Share this article

Upbit Is the Seventh Major Crypto Exchange Hack of 2019

These seven major hacks remind us: not your keys, not your crypto.

Updated Sep 13, 2021, 11:44 a.m. Published Nov 27, 2019, 10:02 p.m.
hacks

The recent Upbit hack is a stark reminder of the danger of storing your crypto on an exchange. We explored seven major hacks that happened this year, each one bolder than the last. The lesson? Not your keys, not your crypto.

STORY CONTINUES BELOW
Don't miss another story.Subscribe to the Crypto Daybook Americas Newsletter today. See all newsletters

Cryptopia went dark on Jan. 15 after it discovered a “security breach” with “significant losses.” It stayed dark, and mostly silent, through the rest of January and deep into February. The site claimed it could not comment during the police investigation of the estimated $16 million hack.

It is not clear how Cryptopia was hacked, but investigators discovered in August that Cryptopia had been pooling users’ funds in a catchall wallet. The New Zealand exchange tried to right its ship after the hack and even briefly reopened trading services in March. But the revival was not meant to be: the exchange went into liquidation in May and 10 days later filed for bankruptcy.

DragonEx of Singapore lost an “undisclosed” amount of user funds in a March 24 hack. It initially declined to estimate how much but days later it revealed over telegram that it lost $7 million in the security breach. DragonEx did not appear to promise users a full refund, as other exchanges generally did in 2019. Instead, it said it was working on a “preliminary compensation plan” that would reimburse victims’ lost funds in Tether or Dragon Token equivalent.

Hackers targeted Bithumb in March for $13 million of EOS and the South Korean exchange later learned it was missing $6.2 million in XRP. The heist came less than a year after another massive hack: $31 million in late 2018. Bithumb suspects that the hack was an inside job as it spotted an “abnormal withdrawal” from one of its wallets. The exchange claims it lost no user funds in the hack.

Hackers stole a massive 7,000 bitcoin haul worth some $40.7 million from Binance in May. The world’s largest exchange by volume found a vulnerability in its hot wallet, though it claims that only 2 percent of total funds were in that wallet at the time of the hack. Funds quickly moved through a network of smaller and smaller wallets as hackers tried to wash their stolen coins. Some of the funds were eventually turned into fiat. In response, Binance shuttered deposit and withdrawal services for a week to beef up security protocols. The exchange reopened services on May 15. It pledged to refund users from its emergency fund.

Singapore’s BiTrue exchange lost $4.2 million of its users’ funds in June. Hackers targeted XRP ($4.01 million) and ADA ($231,800) in a breach that exploited BiTrue’s internal user access review process. Using what they learned, the hackers then transferred 9.3 million XRP and 2.5 million ADA into different exchanges. BiTrue says it worked with partner exchanges to freeze those funds and further promised to refund all users affected.

Japanese exchange Bitpoint lost $28 million in a July hack that hit 50,000 users. It is not known how the hackers breached Bitpoint’s security, though it forced Bitpoint to halt trading for a month. Soon after the hack, Bitpoint’s parent company, Remixpoint, promised to reimburse affected users. Trading in Bitpoint’s five supported cryptos (bitcoin, bitcoin cash, ether, litecoin and XRP) started up again in August.

Upbit is the latest hacking victim after losing $49 million at 9:00 UTC on November 26, 2019. An "abnormal transaction" resulted in a 342,000 ether loss in a few minutes. The exchange said that the loss didn't come from user funds and that it has suspended all functions for at least two weeks.

As the year winds down, these hacks represent the massive - and precarious - risks exchanges and users take with their private and public wallets. What will 2020 bring? Here's hoping for fewer losses from fewer big names in the crypto ecosystem.

Poster vector created by freepik - www.freepik.com

More For You

Protocol Research: GoPlus Security

GP Basic Image

What to know:

  • As of October 2025, GoPlus has generated $4.7M in total revenue across its product lines. The GoPlus App is the primary revenue driver, contributing $2.5M (approx. 53%), followed by the SafeToken Protocol at $1.7M.
  • GoPlus Intelligence's Token Security API averaged 717 million monthly calls year-to-date in 2025 , with a peak of nearly 1 billion calls in February 2025. Total blockchain-level requests, including transaction simulations, averaged an additional 350 million per month.
  • Since its January 2025 launch , the $GPS token has registered over $5B in total spot volume and $10B in derivatives volume in 2025. Monthly spot volume peaked in March 2025 at over $1.1B , while derivatives volume peaked the same month at over $4B.

More For You

Coinbase Sees Crypto Recovery Ahead as Liquidity Improves and Fed Rate Cut Odds Climb

Coinbase

The crypto exchange also took note of a so-called AI bubble that continues to go strong and a weaker U.S. dollar.

What to know:

  • Coinbase Institutional is seeing a potential December recovery in crypto, citing improving liquidity and a shift in macroeconomic conditions that could favor risk assets like bitcoin.
  • The firm's optimism is driven by rising odds of Federal Reserve rate cuts, with markets pricing in a 93% chance easing next week, and improving liquidity conditions.
  • Several recent institutional developments, including Vanguard's crypto ETF policy reversal and Bank of America's greenlighting of crypto allocations, have contributed to bitcoin's rebound from recent lows.