• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer
  • About TronWeekly
  • Write for us
  • Terms and Conditions
  • Privacy Policy
  • Disclaimer
  • Contact
  • All Posts
  • Advertise

TronWeekly

Crypto World News

  • Home
  • Latest News
  • Opinion
    • Education
    • Best TRON Wallets
    • Beginner’s guide to TRON
    • Tron Tokens
    • Market Analysis
  • Industry
    • Tron Exchange
    • Project Review
  • Press Release
  • Bitcoin (BTC)
  • Ripple (XRP)
  • Advertise
  • About TronWeekly
    • The Team
    • Editorial Policy
    • Write for us
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • Contact
You are here: Home / Cryptocurrency News / South Korean Crypto Exchange Loses $35 Million in 15-Minute Hot Wallet Hack

South Korean Crypto Exchange Loses $35 Million in 15-Minute Hot Wallet Hack

By Mishal Ali | Edited By Messam Raza,December 4, 2025, 2:00 PM

crypto
  • A South Korean exchange lost $35 million in 15 minutes after attackers drained hundreds of hot wallets.
  • Multi-chain withdrawal systems and complex cloud setups make CEXs increasingly vulnerable.
  • Real-time detection tools like Hexagate and GateSigner can limit losses during wallet breaches.

Earlier this year, one of South Korea’s largest cryptocurrency exchanges suffered a major security breach that drained hundreds of hot wallets in just 15 minutes.

According to a Chainalysis report, the attackers stole roughly ₩44.5 billion KRW, equivalent to $33–35 million, before the exchange could halt withdrawals. Assets taken included USDC, BONK, SOL, ORCA, RAY, PYTH, and JUP.

The exchange was able to freeze over half of the stolen funds, including ₩23 billion KRW worth of LAYER tokens, but the remaining amount was unrecoverable.

Analysis of the attack shows that it was not caused by a smart contract bug or a user error. Instead, the breach targeted the hot-wallet signing flow, a critical step in approving outgoing transactions.

The attackers executed hundreds of transfers in a highly automated and rapid manner, highlighting a pattern common in sophisticated CEX breaches.

Also Read: Retail Traders’ Interest in Crypto Fades, Signaling a Potential Market Bottom

Hackers Target Multi-Chain Crypto Withdrawal Systems

This particular incident reveals another trend: centralized exchanges and custodians are being impacted by breaches that are happening more frequently and are more costly.

Observers of hackers like the Lazarus Group report that hackers are interested in platforms with complicated multi-chain withdrawal systems because only one vulnerability can result in losses totaling millions of dollars.

Similar examples of previous hacks include Bybit, BTCTurk, SwissBorg, and Phemex.

The reasons are many, from social engineering and malware threats, and in many cases, from internal threats too, but in the end, the common result has always been significant losses in terms of money due to the delayed detection of the issue.

According to analysts, in this world, there are no absolute ways of being secure. The exploit demonstrates the difficulty in tracing the balances in multiple blockchains.

For example, the balances in the Solana wallets also behaved in the usual manner for quite a number of weeks until they went to zero when the attack happened.

There were 80 major transactions recorded in 15 minutes by the exchange, a drastic increase from the single $100,000 transaction recorded in the preceding week.

Real-Time Monitoring Reduces Financial Losses

Real-time tracking and automatic detection technologies can help minimize losses in such situations. The Wallet Compromise Detection Kit in Chainalysis Hexagate’s tool identifies possible wallet compromise.

Examples of this include sudden balances of zero, many large withdrawals, and transactions going to unknown addresses.

Machine-learning algorithms are trained based on past breaches to alert such systems to anomalies in behavior in the first few malicious transactions.

Moreover, there are pre-signing protection solutions, such as GateSigner, that screen transactions before they get approved. Once there are suspicious transactions, alerts are raised, or the transaction is halted before the funds are drained from the platform.


Also Read: U.S. Justice Department Seizes Crypto Scam Domain Linked to Southeast Asia

Filed Under: Cryptocurrency News, Crypto Scam

About Mishal Ali

Mishal Ali is a Policy and Regulations Reporter at Tron Weekly with over four years of experience covering the global crypto and blockchain space. Her reporting focuses on crypto regulations and policy, alongside Bitcoin, Ethereum, altcoins, DeFi, NFTs, Web3, Layer 2 solutions, and AI-driven crypto use cases. She also tracks Ripple-related developments, enforcement actions, licensing updates, and crypto scams and fraud trends, helping readers understand regulatory and compliance risks.

🔗 Connect on LinkedIn

Twitter LinkedIn

Primary Sidebar

Recent Posts

  • HYPE Price Outlook: Support Holds Strong as Bulls Aim for $50 Breakout May 18, 2026
  • Goldman Sachs Predicts Gold Price Recovery as Central Banks Increase Buying Activity May 18, 2026
  • US Debt Crisis: China Dumps $693 Billion Bonds May 18, 2026
  • Capital B Acquires 192 BTC for $15.2M, Expands Bitcoin Treasury to 3,135 BTC May 18, 2026
  • BNB ETF Nears Launch After Strong Filing of Amended S-1 prospectuses with SEC May 18, 2026

Footer

News

  • Latest News
  • Altcoin News
  • Bitcoin (BTC)
  • Blockchain
  • Tron (TRX)
  • World

Digest

  • Meet the Founder
  • Price Winning Article
  • DeFi
  • Cyber Security
  • Crypto Scam

Industry

  • Project Review
  • Technology
  • Fintech
  • Tron Exchange
  • New in Town

Tron Universe

  • Event and Tron Parties
  • New in Town
  • Tron Tokens

FOLLOW US

  • Facebook
  • Telegram
  • Twitter
  • Linkedin

Editorial Policy | Privacy Policy | Disclaimer | Terms and Conditions | Masthead

Copyright © 2026 · Tron Weekly. All Rights Reserved. NOTE: Tron Weekly is an independent crypto news site that adheres to the strict journalism policy anchored on transparency, trust, and objectivity, we have no affiliation with the TRON Foundation, its founder Justin Sun or any other cryptocurrency firm.