Upbit Shifts Nearly All Assets to Cold Storage as Exchange Responds to Security Concerns

bitcoinistPublished on 2025-12-11Last updated on 2025-12-11

Abstract

Following a hack that stole $30 million from a Solana hot wallet, Upbit is shifting nearly all customer assets to cold storage, now holding approximately 99% of funds offline. This move places it among the most conservative exchanges globally in terms of online asset exposure, surpassing cold storage ratios of major competitors like Coinbase and Kraken. The decision follows Upbit's second significant security breach and aligns with stricter regulatory expectations in South Korea. While this enhances security, analysts caution that minimal hot wallet reserves could slow withdrawals during high volatility, potentially exacerbating price discrepancies in Korea’s closed crypto market. Upbit has committed to reimbursing affected users and assures that its rebuilt systems will maintain liquidity under normal conditions.

In the aftermath of a hack that saw attackers steal 44.5 billion won (approximately $30 million) from a Solana hot wallet, Upbit has begun shifting nearly all customer assets into cold storage, a move that now places it among the most conservative platforms globally in terms of online asset exposure.

This transition marks one of the strongest security pivots by a major exchange, signaling a broader industry conversation about balancing rapid withdrawals with the need to reduce attack surfaces.

As digital asset markets continue to expand, Upbit’s response provides a real-time glimpse into how platforms balance operational liquidity against systemic cyber risks.

BTC's price records some small gains on the daily chart. Source: BTCUSD on Tradingview

Upbit Pushes Hot Wallet Usage Toward Zero

Following its internal review and system overhaul, Upbit confirmed that it now stores approximately 99% of user assets in cold wallets, with hot wallet exposure reduced to about 1% and expected to decrease further.

As of late October, the exchange held 98.33% of customer funds offline, a rate already well above the 80% minimum required under South Korea’s Virtual Asset User Protection Act.

This shift follows a pattern of rising caution. The recent breach was Upbit’s second significant attack, occurring on November 27, mirroring a 2019 incident that saw more than 342,000 ETH drained from its systems.

This year’s Solana-based attack resulted in withdrawals across 24 tokens within less than an hour, prompting an immediate shutdown of hot wallet operations and emergency transfers to cold storage. Upbit has pledged to fully reimburse affected users from corporate reserves.

Domestic data suggests that the exchange already leads the market in cold storage usage, maintaining the lowest hot wallet ratio among local competitors, whose cold wallet shares range from 82% to 90%.

Security Benchmark Sets Pressure on Global and Local Exchanges

Upbit’s near-99% cold wallet ratio surpasses the standards of major global exchanges. Coinbase stores about 98% of its funds offline, while Kraken’s ratio sits between 95% and 97%.

Several Asian exchanges, including OKX and Gate.io, maintain similar levels. With Upbit’s latest update, the platform now stands at the forefront of global cold storage practices.

Industry observers note that the move aligns with broader regulatory momentum. South Korea’s Financial Services Commission is considering new rules that would require exchanges to compensate users for losses resulting from hacks, regardless of fault, similar to the standards imposed on banks.

Liquidity Questions Linger in a Restricted Market

While security is at the center of Upbit’s restructuring, analysts caution that running with minimal hot wallet reserves may slow withdrawals during periods of heightened market volatility.

South Korea’s crypto market is largely closed to foreign participants, restricting arbitrage and creating conditions where delays can exacerbate price discrepancies, commonly known as the “Kimchi premium.”

During last month’s temporary withdrawal suspension, liquidity was effectively trapped, resulting in sharply widening price gaps between the Korean and global markets. Still, Upbit maintains that its rebuilt systems and predictive models will ensure sufficient liquidity under normal trading conditions.

Cover image from ChatGPT, BTCUSD chart from Tradingview

Related Reads

$292 Million KelpDAO Cross-Chain Bridge Hack: Who Should Foot the Bill?

