South Korea's Financial Supervisory Service (FSS) recently initiated formal sanctions proceedings against Dunamu, the operator of the nation's largest cryptocurrency exchange, Upbit. This action stems from a significant security breach in November 2025, where Upbit experienced a hack resulting in losses of approximately 44.5 billion won (around $32 million). The FSS has issued an inspection opinion letter to Dunamu, marking the official commencement of a regulatory process that could set a crucial precedent for digital asset platforms in the country.
Regulatory Scrutiny Intensifies
The FSS's move follows a seven-month investigation into the November 2025 hack, which saw Solana-network assets worth 44.5 billion won ($32 million) flow out of Upbit. A key point of contention for regulators is not merely the security breach itself, but also the timing of Upbit's public disclosure. The exploit, which began at 4:42 a.m. KST on November 27, 2025, lasted approximately 54 minutes, but Upbit reportedly delayed its announcement until later that day, after a merger-related event involving Naver Financial had concluded.
This delay has drawn criticism and is a central focus of the FSS's review, which aims to determine if Dunamu violated the Virtual Asset User Protection Act. The inspection opinion letter provides Dunamu with an opportunity to formally respond to the FSS's findings before any proposed sanctions are officially notified.
Legal Ambiguity and Precedent
A significant challenge in this regulatory action is the current legal framework. South Korea's Virtual Asset User Protection Act, while designed to enhance investor safety and asset custody, does not contain explicit provisions for sanctions directly related to cyberattacks, computer hacks, or system failures.
This legal ambiguity creates uncertainty regarding the severity of potential penalties Dunamu might face. The FSS's efforts in this case are therefore seen as a test of the existing law's boundaries and could establish a critical precedent for how future hacking incidents on crypto exchanges are handled. Authorities are reportedly planning to address this regulatory gap by adding specific sanctions and compensation provisions for hacking and computer system failures in the second phase of the Digital Asset Basic Act.
Dunamu's Past and Present Responses
Following the November 2025 exploit, Dunamu stated that it would fully reimburse affected customers using its own balance sheet assets. The company also initiated an overhaul of its crypto wallet architecture and migrated assets from affected wallets to address vulnerabilities. In December 2025, Upbit announced the development of an automatic on-chain tracking service, the Onchain AI Tracer System, to monitor stolen funds and aid recovery efforts.
This is not Dunamu's first encounter with South Korean regulators. In February 2025, the Financial Intelligence Unit (FIU), an affiliate of the Financial Services Commission (FSC), imposed a three-month partial business suspension on Upbit and a 35.2 billion won (approximately $25 million) fine for alleged anti-money laundering (AML) violations and failures to meet customer due diligence requirements. However, a court later partially overturned that suspension in April 2026, citing insufficient specificity in compliance requirements for smaller transactions.
What to Watch
The sanctions process against Dunamu is expected to proceed through several stages. After Dunamu submits its explanation, the FSS will issue an advance notice of its sanctions recommendation. Final sanction measures will then be determined through deliberations by the Sanctions Review Committee, the Securities and Futures Commission (SFC), and ultimately the Financial Services Commission (FSC).
The outcome of this case will be closely watched by the entire South Korean crypto industry. It will not only clarify the extent of regulatory authority under the current Virtual Asset User Protection Act but also likely influence the scope and specifics of upcoming digital asset legislation, particularly concerning accountability for security breaches and user protection. The industry awaits to see if this action leads to more stringent security and disclosure requirements for exchanges operating in the region.
Original announcement: South Korea's Financial Supervisory Service (via Yonhap News)