TL;DR
-
South Korea's Financial Supervisory Service (FSS) has initiated sanction procedures against Upbit operator Dunamu over the exchange's $30 million hack in November 2025.
-
Upbit reimbursed affected users using its own reserves and has frozen $1.7 million of the stolen assets.
-
Regulators are investigating whether the incident violated the Virtual Asset User Protection Act, although current laws offer limited authority to penalize exchanges over cyberattacks.
South Korea's Financial Supervisory Service (FSS) has begun sanction proceedings against Dunamu, the operator of cryptocurrency exchange Upbit, following the platform's roughly $30 million security breach last November.
According to local broadcaster SBS, the regulator recently delivered an inspection report to Dunamu detailing its findings after investigating the incident for about seven months.
The move marks another step in South Korea's broader effort to strengthen oversight of digital asset platforms following several high-profile security incidents.
Upbit Reimbursed Customers After Solana-Based Attack
Upbit, the country's largest cryptocurrency exchange by trading volume, suffered the hack on November 27, 2025, when attackers stole approximately 44.5 billion won (around $30 million) worth of Solana-based digital assets.
The stolen funds were transferred to an external wallet over a period of roughly 54 minutes.
Following the breach, Dunamu compensated affected users by covering approximately 38.6 billion won ($26 million) in customer losses using the company's own reserves.
The exchange has also frozen 2.6 billion won (approximately $1.7 million) worth of the stolen assets and continues efforts to recover the remaining funds.
Beyond the security breach itself, Upbit faced criticism over how it handled public disclosure of the incident.
According to SBS, the exchange did not immediately announce the hack, instead waiting until a merger-related event involving Naver Financial had concluded before informing users.
The delayed announcement attracted attention from regulators and the broader crypto industry, particularly as Dunamu's stock-swap merger with Naver Financial remains pending after being postponed to December 31, 2026.
The sanction process is expected to unfold while the merger awaits completion.
Current Crypto Law Limits Regulators' Enforcement Powers
The FSS is examining whether the incident breached South Korea's Virtual Asset User Protection Act, which focuses primarily on safeguarding users and preventing unfair trading practices.
However, the legislation does not explicitly authorize regulators to penalize exchanges solely for suffering hacking incidents or technology failures.
As a result, the scope and severity of any sanctions against Dunamu remain uncertain.
FSS Governor Lee Chan-jin previously acknowledged that the law provides limited enforcement options but stressed that regulators could not simply overlook a security breach of this scale.
Before any penalties are finalized, the FSS will notify Dunamu of its proposed sanctions and allow the company to respond during a clarification process.
Final disciplinary measures will then be reviewed by the regulator's Sanctions Review Committee, the Securities and Futures Commission, and the Financial Services Commission.
The Upbit investigation has highlighted gaps in South Korea's crypto regulatory framework, prompting authorities to expand oversight through the upcoming Digital Asset Basic Act.
The proposed legislation is expected to introduce specific rules covering:
-
Exchange accountability for hacking incidents.
-
Compensation requirements for affected users.
-
Penalties for cybersecurity failures.
-
Stronger operational and IT risk management standards.
The reforms aim to provide regulators with clearer enforcement powers when exchanges experience security breaches.
Lazarus Group Remains the Primary Suspect
South Korean investigators have previously indicated that the Lazarus Group, a hacking organization widely linked to North Korea, is suspected of carrying out the Upbit attack.
However, neither Upbit nor financial regulators have officially confirmed the attribution.
The Lazarus Group has repeatedly been accused of targeting cryptocurrency platforms worldwide to generate funds through large-scale digital asset thefts.
The regulator has also completed a separate inspection of rival cryptocurrency exchange Bithumb, focusing on an incident involving improperly allocated Bitcoin as well as the company's internal controls and risk management procedures.
According to SBS, the FSS plans to begin sanction proceedings against Bithumb once its legal review is complete.
Meanwhile, the regulator will suspend inspection activities for three weeks beginning Monday before resuming investigations in mid-August.
Nikolas Sargeant