South Korea’s FSS Targets Dunamu Over Upbit Hack as Legal Gaps Surface

Daily Feed
South Korea’s FSS Targets Dunamu Over Upbit Hack as Legal Gaps Surface

South Korea’s financial watchdog has moved against Dunamu after Upbit’s November 27 wallet breach, and the case is exposing a familiar crypto problem: regulators want clear accountability, but the law still looks muddy around hacks and system failures.

  • FSS begins formal sanctions process
  • Upbit breach hit Solana-based assets
  • Legal gap complicates enforcement
  • Upbit says users will be made whole
  • Case may shape future South Korean crypto rules

South Korea’s Financial Supervisory Service (FSS) has begun a formal sanctions process against Dunamu, the operator of crypto exchange Upbit, following a major wallet breach reported in November 2025. The move follows a months-long inspection into whether Upbit met its duties under the Virtual Asset User Protection Act, South Korea’s crypto law focused on custody, unfair trading, and customer protection.

The breach happened on November 27 and hit Solana-based assets held by Upbit. Early estimates put losses at about $36 million, while later South Korean reports placed the affected amount at 44.5 billion won, or roughly $32 million at current exchange rates. The gap likely comes down to shifting valuations and updated reporting, but the point is unchanged: a major exchange got hammered, and the regulator is asking hard questions. Coverage of the incident has been scattered across outlets including Understanding Yahoo's Consent Page, while reporting from South Korea targets Dunamu over Upbit hack as legal gaps and South Korea targets Dunamu over Upbit hack as legal gaps has tracked the regulator’s response.

According to reporting cited by SBS and crypto.news, the FSS sent Dunamu an inspection opinion letter, which gives the company a chance to respond before any penalties are finalized. In plain English, the regulator has not handed down punishment yet, but Dunamu is already on the clock.

Upbit said it responded by moving assets to cold wallets, halting deposits and withdrawals, and tracing stolen funds after detecting abnormal transfers. In its official customer notice, the exchange said customer losses would be covered with company funds.

That is the right move. If an exchange gets clipped, users should not be left holding the bag because some centralized system blew a hole in the side of the ship. Cold wallets, which are offline storage meant to reduce hacking risk, are standard for a reason. They are not magic, though. Once private keys or internal controls are compromised, the damage can spread fast.

The bigger problem is legal. The current Virtual Asset User Protection Act gives regulators tools over custody, unfair trading, and customer protection, but it reportedly does not set direct penalties specifically for hacking or computer system failures. That leaves authorities in an awkward spot. They can investigate the breach, review the response, and question disclosure timing, but they may not have a clean statutory basis for punishing the hack itself.

That ambiguity is not just a technicality. If regulators want sanctions to stick, they need a clear legal foundation. South Korea has already run into that problem in a separate Dunamu case, including the South Korean Court Overturns FIU's Business Suspension and the earlier South Korea targets Dunamu over Upbit hack as legal gaps emerge reporting that pointed to the same legal friction.

The Financial Intelligence Unit previously slapped Dunamu with a 35.2 billion won fine over anti-money laundering and customer verification failures. A court later canceled a three-month partial suspension after finding gaps in the legal basis for the sanction. That ruling matters because it shows courts are willing to push back when regulators stretch a law beyond what it clearly says. No fancy legal gymnastics. No make-believe penalty power.

The current case still has a long road ahead before anything is final. Any proposed measure would have to go through the sanctions review committee, the Securities and Futures Commission, and the Financial Services Commission. That process can filter, reduce, or reshape a penalty before it becomes official.

Authorities are also looking at how Upbit handled its public disclosure. That matters, because crypto enforcement often turns on more than the breach itself. How fast did the exchange detect the problem? How quickly were deposits and withdrawals halted? Did users get clear information, or a polished wall of corporate fog? Those details can matter almost as much as the theft.

South Korean authorities are reportedly considering stronger rules for hacking and technology failures in the next phase of digital asset legislation. That would make sense. Crypto exchanges are centralized targets with big pools of customer assets, which makes them catnip for attackers. If the industry wants to be treated like serious financial infrastructure, it also has to accept serious operational standards. No more “move fast and hope the keys don’t leak.”

The timing of this enforcement push also lands alongside a separate corporate wrinkle: Dunamu and Naver Financial delayed completion of a planned share swap to December 31 because regulatory approvals are still outstanding. The current inspection does not automatically block that deal, but ongoing enforcement pressure is not exactly the kind of backdrop that calms investors or counterparties. The broader consolidation angle has been covered in pieces such as Naver Eyes Dunamu Acquisition to Dominate South Korea’s, Naver Acquires Upbit Operator Dunamu in Bold Equity Swap to, and Hana Bank Invests $670M in Dunamu, Expanding South Korea’s.

For Dunamu, the immediate question is not whether regulators are paying attention, they clearly are, but how they will frame the breach under a law that does not directly spell out penalties for hacks. For South Korea, the larger question is whether the country wants to keep improvising around legal gaps or finally write rules that fit the risks of modern exchange custody.

If exchanges are going to hold billions in customer assets, they need to be held to something better than vague expectations and post-breach finger-pointing. Otherwise, every hack turns into the same tired routine: users get burned, regulators scramble, lawyers feast, and the law gets dragged behind the technology like a tin can tied to a race car.

Key takeaways

  • What did South Korea’s regulator do?
    The Financial Supervisory Service opened a formal sanctions process against Dunamu, but no final penalty has been announced yet.

  • What triggered the action?
    A November 27 wallet breach at Upbit that affected Solana-based assets and led to reported losses of about $32 million to $36 million.

  • Why is the legal issue messy?
    The current Virtual Asset User Protection Act covers custody, unfair trading, and customer protection, but does not clearly set direct penalties for hacking or system failures.

  • Did Upbit try to compensate users?
    Yes. Upbit said customer losses would be covered with company funds, which may help restore trust but does not erase regulatory scrutiny.

  • Could this change South Korea’s crypto rules?
    It could. The case strengthens the argument for clearer rules on exchange security, incident response, and penalties for technical failures.

Share this article

Powered by ADBYTES

Advertise smarter.

Adbytes.Media is a transparent advertising network where advertisers reach real audiences and publishers, affiliates & everyday members earn ADBYTES tokens. Join the community and start earning today.

Back to Blog