Skip to main content
AVOID.NET
Upbitreviewed 2026-09-07 · 41 claims checked

Fact-check findings

What an automated fact-checker found when it re-read Upbit against the sources the page cites. Only the most recent review is shown.

Read this first

These findings are produced by an automated reviewer, and its results vary between runs: the same page, checked three times on the same day, came back with 15%, 20% and 34% of its claims disputed, mostly because each run extracted a different number of claims. Treat what follows as leads, not rulings.

“Disputed” means the reviewer could not reconcile the claim with the evidence it cited. It does not mean the claim is false. “Unverifiable” means no reachable source settled it either way.

Nothing here changes the page on its own. A proposed correction is applied only after a human moderator approves it; until then the page reads as it did when reviewed.

disputed

12 claims

The reviewer could not reconcile the claim with the evidence it cited. This is a lead, not a ruling that the claim is false.

  1. #10[disputed][awaiting moderator]in section: Background
    Dunamu was acquired by a new parent in late 2025, with the acquisition closing on the same date as the second major security breach.
    reviewerDunamu was acquired by a new parent in late 2025, with the acquisition closing on the same date as the second (2025) security breach.The deal was announced/board-approved on Nov 26, 2025, one day before the Nov 27 hack; it had not closed and was still awaiting shareholder votes (May 2026) and a stock-exchange date (June 30, 2026). The page's claim that the acquisition 'closed' on the hack date is contradicted by primary reporting.
    Proposed correction (not yet applied)
    Dunamu agreed to be acquired by Naver in a roughly $10.3 billion all-stock deal announced on November 26, 2025, one day before the second major security breach; the acquisition had not closed as of mid-2026 and remained subject to shareholder votes and regulatory approval.
  2. #11[disputed][awaiting moderator]in section: The 2025 Hack
    On November 27, 2025 — exactly six years after the 2019 incident, and on the same day Dunamu's acquisition closed — Upbit suffered a second significant security breach.
    reviewerThe Nov 27, 2025 breach occurred on the same day Dunamu's acquisition closed.Same underlying error as the Background section: the acquisition was announced, not closed, on/around this date.
    Proposed correction (not yet applied)
    On November 27, 2025 — exactly six years after the 2019 incident, and one day after Naver's acquisition of Dunamu was announced — Upbit suffered a second significant security breach.
  3. #12[disputed][awaiting moderator]in section: The 2025 Hack
    South Korean authorities again attributed the attack to North Korea's Lazarus Group, noting that the timing — on the sixth anniversary of the prior hack and on the acquisition closing date — was consistent with the group's pattern of targeting significant dates.
    reviewerSouth Korean authorities noted the 2025 hack's timing coincided with the acquisition closing date.The Lazarus Group attribution itself is well supported; only the 'acquisition closing date' framing is in error.
    Proposed correction (not yet applied)
    South Korean authorities again attributed the attack to North Korea's Lazarus Group, noting that the timing — on the sixth anniversary of the prior hack and one day after the Naver acquisition was announced — was consistent with the group's pattern of targeting significant dates.
  4. #24[disputed][awaiting moderator]in the timeline
    2021
    reviewerThe Seoul Southern District Court acquitted all three executives for lack of evidence in 2021.The page's own cited source contradicts its timeline date. Note the page's timeline 'date_original' field also reads '2021-01-01' and should likewise be corrected.
    Proposed correction (not yet applied)
    2020
  5. #26[disputed][awaiting moderator]in section: Regulatory History
    The FIU renewed Dunamu's registration on December 23, 2023, after a 16-month review process that concluded alongside a major enforcement action.
    reviewerThe FIU renewed Dunamu's VASP registration on December 23, 2023, after a 16-month review that concluded alongside a major enforcement action.The year is off by two: the renewal application (Aug 2024) plus a 16-month review lands in Dec 2025, not Dec 2023, and multiple sources date the renewal acceptance to Dec 23, 2025.
    Proposed correction (not yet applied)
    The FIU renewed Dunamu's registration on December 23, 2025, after a 16-month review process that concluded alongside a major enforcement action.
  6. #27[disputed][awaiting moderator]in the timeline
    2023-12-23
    reviewerFIU renewed Dunamu's VASP registration on Dec 23, 2023.Same underlying date error as the Regulatory History section text.
    Proposed correction (not yet applied)
    2025-12-23
  7. #29[disputed][awaiting moderator]in section: Regulatory History
