Nearly eight months after one of the most significant security breaches at a South Korean crypto exchange, regulators are finally moving to hold someone accountable. South Korea’s Financial Supervisory Service has formally initiated sanction procedures against Dunamu, the operator of Upbit, following the Upbit $30 million hack that stripped the platform of Solana-based assets in under an hour last November. The move, first reported by local broadcaster SBS, marks the official start of what could become a landmark regulatory test for Asia’s most active crypto market.
Summary
Key takeaways
- The FSS sent an inspection report to Dunamu around July 18–19, officially opening the sanction process over the November 27, 2025 breach.
- Attackers drained 44.5 billion won (~$30 million) in Solana-based assets from Upbit’s hot wallet in just 54 minutes.
- Dunamu covered 38.6 billion won ($26 million) of affected customer assets from its own reserves; an additional 2.6 billion won ($1.7 million) of stolen funds has been frozen.
- South Korea’s current crypto law, the Virtual Asset User Protection Act, contains no direct sanction provisions for exchange hacks, leaving the severity of penalties uncertain.
- North Korea’s Lazarus Group is suspected by authorities, but no public confirmation has been made by Upbit or regulators.
Regulatory action initiated against Dunamu
The FSS’s decision to send Dunamu a formal inspection report is not a fine or a penalty in itself — but it is the trigger that sets everything else in motion. It represents the first formal step in a multi-stage process that will eventually involve the regulator’s Sanctions Review Committee, the Securities and Futures Commission, and the Financial Services Commission before any final penalty is handed down.
According to SBS, the FSS opened its inspection of Upbit roughly seven months ago. That the process has taken this long to reach the sanction stage reflects both the complexity of the investigation and the structural ambiguity in South Korea’s existing crypto legislation. FSS Governor Lee Chan-jin acknowledged as much at a December 1 press conference, stating that while sanctions under the Virtual Asset User Protection Act have limits, the hack was not something the regulator could simply overlook.
Once Dunamu receives the proposed sanction level, it will have an opportunity for clarification before the case moves through the committee chain. The final outcome remains genuinely open — a consequence of a legal framework that was not built with scenarios like this in mind.
Details of the Solana hot wallet breach
What happened on November 27
The attack was swift and precise. Starting at 4:42 a.m. local time, unknown actors drained 44.5 billion won in Solana-based assets from Upbit’s hot wallet over approximately 54 minutes, transferring the funds to an external wallet. The breach affected roughly 38.6 billion won worth of customer assets — the remainder belonging to Upbit itself.
Dunamu moved quickly to limit user damage. The company covered the full 38.6 billion won ($26 million) in customer losses from Upbit’s own reserves, ensuring that affected users were made whole. Separately, Upbit traced and froze 2.6 billion won ($1.7 million) of the stolen funds — an increase from the 2.3 billion won the exchange said it had frozen in the days immediately following the breach — and recovery efforts are continuing.
The exchange’s ability to absorb customer losses internally is notable, but it does not resolve the underlying regulatory question: whether Upbit’s security practices met the standard the law requires, and what consequences should follow when they fall short.
Disclosure timing and the Naver Financial merger
Beyond the breach itself, Dunamu drew sharp criticism for when it chose to go public with the news. According to SBS, the company announced the hack only after a merger event with Naver Financial, held the same day as the breach, had already concluded. Critics argued that users and investors deserved immediate notice, not a disclosure timed to avoid disrupting a corporate transaction.
The optics have lingered. Dunamu’s stock-swap merger with Naver Financial — the fintech arm of South Korea’s largest internet company — is still pending. Earlier this month it was pushed back to December 31, meaning the sanction process will play out in parallel with a deal that has already been delayed and now carries the additional weight of an active regulatory proceeding against one of the parties.
That intersection matters. A significant sanction finding could complicate the merger’s timeline further, introduce new due diligence requirements, or shift the terms of the deal — none of which the parties have publicly addressed.
The legal gap at the center of everything
Virtual Asset User Protection Act and its limits
The FSS’s challenge is that its primary enforcement tool, the Virtual Asset User Protection Act, was designed around user protection and unfair trading practices. It contains no direct provisions for sanctioning crypto exchanges over security breaches or IT failures. That means regulators must find a way to apply existing rules to a scenario the law was never specifically written to address — a significant constraint on both the speed and severity of any outcome.
This is not a minor procedural detail. It means that whatever sanction Dunamu ultimately faces, it will be the product of regulatory interpretation rather than clear statutory mandate. That introduces uncertainty for Dunamu, for its users, and for every other exchange operating in South Korea that might face similar scrutiny.
Reforms planned under the Digital Asset Basic Act
Authorities are aware of the gap. South Korea’s forthcoming Digital Asset Basic Act — the second phase of the country’s crypto legislation — is expected to introduce explicit rules covering sanctions and compensation obligations for hacking and IT incidents, according to SBS. Until that legislation passes, regulators are working with tools that were not built for the problem they are trying to solve.
The Dunamu case, in that sense, is doing double duty: it is both a regulatory proceeding and an argument for why the new law needs to move forward.
Suspected Lazarus Group involvement and the Bithumb parallel
South Korean authorities suspect that North Korea’s Lazarus Group — the state-linked hacking operation responsible for numerous high-profile crypto thefts globally — was behind the Upbit breach. Neither the exchange nor the FSS has publicly confirmed that attribution, and it remains a suspicion rather than an established finding. The scale, speed, and methodology of the attack have drawn comparisons to previous Lazarus-linked operations, but formal confirmation would carry significant geopolitical weight and has not materialized.
Meanwhile, the FSS is running a separate but parallel process against rival exchange Bithumb. According to SBS, the regulator has concluded an inspection of Bithumb related to an incident involving misallocated bitcoin and intends to begin sanction procedures once internal legal reviews are complete. That probe examined Bithumb’s internal controls and risk management practices. The FSS is also set to pause all inspections for three weeks starting this week, resuming in mid-August.
The fact that two of South Korea’s largest crypto exchanges are simultaneously facing regulatory action signals something broader: the FSS is applying a more aggressive enforcement posture across the sector, not just reacting to one isolated incident. Whether the legal framework can keep pace with that ambition is the question South Korea’s crypto industry will be watching most closely over the next several months.
FAQ
What was the extent of the Upbit hack in November 2025?
The Upbit hack involved the theft of approximately 44.5 billion won (~$30 million) in Solana-based assets over a 54-minute period on November 27, 2025, with funds drained to an external wallet starting at 4:42 a.m. local time.
How has Dunamu responded to cover losses from the Upbit hack?
Dunamu covered about 38.6 billion won ($26 million) of affected customer assets from Upbit’s own reserves and has frozen 2.6 billion won ($1.7 million) of stolen funds, with recovery efforts still ongoing.
What legal challenges affect sanctions against Dunamu for the hack?
South Korea’s Virtual Asset User Protection Act lacks direct provisions for sanctions over exchange hacks, making the process complex. Final sanctions must pass through the Sanctions Review Committee, the Securities and Futures Commission, and the Financial Services Commission before any penalty is confirmed.
Is there a known party responsible for the Upbit hack?
South Korean authorities suspect North Korea’s Lazarus Group was behind the breach, but neither Upbit nor the FSS has publicly confirmed that attribution.
Article produced with the assistance of artificial intelligence and reviewed by the editorial team.

