South Korea’s financial regulator has reportedly begun formal sanctions proceedings against Dunamu, the operator of crypto exchange Upbit, following an investigation into a $36 million security breach in November 2025.
According to local media reports, the Financial Supervisory Service (FSS) recently sent Dunamu an inspection opinion letter outlining findings related to the incident. The notice represents an early formal step in the regulatory process and gives the company an opportunity to respond before authorities determine whether sanctions should be imposed.
The case is particularly significant because it could expose a gap in South Korea’s existing crypto regulatory framework, which does not clearly establish penalties specifically for hacking incidents and failures involving exchange computer systems.
Upbit faces scrutiny over handling of $36M hack
The security breach reportedly began at around 4:42 a.m. Korea Standard Time on November 27, 2025, and continued for approximately 54 minutes.
Upbit later disclosed that roughly $36 million in digital assets had been affected.
However, the exchange also faced criticism over the timing of its public announcement. According to reports, Upbit did not formally disclose the incident until later that day, after a merger-related event involving Naver Financial had concluded.
Regulators are now examining the circumstances surrounding the breach and the exchange’s response, including whether its handling of the incident violated obligations under South Korea’s Virtual Asset User Protection Act.
Regulatory gap complicates potential penalties
One of the central issues is whether existing South Korean crypto legislation provides regulators with sufficient authority to impose sanctions specifically related to cyberattacks and computer-system failures.
The Virtual Asset User Protection Act strengthened requirements around customer asset protection, unfair trading practices and oversight of virtual asset service providers. However, reports indicate that it lacks explicit sanctions provisions addressing certain hacking and IT-system incidents.
That creates uncertainty over what penalties authorities could impose on Dunamu if violations are established.
South Korean policymakers are reportedly seeking to close this gap through the next phase of the country’s digital asset legislation. Proposed rules could introduce clearer sanctions and compensation requirements when crypto platforms suffer hacks, security failures or major computer-system disruptions.
The Dunamu case could therefore become an important test of how regulators handle exchange cybersecurity incidents under the current framework.
Upbit reimbursed users and strengthened security
Following the November exploit, Upbit said it took several measures to contain the damage and protect customers.
The exchange reportedly froze approximately 2.3 billion won, or around $1.5 million, connected to the stolen assets and committed to reimbursing affected customers using its own funds.
Upbit also began restructuring its wallet architecture, moving assets away from affected wallets and reviewing potential security vulnerabilities.
In December 2025, the exchange introduced its Onchain AI Tracer System, an automated blockchain-tracking tool designed to follow stolen assets across onchain transactions and support recovery efforts.
The system reflects a broader trend among major crypto platforms toward using blockchain analytics and AI-assisted monitoring to respond more quickly to hacks and trace illicit fund movements.
Case could shape South Korea’s next crypto rules
The regulatory action carries wider implications because Upbit is one of South Korea’s most influential cryptocurrency exchanges and a major player in global spot trading.
Any sanctions against its operator could establish an important precedent for how South Korean authorities assess cybersecurity controls, incident disclosure, customer compensation and operational responsibility at crypto exchanges.
The case also highlights an evolving challenge for crypto regulation: protecting users requires more than rules against market manipulation and misuse of customer assets. Regulators increasingly need clear frameworks governing what happens when exchanges suffer hacks, infrastructure failures or other major security incidents.
As South Korea develops the next phase of its digital asset legislation, the Dunamu investigation could help shape stricter standards for exchange cybersecurity, breach reporting and customer compensation across the country’s crypto industry.

