Upbit hacker slips through Railgun checks to mix stolen funds after $36M exploit

Source Cryptopolitan

The Upbit hacker may be using Railgun to mix funds. Despite the mixer’s checks, the hacker addresses were not flagged, and the transactions were allowed to continue. 

On-chain analysis showed addresses linked to the Upbit hack used the Railgun mixer. The mixer performs a zero-knowledge check for the origin of funds. This time, however, the check did not prevent the funds from being mixed. 

Upbit was hacked for over $36M, with over $30M in Solana assets. The multi-chain attack led to immediate swaps and movements of funds between wallets. 

The hacker sold most assets almost immediately, especially Solana-based tokens. On-chain investigator @dethective noted the selling had an effect on decentralized market volumes. The day after the hack, the exploiter’s wallets swapped Solana tokens into SOL. After that, the SOL was traded for USDC, and the stablecoins were bridged to Ethereum for mixing. 

In total, the hacker held over 533 ETH after fees, valued at around $1.6M. The shift to Ethereum and subsequent mixing is a pattern usually ascribed to North Korean hackers. 

Upbit also added new information on its hack. According to a statement from the exchange, the exploit may be due to a flaw in the exchange’s internal system, which has been patched. Upbit stated that the hacker may have inferred private keys from publicly available hot wallets due to predictable key hashing and weak cryptography.

Railgun lacked the latest information on the hackers’ wallets

Railgun’s approach is to test each user’s wallets against constantly updated databases for bad actors. In this case, the hacker’s full list of addresses was very recent. Additionally, the exploit went through multiple direct DEX swaps and some of the funds were shifted to new wallets. The data available to Railgun was therefore outdated, and the hacker’s latest wallet passed the test. 

The last intercepted wallet laundered a total of 410 ETH. The new address was created just hours after the hack, and briefly used as an intermediary. The rapid change in wallets additionally avoided Railgun’s filters.  

Railgun used for DeFi activity

Railgun gained popularity during the recent revival of the privacy narrative. Railgun grew its asset pool, with $95M in value locked as of November 2025. The increased value signals a growing interest, as the mixer achieved $1.31M in fees for Q3. 

The usage of mixers grew in the past year. Tornado Cash, previously seeing only baseline activity, increased its value locked to a new peak. The mixer holds over 32K ETH, following multiple high-profile exploits. 

The Upbit hacker launders funds through Railgun, passing the mixer's proof of innocence
Tornado Cash posted a record number of ETH in its reserves after an increased demand for privacy. | Source: Dune Analytics

The native RAIL token also rose by over 200% for the past three months, trading at $3.26. Railgun reflected the success of ZCash and other privacy tokens, while also being promoted by Vitalik Buterin. 

Railgun is not a go-to tool for hackers and exploiters. Rather, it has been a general privacy tool for regular transactions. Crypto influencers and high-profile individuals aim for privacy, as even transaction data can lead to tracking or even price swings. 

However, Railgun usage can also be tracked. Additionally, hacker addresses can use tools to test which wallets would be flagged by Railgun. This would allow hackers to keep hiding the proceeds of exploits, most of which are untraceable. 

If you're reading this, you’re already ahead. Stay there with our newsletter.

Disclaimer: For information purposes only. Past performance is not indicative of future results.
placeholder
Google accelerates its post-quantum cryptography timeline to 2029 in its latest researchGoogle Quantum AI has released research showing that breaking Bitcoin’s encryption may require significantly fewer quantum resources than previously estimated. This discovery could potentially unlock billions of dollars in funds dormant due to private key losses. While Google’s discovery benefits individuals with no access to their fortunes, as Elon Musk promptly pointed out, it also […]
Author  Cryptopolitan
19 hours ago
Google Quantum AI has released research showing that breaking Bitcoin’s encryption may require significantly fewer quantum resources than previously estimated. This discovery could potentially unlock billions of dollars in funds dormant due to private key losses. While Google’s discovery benefits individuals with no access to their fortunes, as Elon Musk promptly pointed out, it also […]
placeholder
Ripple and Convera make payments faster as the XRP price holds around $1.34Ripple and Convera are working together to make cross-border payments faster using stablecoins and blockchain.
Author  Cryptopolitan
19 hours ago
Ripple and Convera are working together to make cross-border payments faster using stablecoins and blockchain.
placeholder
Silver Price Recovers From 2026 Low, but April Arrives With a 36% Downside ThreatSilver (XAG/USD) price has bounced roughly 18% from its 2026 low, currently trading above $72. The recovery followed a hidden bullish divergence that began forming in December. Additionally, the lates
Author  Beincrypto
19 hours ago
Silver (XAG/USD) price has bounced roughly 18% from its 2026 low, currently trading above $72. The recovery followed a hidden bullish divergence that began forming in December. Additionally, the lates
placeholder
Can XRP Price Survive the $1.30 Threat Before March Ends?The XRP price traded at $1.31 on March 31, sitting directly above the neckline of a head-and-shoulders pattern that carries an 18% measured breakdown target if it fails.The 4-hour chart shows the righ
Author  Beincrypto
19 hours ago
The XRP price traded at $1.31 on March 31, sitting directly above the neckline of a head-and-shoulders pattern that carries an 18% measured breakdown target if it fails.The 4-hour chart shows the righ
placeholder
If the US Troops Enter Iran, What Happens to Bitcoin? Lessons From Past WarsMarkets are already reacting to rising geopolitical risk. Several Polymarket insiders who successfully bet on the start date of the Iran war are now betting heavily on US boots on the ground in Iran.N
Author  Beincrypto
19 hours ago
Markets are already reacting to rising geopolitical risk. Several Polymarket insiders who successfully bet on the start date of the Iran war are now betting heavily on US boots on the ground in Iran.N
goTop
quote