    On January 9, 2025, the FIU issued a preliminary notice of sanctions against Dunamu, alleging approximately 5.3 million instances of inadequate customer due diligence and 15 instances of failure to report suspicious transactions.
    reviewerOn Jan 9, 2025 the FIU issued a preliminary notice alleging ~5.3 million CDD violations and 15 unreported suspicious transactions.The page appears to conflate two distinct FIU notices: the January 2025 notice (which cited a much smaller violation count and concerned unregistered overseas VASP dealings) and a later, separate November 2025 notice that produced the 5.3 million figure.
    Proposed correction (not yet applied)
    On January 9, 2025, the FIU issued a preliminary notice of sanctions against Dunamu, alleging an estimated 500,000–700,000 instances of inadequate customer due diligence tied to dealings with unregistered overseas virtual asset service providers; the larger figure of approximately 5.3 million customer due diligence failures and 15 unreported suspicious transactions was cited in a separate FIU notice issued in November 2025.
  8. #30[disputed][awaiting moderator]in section: Regulatory History
    On February 25, 2025, the FIU formalized sanctions: a fine of 35.2 billion won (approximately $25 million) and a three-month partial business suspension prohibiting Upbit from onboarding new customers, effective March 7 to June 6, 2025.
    reviewerOn Feb 25, 2025 the FIU formalized a 35.2 billion won ($25M) fine and a three-month suspension effective March 7 to June 6, 2025.Multiple sources indicate the 35.2 billion won fine was a distinct, later (Nov 2025) action from the Feb 25, 2025 suspension order; the page presents them as a single event finalized in February.
    Proposed correction (not yet applied)
    On February 25, 2025, the FIU formalized a three-month partial business suspension prohibiting Upbit from onboarding new customers, effective March 7 to June 6, 2025; a separate fine of 35.2 billion won (approximately $25 million) was proposed by the FIU in November 2025 and remained subject to finalization.
  9. #31[disputed][awaiting moderator]in the timeline
    FIU issues preliminary sanctions notice against Dunamu, citing 5.3 million KYC violations and 15 unreported suspicious transactions.
    reviewerFIU issues preliminary sanctions notice against Dunamu citing 5.3 million KYC violations and 15 unreported suspicious transactions [timeline].Same conflation as the Regulatory History section, reproduced in the timeline.
    Proposed correction (not yet applied)
    FIU issues preliminary sanctions notice against Dunamu, citing an estimated 500,000-700,000 KYC violations tied to dealings with unregistered overseas virtual asset service providers.
  10. #32[disputed][awaiting moderator]in the timeline
    FIU formalizes a 35.2 billion KRW (~$25M) fine and three-month partial business suspension on Dunamu, effective March 7.
    reviewerFIU formalizes a 35.2 billion KRW fine and three-month suspension on Dunamu, effective March 7 [timeline].Same conflation as the Regulatory History section, reproduced in the timeline.
    Proposed correction (not yet applied)
    FIU formalizes a three-month partial business suspension on Dunamu, effective March 7; a separate 35.2 billion KRW (~$25M) fine was proposed by the FIU in November 2025.
  11. #39[disputed][awaiting moderator]in section: Risk Assessment
    The FIU's finding of 5.3 million KYC violations and 15 unreported suspicious transactions — the largest AML enforcement action in South Korean crypto history at the time — indicates systemic compliance failures at scale.
    reviewerThe FIU's finding of 5.3 million KYC violations and 15 unreported suspicious transactions was the largest AML enforcement action in South Korean crypto history at the time.Repeats the same date conflation found in the Regulatory History section.
    Proposed correction (not yet applied)
    The FIU's finding of approximately 5.3 million customer due diligence violations and 15 unreported suspicious transactions, cited in a November 2025 FIU notice, is one of the largest AML enforcement matters in South Korean crypto history and indicates systemic compliance failures at scale.
  12. #41[disputed][awaiting moderator]in the timeline
    $36 million in Solana-ecosystem assets stolen from Upbit hot wallet on the sixth anniversary of the 2019 hack and on the day of Dunamu's acquisition closing. South Korea attributes attack to Lazarus Group.
    reviewer$36 million in Solana-ecosystem assets stolen on the sixth anniversary of the 2019 hack and on the day of Dunamu's acquisition closing [timeline].Same underlying error as the Background and 2025 Hack section text, reproduced in the timeline.
    Proposed correction (not yet applied)
    $36 million in Solana-ecosystem assets stolen from Upbit hot wallet on the sixth anniversary of the 2019 hack and one day after Naver's acquisition of Dunamu was announced. South Korea attributes attack to Lazarus Group.

unverifiable

3 claims

No source the reviewer could reach confirms or contradicts the claim.

