Upbit Shifts Nearly All Assets to Cold Storage as Exchange Responds to Security Concerns

bitcoinistPublicado em 2025-12-11Última atualização em 2025-12-11

Resumo

Following a hack that stole $30 million from a Solana hot wallet, Upbit is shifting nearly all customer assets to cold storage, now holding approximately 99% of funds offline. This move places it among the most conservative exchanges globally in terms of online asset exposure, surpassing cold storage ratios of major competitors like Coinbase and Kraken. The decision follows Upbit's second significant security breach and aligns with stricter regulatory expectations in South Korea. While this enhances security, analysts caution that minimal hot wallet reserves could slow withdrawals during high volatility, potentially exacerbating price discrepancies in Korea’s closed crypto market. Upbit has committed to reimbursing affected users and assures that its rebuilt systems will maintain liquidity under normal conditions.

In the aftermath of a hack that saw attackers steal 44.5 billion won (approximately $30 million) from a Solana hot wallet, Upbit has begun shifting nearly all customer assets into cold storage, a move that now places it among the most conservative platforms globally in terms of online asset exposure.

This transition marks one of the strongest security pivots by a major exchange, signaling a broader industry conversation about balancing rapid withdrawals with the need to reduce attack surfaces.

As digital asset markets continue to expand, Upbit’s response provides a real-time glimpse into how platforms balance operational liquidity against systemic cyber risks.

BTC's price records some small gains on the daily chart. Source: BTCUSD on Tradingview

Upbit Pushes Hot Wallet Usage Toward Zero

Following its internal review and system overhaul, Upbit confirmed that it now stores approximately 99% of user assets in cold wallets, with hot wallet exposure reduced to about 1% and expected to decrease further.

As of late October, the exchange held 98.33% of customer funds offline, a rate already well above the 80% minimum required under South Korea’s Virtual Asset User Protection Act.

This shift follows a pattern of rising caution. The recent breach was Upbit’s second significant attack, occurring on November 27, mirroring a 2019 incident that saw more than 342,000 ETH drained from its systems.

This year’s Solana-based attack resulted in withdrawals across 24 tokens within less than an hour, prompting an immediate shutdown of hot wallet operations and emergency transfers to cold storage. Upbit has pledged to fully reimburse affected users from corporate reserves.

Domestic data suggests that the exchange already leads the market in cold storage usage, maintaining the lowest hot wallet ratio among local competitors, whose cold wallet shares range from 82% to 90%.

Security Benchmark Sets Pressure on Global and Local Exchanges

Upbit’s near-99% cold wallet ratio surpasses the standards of major global exchanges. Coinbase stores about 98% of its funds offline, while Kraken’s ratio sits between 95% and 97%.

Several Asian exchanges, including OKX and Gate.io, maintain similar levels. With Upbit’s latest update, the platform now stands at the forefront of global cold storage practices.

Industry observers note that the move aligns with broader regulatory momentum. South Korea’s Financial Services Commission is considering new rules that would require exchanges to compensate users for losses resulting from hacks, regardless of fault, similar to the standards imposed on banks.

Liquidity Questions Linger in a Restricted Market

While security is at the center of Upbit’s restructuring, analysts caution that running with minimal hot wallet reserves may slow withdrawals during periods of heightened market volatility.

South Korea’s crypto market is largely closed to foreign participants, restricting arbitrage and creating conditions where delays can exacerbate price discrepancies, commonly known as the “Kimchi premium.”

During last month’s temporary withdrawal suspension, liquidity was effectively trapped, resulting in sharply widening price gaps between the Korean and global markets. Still, Upbit maintains that its rebuilt systems and predictive models will ensure sufficient liquidity under normal trading conditions.

Cover image from ChatGPT, BTCUSD chart from Tradingview

Leituras Relacionadas

The Essence of AI Layoffs: Why More AI Adoption Leads to More Corporate Anxiety?

The author, awaiting potential inclusion on an 8000-person layoff list, analyzes the true nature of recent "AI-driven" layoffs. They argue that while AI use, particularly tools like Claude for code generation, has skyrocketed and boosted developer output (e.g., 2-5x more code commits), this has not translated into proportional business growth or revenue. The core issue is a misalignment between increased "Input" (code) and tangible "Outcomes" (user value, revenue). AI acts as a costly B2B SaaS, inflating operational expenses without guaranteed returns. Two key problems emerge: 1) The friction that once filtered out bad ideas is gone, as AI allows cheap pursuit of even weak concepts. 2) Organizational "alignment tax"—the difficulty of coordinating across teams—becomes crippling when development velocity outpaces consensus-building. Thus, layoffs serve two immediate purposes: 1) To offset ballooning AI costs (Token consumption) and maintain cash flow, as rising input costs without outcome growth destroys unit economics. 2) To reduce organizational bloat and alignment friction by simply removing teams, thereby speeding up execution in the short term. Therefore, these layoffs are fundamentally caused by AI, even if AI doesn't directly replace roles. They represent a painful correction until companies learn to convert AI-driven productivity into real business outcomes and streamline organizational coordination to match the new pace of work. The cycle will continue until this learning curve is mastered.

