TLDR
South Koreas Financial Supervisory Service has formally begun sanctions proceedings against Upbit operator Dunamu following a multimillion dollar hack, highlighting both regulatory gaps and rising scrutiny of major crypto exchanges.
- The FSS sent an inspection opinion letter to Dunamu over the November 2025 Upbit wallet breach, formally opening a sanctions process on the incident.
- Regulators are testing the limits of the Virtual Asset User Protection Act, which has no clear penalties for hacks, while Upbit points to reimbursement and security upgrades.
- Sanctions decisions and new digital asset laws later this year could reshape how Korean exchanges handle security, disclosure and user protection.
Deep Dive
1. Sanctions Process Begins
South Koreas Financial Supervisory Service (FSS) has sent an inspection opinion letter to Dunamu, the company behind Upbit, over a hack that drained roughly 44.5 billion won, about 3032 million dollars, from Solana based wallets on 27 Nov 2025, formally launching a sanctions procedure against the firm. This letter is the first official step in a multi stage process that includes internal review committees and the Financial Services Commission, and it gives Dunamu a chance to respond before penalties are set. Upbit was criticized for only disclosing the breach after a same day merger event with Naver Financial, raising questions about its incident reporting and transparency, according to Korean press and community coverage.
A major regulated exchange is now under formal sanction review for how it handled a hack, not just for the hack itself.
2. Regulation And Exchange Risk
The FSS is examining whether Upbit violated the Virtual Asset User Protection Act, which governs custody and unfair trading but does not yet spell out direct penalties for hacks or IT failures, leaving the severity of possible sanctions unclear. Authorities have signaled plans to close this gap by adding explicit sanctions and compensation rules for hacking incidents in the second phase of the Digital Asset Basic Act, as reported in regulatory summaries. Dunamu has already faced a large anti money laundering fine, later partly overturned due to legal gaps, showing regulators are willing to push but still refining their toolkit.
Korean exchanges face growing enforcement pressure even while the legal framework for cyber incidents is still being built.
3. What To Watch Next
Regulators must now decide whether and how to sanction Dunamu, and any penalty or formal finding will send a signal to the rest of the Korean market. In parallel, legislators are working on broader digital asset bills that could tighten rules on exchange ownership, disclosure and security standards, with debates in the National Assembly over how strict to be. For users and projects, the key markers will be the final sanctions decision, the timing and content of the Digital Asset Basic Act phase two, and whether similar inspections expand to other Korean exchanges.
Conclusion
South Korea is using the Upbit hack as a test case for how far its current laws can reach into crypto exchange security and disclosure, while it drafts stricter rules for the future. The outcome will matter not only for Dunamu, but for any exchange operating in Korea that needs to align technical defenses, incident reporting and user protection with an evolving regulatory regime.