On April 18, 2026, an attacker stole 116,500 rsETH (worth ~$292M) from KelpDAO’s cross-chain bridge in 46 minutes—the largest DeFi exploit of 2026. The stolen assets were deposited into Aave V3 as collateral, causing $177–200M in bad debt and triggering a cascade of losses across nine DeFi protocols. Aave’s TVL dropped by ~$6B overnight. This legal analysis argues that KelpDAO and LayerZero Labs share concurrent liability, with fault apportioned 60%/40%. KelpDAO negligently configured its bridge with a 1-of-1 decentralized verifier network (DVN)—a single point of failure—despite LayerZero’s explicit recommendation of a 2-of-3 setup. LayerZero, which operated the compromised DVN, failed to secure its RPC infrastructure against a known poisoning attack vector. Both protocols’ terms of service cap liability at $200 (KelpDAO) or $50 (LayerZero), but these limits are likely unenforceable due to unconscionability, gross negligence exceptions, and potential securities law invalidation (if rsETH is deemed a security under the Howey test). Aave’s governance also faces fiduciary duty claims for raising rsETH’s loan-to-value ratio to 93%—far above competitors’ 72–75%—without adequately assessing bridge risks, amplifying the systemic fallout. Practical recovery targets include LayerZero Labs (a registered Canadian entity), KelpDAO’s founders, auditors, and identifiable Aave governance delegates. The incident underscores escalating legal risks for DeFi protocols, infrastructure providers, and governance participants.

marsbit5m ago

$292 Million KelpDAO Cross-Chain Bridge Hack: Who Should Foot the Bill?

marsbit5m ago

Insider Trading in War: 5 People Involved, the Highest Earner Was Arrested

On April 24, the U.S. Department of Justice arrested U.S. Army Special Forces Staff Sergeant Gannon Ken Van Dyke for insider trading related to the capture of Venezuelan President Nicolás Maduro on January 3. Van Dyke allegedly profited over $400,000 by placing bets on a prediction market, Polymarket, using insider knowledge of the covert operation. According to the indictment, Van Dyke registered an account (0x31a5) on December 26 and made a series of bets predicting Maduro’s capture and U.S. military involvement in Venezuela. He withdrew most of his funds on the day of the operation and attempted to obscure his tracks by transferring assets through crypto and brokerage accounts. This case marks the first time the DOJ has prosecuted insider trading on Polymarket. PolyBeats had previously identified five suspicious accounts, including Van Dyke’s—the highest earner—in January. The other accounts, with profits ranging from $34,000 to $145,000, remain under unofficial scrutiny but have not been charged. Their lower profits, indirect access to information, and unclear legal boundaries may complicate prosecution. Polymarket has since strengthened its market integrity rules, explicitly prohibiting trading based on confidential or insider information. Van Dyke’s arrest, nearly four months after his trades, signals increased regulatory attention and the persistent traceability of blockchain-based transactions.

marsbit6m ago

Insider Trading in War: 5 People Involved, the Highest Earner Was Arrested

marsbit6m ago

Bitwise: Bullish on Bitcoin's Performance in the Second Half of the Year, AI and Regulation Will Spark a New Altcoin Season

Bitwise CIO Matt Hougan and Research Lead Ryan Rasmussen express strong bullish sentiment on Bitcoin's long-term prospects, suggesting that its $1 million price target may be too conservative. They argue Bitcoin serves a dual role: as digital gold and a potential global settlement asset, especially amid declining trust in traditional monetary systems. Despite a weak Q1 2026 where nearly all crypto assets and prices saw double-digit declines, the analysts remain optimistic due to strong forward-looking catalysts, including institutional adoption via Bitcoin ETFs from major firms like Morgan Stanley and Goldman Sachs. Geopolitical instability, such as Iran’s mention of using Bitcoin for international payments, increases the value of Bitcoin’s “out-of-the-money call option” as a non-political, global settlement currency. This enhances its appeal beyond a mere store of value. . Additionally, Hougan highlights that a clearer regulatory token framework under current SEC leadership, combined with AI efficiency gains and high-performance blockchains, could fuel a new “altseason” by late 2026. This may lead to a wave of legitimate, value-capturing token projects, unlike the earlier ICO boom. . Bitwise also announced an Avalanche ETF, citing its unique architecture and rapid growth in real-world asset (RWA) tokenization, which has surged 10x to nearly $30 billion in two years. The firm believes Layer 1 blockchains are still early in their growth cycle, with significant potential ahead.

marsbit52m ago

Bitwise: Bullish on Bitcoin's Performance in the Second Half of the Year, AI and Regulation Will Spark a New Altcoin Season

marsbit52m ago

Trading

Spot
Futures
活动图片