  1. #9[unverifiable][awaiting moderator]in section: Background
    The exchange has expanded internationally, operating services in Singapore, Indonesia, and Thailand.
    reviewerUpbit expanded internationally, operating in Singapore, Indonesia, and Thailand.Could not independently confirm the full list of international markets (Indonesia, Thailand) within the scope of this review.
  2. #16[unverifiable][awaiting moderator]in section: The 2019 Hack
    On-chain analysis estimated that approximately 65,000–75,000 of the hacked ETH was moved to various exchange entities within three weeks of the theft.
    reviewerOn-chain analysis estimated 65,000-75,000 of the hacked ETH moved to exchanges within three weeks.Could not locate a source that specifically corroborates this 65,000-75,000 within-three-weeks figure; not necessarily contradicted, but unverifiable with the sources reviewed.
  3. #38[unverifiable][awaiting moderator]in section: User Protections
    The exchange does not offer a formal public bug bounty program as of research date, though third-party review sources cite an active bounty program.
    reviewerUpbit does not offer a formal public bug bounty program, though third-party review sources cite an active one.Could not independently confirm or refute the bug bounty status within the scope of this review; the page itself flags the ambiguity.

stale

4 claims

The claim was accurate when written but events since have overtaken it.

  1. #7[stale][awaiting moderator]in section: Background
    Upbit's parent company Dunamu is backed by Kakao, the South Korean internet conglomerate.
    reviewerDunamu is backed by Kakao.True historically, but superseded by 2026 reporting that Kakao has divested from Dunamu as Naver's acquisition and new investors (Hana Bank, Samsung affiliates) came in.
    Proposed correction (not yet applied)
    Upbit's parent company Dunamu was historically backed by Kakao, the South Korean internet conglomerate, though Kakao divested its remaining stake in 2026 amid Hana Financial and Samsung-affiliate investments and Naver's pending acquisition of Dunamu.
  2. #28[stale][awaiting moderator]in section: Regulatory History
    **$25M AML/KYC Fine and Suspension (2024–2025):**
    reviewer**$25M AML/KYC Fine and Suspension (2024-2025)** heading frames the entire matter as resolved within 2024-2025.The saga's final resolution (court cancellation) postdates the heading's implied 2024-2025 window.
    Proposed correction (not yet applied)
    **$25M AML/KYC Fine and Suspension (2024–2026):**
  3. #34[stale][awaiting moderator]in section: Regulatory History
    The Seoul Administrative Court ultimately overturned the suspension in full, finding that clear regulatory rules existed only for transactions above 1 million won (~$675) and that rules for smaller transfers were insufficiently specific to support enforcement.
    reviewerThe Seoul Administrative Court ultimately overturned the suspension in full on the basis that rules for small transfers were insufficiently specific.The reasoning is accurately described, but the ruling date is missing/implied to be within the 2024-2025 window when it actually occurred in April 2026.
    Proposed correction (not yet applied)
    In April 2026, the Seoul Administrative Court ultimately overturned the suspension in full, finding that clear regulatory rules existed only for transactions above 1 million won (~$675) and that rules for smaller transfers were insufficiently specific to support enforcement.
  4. #40[stale][awaiting moderator]in section: Risk Assessment
    While the associated suspension was overturned on a technicality (lack of clear rules for small transfers), the fine remained under consideration for appeal as of late 2025.
    reviewerThe suspension was overturned on a technicality while the fine remained under appeal consideration as of late 2025.As written, the sentence implies the suspension had already been overturned by 'late 2025,' when the court ruling actually followed several months later.
    Proposed correction (not yet applied)
    The suspension was overturned on a technicality (lack of clear rules for small transfers) by the Seoul Administrative Court in April 2026, and the separate $25M fine remained under consideration for appeal as of late 2025.

partially supported

1 claim

The cited evidence supports part of the claim but not all of it.

  1. #4[partially supported][awaiting moderator]in section: Background
    Upbit offers trading across approximately 180 cryptocurrencies with over 300 trading pairs and charges a 0.05% fee on KRW-denominated pairs.
    reviewerUpbit offers ~180 cryptocurrencies, 300+ trading pairs, and charges a 0.05% fee on KRW pairs.The figures are accurate for Upbit's Korean (KRW) platform per independent verification, but the specific source cited on the page describes a different product (Upbit Global/Singapore) with different fees, so the citation does not actually support this sentence.

confirmed

21 claims

The cited evidence supports the claim as written.

