News/Regulation/Dunamu Faces Sanctions Over $36M Upbit…
Regulation

Dunamu Faces Sanctions Over $36M Upbit Hack, Eight Months After Breach

South Korea's FSS opens sanctions process against Upbit parent Dunamu for the Nov. 2025 hack, with penalty rules still unclear under current law.

Dunamu Faces Sanctions Over $36M Upbit Hack, Eight Months After Breach

South Korea’s Financial Supervisory Service has opened a formal sanctions process against Dunamu, the operator of crypto exchange Upbit, nearly eight months after a hack that drained funds reported at either $30 million or $36 million depending on the outlet. Local news agency Yonhap reported that the FSS recently sent Dunamu an inspection opinion letter, the procedural step that kicks off a sanctions review under Korean financial regulation.

The letter gives Dunamu a chance to respond before the FSS finalizes and notifies the company of any proposed penalties. But the size and nature of those penalties remain genuinely unclear: South Korea’s Virtual Asset User Protection Act, the main law governing exchange conduct, contains no explicit sanctions provisions for hacks or IT system failures. Regulators are instead reviewing whether Dunamu breached other parts of the statute.

A 54-minute breach and a delayed disclosure

The exploit at the center of the case took place on Nov. 27, 2025, starting at 4:42 a.m. KST and lasting roughly 54 minutes, according to details reported by Yonhap. Upbit did not disclose the breach until the end of that day, after a merger-related event involving internet giant Naver Financial had concluded — a sequencing that drew criticism at the time for delaying customer notification.

In the immediate aftermath, Upbit said it froze approximately 2.3 billion won, equivalent to about $1.5 million, tied to the incident. The exchange committed to fully reimbursing affected users out of its own balance sheet, rather than passing losses on to customers, and said it would overhaul its wallet architecture and stand up an onchain tracing system aimed at recovering stolen funds.

Why the penalty is a legal grey area

The core problem for regulators is that the Virtual Asset User Protection Act was written without direct provisions covering cyberattacks or computer hacks, leaving the FSS to determine whether Dunamu’s conduct falls under other clauses of the law. That gap is exactly why Korean authorities are reportedly planning to add explicit sanctions and compensation rules for hacking and system failures in the second phase of the country’s Digital Asset Basic Act, a broader legislative package still being finalized.

Until that legislation lands, Dunamu’s case will likely serve as a test of how far the FSS can stretch existing rules to penalize an exchange over a security failure rather than a straightforward disclosure or trading violation. Cointelegraph said it had approached Dunamu for comment on the matter; no response was noted in reporting so far.

What it means for Upbit users

For Upbit’s customer base, the immediate financial exposure from the hack was already addressed through Dunamu’s self-funded reimbursement of the frozen 2.3 billion won. The bigger question now is regulatory: whether South Korea’s largest exchange by volume faces a fine, an operational restriction, or a lighter administrative rebuke — and whether the eventual outcome shapes how the pending Digital Asset Basic Act treats hacking liability across the entire Korean exchange sector going forward.

Sources

Related articles