South Korea opens sanctions case against Upbit owner over $30m hack
FSS begins formal proceedings against Dunamu after Solana hot wallet breach, exposing gaps in Korea's crypto security rules.

South Korea’s Financial Supervisory Service has opened formal sanctions proceedings against Dunamu, the parent company of the country’s largest cryptocurrency exchange, Upbit, over a hot wallet breach that drained roughly $30 million in November 2025. The move, confirmed by an inspection opinion letter sent to Dunamu around 18-19 July, follows a seven-month investigation and could set a precedent for how Seoul disciplines exchanges after security failures.
The case is being closely watched because South Korea’s existing crypto framework contains no specific statutory penalties for security breaches at virtual asset exchanges. Any sanctions against Dunamu will still need to clear a sanctions committee and be reviewed by other financial authorities before penalties, if any, are finalised.
What the breach involved
Attackers compromised Upbit’s Solana-based hot wallet on 27 November 2025. Total losses came to approximately 44.5 billion won, equivalent to roughly $30 million to $37 million depending on exchange rates at the time, with about 38.6 billion won of that belonging to customers.
South Korean authorities suspect the Lazarus Group, the North Korean state-linked hacking operation, was responsible for the intrusion. Upbit has said it will cover customer losses from its own funds, and the exchange has traced and frozen around 2.3 billion won, roughly $1.5 million, of the stolen assets.
Regulator cites disclosure failures
The FSS’s inquiry, which ran for around seven months, identified both security shortcomings at the exchange level and delays in how quickly Upbit informed the public about the breach. That combination of findings — technical failure and disclosure lag — appears to underpin the regulator’s decision to escalate the matter into a formal sanctions process rather than treat it as a closed incident.
The absence of dedicated statutory penalties for hacking or IT failures at crypto exchanges means the ultimate severity of any sanctions against Dunamu remains uncertain. Regulators may be forced to rely on broader financial conduct rules rather than crypto-specific provisions, a gap that has drawn attention from analysts watching how Seoul polices the sector.
A repeat vulnerability
This marks the second major hot wallet breach at Upbit in six years, raising questions about whether the exchange’s security posture has kept pace with its scale as South Korea’s dominant trading venue. For a market regulator still building out its enforcement toolkit for digital assets, the case offers an early test of how far Seoul is willing to go in holding exchange operators accountable for repeated lapses.
The outcome will also be watched beyond Korea’s borders. As European regulators continue to implement MiCA and debate operational resilience requirements for crypto firms, a precedent-setting sanction against one of Asia’s largest exchanges could inform how supervisors elsewhere approach liability for exchange-level security failures, particularly those linked to state-sponsored actors such as Lazarus Group.
Read more: Consensys halts MetaMask releases after North Korea-linked coder joins team