  1. #1[confirmed][no action needed]in section: Background
    Upbit is a South Korean cryptocurrency exchange launched on October 24, 2017, and operated by Dunamu Inc., one of South Korea's highest-valued tech startups. The platform launched with a partnership with American exchange Bittrex and quickly grew to become the dominant force in South Korean crypto trading.
    reviewerUpbit launched Oct 24, 2017, operated by Dunamu, in partnership with Bittrex, and grew to dominate South Korean crypto trading.Confirmed via Wikipedia and consistent with multiple secondary sources.
  2. #2[confirmed][no action needed]in section: Background
    Within two months of launch, it briefly ranked as the world's highest-volume exchange.
    reviewerWithin two months of launch Upbit briefly ranked as the world's highest-volume exchange.Directly confirmed by the cited Wikipedia text.
  3. #3[confirmed][no action needed]in section: Background
    As of 2024–2026, Upbit holds approximately 70–80% of South Korea's domestic crypto market share and serves over 8 million registered users.
    reviewerUpbit holds approximately 70-80% domestic market share and serves over 8 million registered users.Corroborated by independent monopoly-investigation coverage citing the same market share and user figures.
  4. #5[confirmed][no action needed]in section: Background
    The exchange does not offer margin or leveraged trading products.
    reviewerUpbit does not offer margin or leveraged trading.Confirmed by the cited source.
  5. #6[confirmed][no action needed]in section: Background
    It is partnered with K-Bank to provide real-name, verified bank accounts for Korean users — a regulatory requirement under South Korean anti-money laundering law.
    reviewerUpbit is partnered with K-Bank for real-name verified accounts.Confirmed via independent reporting on the K-Bank deposit-concentration story.
  6. #8[confirmed][no action needed]in section: Background
    In December 2018, Upbit became the first cryptocurrency exchange in the world to receive ISMS certification from the Korea Internet and Security Agency, as well as ISO 27001, ISO 27017, and ISO 27018 certifications.
    reviewerIn Dec 2018 Upbit became the first exchange globally to receive ISMS certification plus ISO 27001/27017/27018.Directly confirmed.
  7. #13[confirmed][no action needed]in section: The 2019 Hack
    On November 27, 2019, Upbit's Ethereum hot wallet was drained of 342,000 ETH — worth approximately $49 million at the time — in a single unauthorized transaction at 1:06 p.m. KST.
    reviewer342,000 ETH (~$49M) was stolen from Upbit's hot wallet on Nov 27, 2019 at 1:06pm KST in a single transaction.Core facts of the 2019 hack are well corroborated across multiple independent sources.
  8. #14[confirmed][no action needed]in section: The 2019 Hack
    Upbit's CEO stated that no investor assets were lost and that the company would cover the missing Ethereum from its own corporate reserves, which it subsequently did.
    reviewerUpbit's CEO stated no investor assets were lost and the company would cover losses from its own reserves, which it did.Confirmed and consistent with subsequent reporting that Upbit did reimburse users.
  9. #15[confirmed][no action needed]in section: The 2019 Hack
    Following the theft, attackers began moving the stolen ETH across approximately 50,000 wallets and 100,000 transactions over the following weeks in an attempt to launder the funds.
    reviewerAttackers moved the stolen ETH across approximately 50,000 wallets and 100,000 transactions.Confirmed via search corroboration of the cylynx.io analysis; the primary page could not be directly fetched (paywalled) but its reported figures matched independently.
  10. #17[confirmed][no action needed]in section: The 2019 Hack
    South Korean police and cybersecurity investigators later attributed the hack to North Korea's Lazarus Group, controlled by North Korea's Reconnaissance General Bureau.
    reviewerSouth Korean police and investigators attributed the 2019 hack to Lazarus Group / North Korea's Reconnaissance General Bureau.Confirmed by multiple independent reports of the official South Korean police attribution.
  11. #18[confirmed][no action needed]in section: The 2019 Hack
    This event made Upbit the seventh major crypto exchange to be hacked in 2019, a year marked by widespread exchange security failures.
    reviewerThe 2019 hack made Upbit the seventh major exchange hacked in 2019.Directly confirmed by the cited article's own headline.
  12. #19[confirmed][no action needed]in section: The 2025 Hack
    Attackers stole approximately $36 million in Solana-ecosystem assets, including SOL, USDC, BONK, JUP, RAY, RENDER, ORCA, and PYTH tokens, by exploiting an alleged flaw in Upbit's digital signature algorithm.
    reviewerAttackers stole ~$36M in Solana-ecosystem assets (SOL, USDC, BONK, JUP, RAY, RENDER, ORCA, PYTH) by exploiting a flaw in Upbit's digital signature algorithm.Corroborated by multiple independent reports (Halborn, DL News, CCN).
