Upbit Hacker Covers Their Tracks Again
Attacker Uses Railgun to Obscure Stolen Funds
The hacker behind the theft from the Upbit exchange is once again trying to erase their tracks. This time, they turned to Railgun — a privacy tool that mixes cryptocurrencies using zero-knowledge technology. Railgun typically checks whether incoming funds are linked to illicit activity, but in this case, the system didn’t flag anything because the associated addresses were simply too new.
The attack on Upbit totaled more than $36 million, most of it in Solana-ecosystem assets. The stolen tokens were quickly sold off, swapped into SOL, and then converted to USDC. The stablecoins were moved onto Ethereum, where the mixing process began. In the end, the hacker accumulated over 533 ETH, worth around $1.6 million. This pattern of behavior is often associated with North Korean hacking groups.
Upbit stated that the breach may have resulted from a flaw in its internal systems. According to the exchange, it was possible to infer private keys from publicly available hot-wallet data due to predictable hashing and weak cryptographic practices.
Railgun did not react because its database of suspicious addresses had not yet been updated. The hacker rapidly created new wallets and routed funds directly through DEXs, making identification significantly more difficult. The last detected wallet laundered 410 ETH and remained active for only a few hours.
Railgun continues to grow in popularity as interest in privacy within DeFi increases. As of November 2025, the protocol held $95 million in assets and generated $1.31 million in fees in the third quarter.