marsbitHá 53m

The Essence of AI Layoffs: Why More AI Adoption Leads to More Corporate Anxiety?

marsbitHá 53m

Can the Solana Foundation and Google's Collaboration on Pay.sh Bridge the Payment Link Between Web2 and Web3 in the Agent Economy?

Solana Foundation, in collaboration with Google Cloud, has launched Pay.sh, a payment gateway designed to bridge the gap between AI agents and enterprise-grade service infrastructure. The initiative aims to solve a key bottleneck in the "agent economy": existing payment systems are ill-suited for autonomous AI agents. Traditional methods like credit cards require human verification, while newer on-chain protocols like x402 and MPP create a separate, Web3-native system that raises barriers for service providers. Pay.sh functions as a universal payment layer. It allows users to fund a Solana wallet via credit card or stablecoin, which then acts as an identity and payment proxy for AI agents. When an agent needs to access a paid API service (e.g., Google Cloud, Alibaba Cloud), Pay.sh handles the transaction seamlessly. It leverages the HTTP 402 status code ("Payment Required") to initiate payments, intelligently choosing between one-time transfers (x402-style) or session-based authorizations (MPC-style) based on the service's billing model. This spares agents from manual account registration and API key management. A key feature for service providers is low integration effort. They can adopt Pay.sh by providing a declarative configuration file, enabling features like tiered pricing, free tiers, and automatic revenue splitting to multiple addresses (e.g., for royalties, cloud costs). Providers can also list their APIs in a central Pay Skill Registry for agent discovery. The collaboration with Google Cloud provides crucial infrastructure for API proxying, traffic routing, and compliance logging, aiming to keep agent activities within regulated boundaries. By connecting Web2 services with Web3 payment rails, Pay.sh positions the Solana wallet as a foundational identity and payment tool for AI agents, potentially driving more transaction volume to the Solana ecosystem. However, the report notes challenges. The service registry currently lacks robust vetting, risking exposure to unauthorized or malicious third-party APIs. Pay.sh also inherits security and compatibility risks from its underlying payment protocols (x402, MPC). Furthermore, adoption may be hindered by varying regional data privacy and payment compliance regulations among API providers. Despite these hurdles, Pay.sh represents a significant step towards integrating Web2 and Web3 for autonomous agent commerce.

marsbitHá 1h

Can the Solana Foundation and Google's Collaboration on Pay.sh Bridge the Payment Link Between Web2 and Web3 in the Agent Economy?

marsbitHá 1h

Bitcoin's Bull-Bear Cycle Indicator Turns Positive for the First Time in 7 Months: End of Bear Market or False Breakout?

Bitcoin's "Bull-Bear Market Cycle Indicator" from CryptoQuant has turned positive for the first time since October 2025. This gauge, based on the P&L Index relative to its 365-day moving average, suggests a potential shift from a bear market phase. Concurrently, the Bull Score Index rose to a neutral reading of 50 in late April. The indicator's move into positive territory follows a roughly 35% price rebound from a low near $60,000 in February to above $81,000. The recovery over approximately three months was faster than the 12-month period observed during the 2022 bear market. However, analysts caution against premature optimism, citing a historical precedent from March 2022. Back then, the Bull Score Index briefly hit 50, but it proved to be a false signal as Bitcoin's price subsequently plunged further. Structural differences exist in the current cycle, including consistent inflows into spot Bitcoin ETFs and an increase in large holder addresses. Yet, some models, referencing the four-year halving cycle, suggest a potential deeper bottom near $50,000 might still be possible around late 2026. In summary, while on-chain data shows marked improvement and the worst panic may be over, market participants remain cautious. A convincing trend reversal confirmation likely requires Bitcoin to sustainably break above key resistance, such as the 200-day moving average near $82,000.

marsbitHá 1h

Bitcoin's Bull-Bear Cycle Indicator Turns Positive for the First Time in 7 Months: End of Bear Market or False Breakout?

marsbitHá 1h

Trading

Spot
Futuros
活动图片