The Financial Supervisory Service (FSS) of South Korea has launched a formal sanctions process against Dunamu, the operator of the crypto exchange Upbit, in connection with a major wallet breach reported in November 2025.
Summary
- The FSS has initiated sanctions proceedings against Dunamu due to the wallet breach at Upbit in November 2025.
- The lack of defined penalties for hacking under existing laws leaves regulators in a state of uncertainty regarding the severity of any potential sanctions.
- Upbit has reimbursed affected users and updated its wallet systems, while regulators continue their investigation into the incident.
This action follows an extensive investigation into whether the exchange adhered to the country’s Virtual Asset User Protection Act.
According to reports from SBS, the FSS has sent an inspection opinion letter to Dunamu, allowing the company a chance to respond before regulators decide on any potential sanctions. This process will proceed through various levels of regulatory assessment.
FSS reviews Upbit’s response to the 2025 breach
The breach on November 27 affected Solana-based assets handled by Upbit. Initial estimates varied, with crypto.news reporting losses of about $36 million, while South Korean reports now suggest the total affected amount is 44.5 billion won, approximately $32 million at current exchange rates.
After detecting unusual transfers, Upbit announced that it had transferred assets to cold wallets, halted deposits and withdrawals, and began tracing the stolen funds. In its official communication to customers, the exchange assured that it would cover the losses using its own resources. Authorities later examined both the security failure and the timing of Upbit’s public disclosure.
Legal uncertainty complicates potential sanctions
The current Virtual Asset User Protection Act provides regulators with authority over custody, unfair trading, and consumer protection, but it does not specify penalties for hacking incidents or system failures. This lack of clarity raises questions about the FSS’s ability to impose sanctions in this case.
The regulator will evaluate Dunamu’s response before issuing any advance notice of intended actions. Final decisions will require further analysis by the sanctions review committee, the Securities and Futures Commission, and the Financial Services Commission. Additionally, South Korean authorities are considering stricter regulations to address hacking and technological failures in upcoming digital asset legislation.
Upbit under increasing regulatory scrutiny
This hacking incident happened amidst intensified regulatory oversight of Dunamu. As reported by crypto.news, South Korea’s Financial Intelligence Unit had previously fined the firm 35.2 billion won for deficiencies related to anti-money laundering and customer verification.
A previous enforcement measure was subject to judicial review, with a court overturning a three-month partial suspension against Dunamu, citing flaws in the legal basis for the sanctions. This recent hacking incident may serve as yet another test for how existing laws apply to crypto exchange operations.
Dunamu’s agreement with Naver still under review
The sanctions process aligns with Dunamu’s ongoing discussions for a proposed share swap with Naver Financial. The companies have recently delayed concluding the transaction until December 31, awaiting several regulatory approvals.
While the ongoing inspection does not automatically disrupt that deal, Dunamu remains subject to multiple layers of regulatory examination as South Korea works to establish more comprehensive digital asset regulations. The FSS has yet to announce a proposed level of sanctions concerning the hacking incident, and Dunamu retains the opportunity to challenge the inspection findings before any final resolution.





