TLDR
South Koreas Financial Supervisory Service has formally begun a sanctions process against Upbits parent Dunamu after a multimillion dollar hack of the exchange in late 2025.
- The regulator sent an inspection opinion letter over the November 2025 Upbit wallet breach, officially opening a sanctions case against Dunamu.
- Existing law covers user protection and unfair trading but has no clear penalties for hacks, so the eventual severity of sanctions is still uncertain.
- Authorities plan to plug this gap in upcoming digital asset legislation, which would tighten standards for exchanges and incident response in South Korea.
Confidence: high, based on multiple detailed regulatory and news reports.
Deep Dive
1. What Action The Regulator Took
South Koreas Financial Supervisory Service (FSS) has sent an inspection opinion letter to Dunamu, the operator of Upbit, over a hack in November 2025 that drained roughly 30 to 36 million dollars in Solana based assets from an exchange wallet. This letter marks the formal start of sanctions proceedings and gives Dunamu a chance to respond before the FSS proposes specific penalties, as described in reports from Cointelegraph and others about the Upbit hack sanctions process.
The case then moves through several review bodies, including a sanctions committee and the Financial Services Commission, before any punishment is finalized, according to a summary of the process in a separate regulatory overview.
This is not just an investigation but the start of a formal enforcement track that could result in fines or other restrictions for a major Korean exchange operator.
2. Legal Gaps Around Hacks
The proceedings sit under the Virtual Asset User Protection Act, which focuses on custody rules and unfair trading but does not spell out direct penalties for security breaches or technology failures. Both Cointelegraph and crypto.news note that the FSS is testing how far it can go under a law that was not written with exchange hacks in mind.
Authorities have publicly signaled plans to add explicit sanctions and compensation rules for hacking and system incidents in the second phase of the Digital Asset Basic Act, closing this gap in future cases.
Current sanctions might be limited by the letter of the law, but future Korean rules are likely to be tougher and more specific about hack liability.
3. Impact On Exchanges And Users
Upbit has said it froze a portion of the stolen funds, shifted assets to safer wallets, and fully reimbursed affected customers from its own balance sheet, while also rolling out an on chain tracing system to follow the stolen coins. Regulators are scrutinizing both the technical failure and the timing of Upbits public disclosure, which drew criticism for being delayed until after a corporate event.
In parallel, the Financial Services Commission reports more than 40 unfair trading investigations in two years under the same Act, underscoring a wider push to police crypto markets.
Korean exchanges face rising expectations around security, transparency, and incident handling; users get stronger oversight, but also more potential disruption if platforms fall short.
Conclusion
South Koreas move to start sanctions proceedings over the Upbit hack shows regulators are ready to treat large crypto security failures as formal enforcement matters, even before the legal framework fully catches up. For market participants, the combination of hack scrutiny and broader unfair trading investigations points to a more regulated Korean crypto environment where operational security and timely disclosure become core competitive requirements.
