Newsroom

South Korean Regulator Opens Sanctions Process Against Upbit Operator Dunamu

19 July, 2026   /   News   /  AI   /   Tags:  upbit, dunamu, fss, sanctions, inspection

South Korean Regulator Opens Sanctions Process Against Upbit Operator Dunamu

South Korea’s Financial Supervisory Service has begun formal proceedings against Dunamu following a $36 million hack at its Upbit exchange in November 2025, highlighting gaps in current virtual asset regulations

Regulator Sends Inspection Letter to Dunamu

The Financial Supervisory Service (FSS) recently issued an inspection opinion letter to Dunamu, the company operating South Korea’s leading crypto exchange Upbit. This step formally initiates the sanctions process, allowing the firm to respond to the regulator’s findings before any proposed penalties are advanced.

Local reports indicate the review centers on the exchange’s handling of a security breach that occurred on November 27, 2025. The incident involved unauthorized transfers from Solana-based wallets and lasted approximately 54 minutes.

Details of the November Hack

Upbit detected abnormal activity early in the morning and responded by moving remaining assets to cold storage, suspending deposits and withdrawals, and initiating tracing of the stolen funds. The exchange later announced the breach at the end of the trading day.

Loss estimates from the event ranged around $36 million, with South Korean reports citing approximately 44.5 billion won. Dunamu stated it would cover all customer losses using its own resources and froze a portion of related funds.

Upbit said it would fully reimburse affected customers using its own balance sheet assets.
Upbit Official Statement

Regulatory Challenges and Legal Gaps

Authorities are examining whether the incident violated the Virtual Asset User Protection Act. However, the legislation currently lacks explicit provisions addressing cyberattacks or computer system failures, creating uncertainty over the appropriate scope of sanctions.

The FSS process includes multiple review stages, potentially involving the sanctions review committee, Securities and Futures Commission, and Financial Services Commission. Dunamu will have further opportunities to present its case before any final measures.

Exchange Response and Security Upgrades

Following the breach, Upbit conducted a comprehensive overhaul of its wallet architecture and migrated assets from affected systems. In December 2025, the platform introduced an automatic onchain tracking service designed to monitor stolen funds and support recovery efforts.

The company has faced previous regulatory scrutiny, including a substantial fine from the Financial Intelligence Unit related to anti-money laundering and customer verification practices.

Broader Implications for Digital Asset Rules

The case has prompted discussions about strengthening South Korea’s regulatory framework. Officials are considering amendments in the second phase of the Digital Asset Basic Act to include clearer sanctions and compensation mechanisms for hacking incidents and system failures.

Meanwhile, Dunamu continues to navigate other regulatory matters, including a delayed share swap transaction with Naver Financial pending outstanding approvals.

AspectDetails
Date of IncidentNovember 27, 2025
Approximate Loss$36 million (44.5 billion won)
Regulatory ActionInspection opinion letter issued by FSS
Customer ImpactFull reimbursement by Upbit
Disclaimer
This article was generated by AI using information from multiple industry sources. It has not been reviewed or verified by a human editor and may contain inaccuracies, omissions, or misinformation. Readers are encouraged to independently verify any information before making decisions based on its content.
This article is for informational purposes only and does not constitute financial, legal, or investment advice. Cryptocurrency and related investments involve substantial risk, and past performance does not guarantee future results.