South Korea Targets Dunamu After Upbit Hack Exposes Legal Loopholes
The Financial Supervisory Service (FSS) of South Korea has initiated a formal sanctions process against Dunamu, the operator of the crypto exchange Upbit, following a major wallet breach that occurred in November 2025.
Summary
- The FSS has opened sanctions proceedings against Dunamu due to Upbit’s wallet breach in November 2025.
- Current regulations lack clear penalties for hacking, leaving regulators in doubt about the severity of potential sanctions.
- Upbit has compensated those affected and upgraded its wallet systems as the investigation continues.
This decision follows a lengthy investigation into whether the exchange adhered to the Virtual Asset User Protection Act in South Korea.
According to SBS, the FSS has recently sent an inspection opinion letter to Dunamu, allowing the company to respond before regulators decide on possible sanctions. The process will progress through several stages of regulatory review.
FSS assesses Upbit’s response to the breach
The attack on November 27 had significant effects on Solana-based assets managed by Upbit. Initial estimates varied, with crypto.news reporting losses of roughly $36 million, while local sources now estimate the total impact at 44.5 billion won, or about $32 million at current exchange rates.
In response to unusual transfers, Upbit reported that it transferred assets to cold wallets, halted deposits and withdrawals, and began tracing the stolen funds. In its official communication to customers, the exchange assured that the losses would be covered using company resources. Authorities later examined both the security oversight and the timing of Upbit’s public statement.
Legal uncertainty complicates potential sanctions
The current Virtual Asset User Protection Act gives regulators authority over custody, unfair trading, and consumer protection but does not specify penalties for hacking or system failures. This absence creates uncertainty about the FSS’s ability to impose sanctions in this case.
The regulator will evaluate Dunamu’s response before providing any preliminary notice of proposed actions. Final determinations will require additional assessment from the sanctions review committee, the Securities and Futures Commission, and the Financial Services Commission. Authorities in South Korea are also considering stricter regulations around hacking and technological failures in upcoming digital asset legislation.
Upbit faces heightened regulatory oversight
This hacking incident took place amid increased regulatory scrutiny of Dunamu. As reported by crypto.news, the Financial Intelligence Unit of South Korea had previously fined the firm 35.2 billion won for shortcomings related to anti-money laundering and customer verification.
A previous enforcement action faced judicial review, leading to a court overturning a three-month partial suspension against Dunamu due to insufficient legal grounding for the sanctions. This latest hacking incident could further challenge how existing laws apply to crypto exchange operations.
Dunamu’s Naver agreement remains under review
The sanctions process coincides with Dunamu’s ongoing negotiations for a planned share swap with Naver Financial. The companies recently postponed the completion of this transaction until December 31, awaiting several regulatory approvals.
While the current inspection does not automatically obstruct this deal, Dunamu continues to face multiple layers of regulatory scrutiny as South Korea seeks to establish more comprehensive digital asset regulations. The FSS has not yet revealed a proposed sanction level concerning the hacking incident, and Dunamu retains the opportunity to contest the inspection findings before any final resolution.
