and Local Exchanges

Upbit’s near-99% cold wallet ratio surpasses the standards of major global exchanges. Coinbase stores about 98% of its funds offline, while Kraken’s ratio sits between 95% and 97%.

Several Asian exchanges, including OKX and Gate.io, maintain similar levels. With Upbit’s latest update, the platform now stands at the forefront of global cold storage practices.

Industry observers note that the move aligns with broader regulatory momentum. South Korea’s Financial Services Commission is considering new rules that would require exchanges to compensate users for losses resulting from hacks, regardless of fault, similar to the standards imposed on banks.

Liquidity Questions Linger in a Restricted Market

While security is at the center of Upbit’s restructuring, analysts caution that running with minimal hot wallet reserves may slow withdrawals during periods of heightened market volatility.

South Korea’s crypto market is largely closed to foreign participants, restricting arbitrage and creating conditions where delays can exacerbate price discrepancies, commonly known as the “Kimchi premium.”

During last month’s temporary withdrawal suspension, liquidity was effectively trapped, resulting in sharply widening price gaps between the Korean and global markets. Still, Upbit maintains that its rebuilt systems and predictive models will ensure sufficient liquidity under normal trading conditions.

Cover image from ChatGPT, BTCUSD chart from Tradingview

Related Reads

Bitcoin Withdrawals Continue: 8 Years of Storage in a Coldcard Cold Wallet Ended in Zero

Coldcard Hardware Wallet Hacked: Losses Mount Due to Vulnerable Seed Generation A critical vulnerability in Coldcard hardware wallets has led to a continued wave of fund thefts. According to Galaxy Research, the total stolen has reached 1,367.05 BTC (approx. $88.6 million) from 4,585 addresses, a significant increase from the initial 594.5 BTC reported on July 30, 2026. Most of the stolen funds remain on the attackers' addresses. The issue is not with the current firmware, which Coinkite has updated, but with seed phrases generated on vulnerable devices between March 2021 and the release of fixed firmware versions. Due to a programmer error, devices switched from using a hardware random number generator to the software-based Yasmarang generator, which was initialized with publicly accessible data like the chip's serial number. This made the seed phrases predictable through offline brute-force attacks, meaning wallets remain at risk until funds are moved to a new wallet generated with the patched firmware. Affected devices include Mk2/Mk3 with firmware 4.0.1–4.1.9 (and up to 5.0.3), Mk4/Mk5 up to version 5.6.0, and Q models up to 1.5.0Q. The only exceptions are seeds created with a high-entropy method like at least 50 independent dice rolls or a strong unique BIP-39 passphrase. All other owners must generate a new seed on the fixed firmware and transfer their assets. A case highlighting the human impact involves a 39-year-old long-term investor who lost 2 BTC (approx. $130,000) in minutes. He had accumulated the Bitcoin over eight years through physical labor, viewing it as a financial lifeline and a retirement plan in a country suffering from hyperinflation. His story underscores that even conservative "buy and hold in cold storage" strategies can be compromised by such underlying technical flaws. From a technical perspective, this incident echoes historical failures where weak random number generators undermined cryptographic security, challenging the assumption that offline storage is automatically foolproof.

cryptonews.ru4h ago

Bitcoin Withdrawals Continue: 8 Years of Storage in a Coldcard Cold Wallet Ended in Zero

cryptonews.ru4h ago

Trading

Spot
活动图片