  13. #20[confirmed][no action needed]in section: The 2025 Hack
    CEO Oh Kyoung-suk halted all deposits and withdrawals as a precautionary measure and announced Upbit would cover all losses from its own assets.
    reviewerCEO Oh Kyoung-suk halted deposits/withdrawals after the 2025 hack and pledged to cover losses from Upbit's own assets.Confirmed; the CEO's name is romanized slightly differently across sources (Oh Kyoung-suk vs. Oh Kyung-seok), a common variance for Korean names that does not affect the substance of the claim.
  14. #21[confirmed][no action needed]in section: The 2025 Hack
    South Korea subsequently initiated legislative discussions to impose bank-level, no-fault liability on cryptocurrency exchanges for losses arising from hacks or system failures.
    reviewerSouth Korea initiated legislative discussions on bank-level no-fault liability for exchange hack losses following the 2025 breach.Confirmed.
  15. #22[confirmed][no action needed]in section: Regulatory History
    In March 2018, prosecutors raided Upbit's Gangnam-gu headquarters.
    reviewerIn March 2018, prosecutors raided Upbit's Gangnam-gu headquarters.Confirmed.
  16. #23[confirmed][no action needed]in section: Regulatory History
    In December 2018, three senior executives, including founder Song Chi-Hyung, were indicted on charges of fraud and market manipulation, accused of using a fake corporate account to place bogus orders worth 254 trillion won ($226B) to inflate volume and of selling 11,550 BTC through alleged manipulative practices.
    reviewerIn Dec 2018 three senior execs including founder Song Chi-Hyung were indicted for fraud/manipulation involving 254 trillion won ($226B) in fake orders and 11,550 BTC.Confirmed; the $226B conversion matches independent reporting almost exactly.
  17. #25[confirmed][no action needed]in section: Regulatory History
    Under the revised Act on Reporting and Using Specified Financial Transaction Information, which took effect September 24, 2021, all crypto exchanges in South Korea were required to obtain ISMS certification, register with the Financial Intelligence Unit (FIU), and secure real-name bank account partnerships. Upbit (via Dunamu) was one of only five exchanges to meet these requirements.
    reviewerSouth Korea's revised VASP reporting law took effect Sept 24, 2021, requiring ISMS/FIU registration/real-name accounts, and Upbit was one of five exchanges to qualify.Confirmed via independent reporting on South Korea's five major won-market exchanges.
  18. #33[confirmed][no action needed]in section: Regulatory History
    Dunamu filed for an injunction on February 28, 2025. On March 27, 2025, a Seoul court granted the injunction, temporarily allowing new user onboarding to continue.
    reviewerDunamu filed for an injunction on Feb 28, 2025 and the Seoul court granted it on March 27, 2025.Confirmed.
  19. #35[confirmed][no action needed]in section: Regulatory History
    The Financial Services Commission launched an investigation into Upbit's market dominance, which reached approximately 80% of South Korean crypto trading volume by mid-2024. Concerns centered on systemic risk and Upbit's relationship with K-Bank, where Upbit customer deposits ($4 trillion KRW) constituted roughly 20% of K-Bank's total deposit base.
    reviewerThe FSC investigated Upbit's ~80% market dominance and its K-Bank relationship, where Upbit deposits (4 trillion KRW) were ~20% of K-Bank's total deposits.Confirmed with precise, matching figures from independent reporting.
  20. #36[confirmed][no action needed]in section: Security Posture
    In the first half of 2023, the exchange reported approximately 160,000 hacking attempts, more than double the figure for the same period in 2021. In response, Upbit announced it was decentralizing operational hot wallets and expanding cold wallet storage to over 70% of held assets.
    reviewerIn H1 2023 Upbit reported ~160,000 hacking attempts (more than double H1 2021) and moved to 70%+ cold storage.Confirmed by the cited article's own headline and framing.
  21. #37[confirmed][no action needed]in section: User Protections
    However, as of the time of the 2025 hack, current South Korean law capped fines at 5 billion won ($3.4 million) and offered no mandatory compensation framework, leaving victims dependent on voluntary exchange payouts.
    reviewerCurrent South Korean law (pre-reform) capped fines at 5 billion won and offered no mandatory compensation framework.Confirmed.
How this fits together. The reviewer reads the published page and its cited sources and records one finding per claim. A human moderator decides whether each proposed correction is applied; those decisions, and the score changes they cause, appear in the audit log. Earlier review runs are not shown here; only the latest reflects the page as it stands.