South Korea Opens Sanctions Process Against Upbit Operator Dunamu, Nearly Eight Months After $30 Million Solana Hack
South Korea's Financial Supervisory Service (FSS) has formally initiated a sanctions review process against Dunamu, the company that operates the country's largest cryptocurrency exchange Upbit, following a roughly $30 million hack in November 2025 (some sources report the figure as $36 million; the lower estimate reflects a conversion of the confirmed 44.5 billion Korean won at the exchange rate prevailing at the time of the breach).
South Korea's Financial Supervisory Service (FSS) has formally initiated a sanctions review process against Dunamu, the company that operates the country's largest cryptocurrency exchange Upbit, following a roughly $30 million hack in November 2025 (some sources report the figure as $36 million; the lower estimate reflects a conversion of the confirmed 44.5 billion Korean won at the exchange rate prevailing at the time of the breach). The move comes nearly eight months after attackers drained Upbit's Solana hot wallet in a 54-minute breach, and it places Dunamu at the start of a multi-stage regulatory process whose outcome remains uncertain due to gaps in current law.
What Happened
The breach occurred on November 27, 2025, beginning at approximately 4:42 AM Korean Standard Time. The date carries additional resonance: November 27 is the same calendar date on which Upbit was targeted in its 2019 attack, a breach attributed to Lazarus Group in which 342,000 ETH worth approximately $50 million was stolen. The 2025 hack also occurred on the same day Dunamu announced its merger with Naver Financial, a deal Bloomberg valued at approximately $10.3 billion.
Attackers targeted Upbit's Solana hot wallet, a type of internet-connected wallet used for active trading rather than long-term storage, and extracted funds at a rate of roughly $9,296 per second. Over 54 minutes, the thieves removed approximately 44.5 billion Korean won, equivalent to between $30 million and $32 million depending on the exchange rate used. Stolen assets included several Solana-network tokens: SOL, USDC, BONK, JUP, RAY, RENDER, ORCA, and PYTH. BONK, a meme token, accounted for roughly 91 percent of the total stolen token volume, though SOL alone represented approximately $12.9 million of the total.
Security firm Halborn and South Korean investigators identified a critical vulnerability in wallet software potentially capable of leaking private key data through publicly visible blockchain records. Dunamu has not officially confirmed this was the entry point.
Lazarus Group, the state-backed North Korean hacking unit operating under Pyongyang's Reconnaissance General Bureau, was flagged as the primary suspect by the National Police Agency's Cyber Terrorism Investigation Unit. The group is widely believed to conduct cryptocurrency theft to fund Pyongyang's missile and military programs. No formal attribution has been confirmed.
An Upbit spokesperson told DL News: "After the hack, we focused on preventing further withdrawals." The exchange pledged full reimbursement to all affected users.
Separately, according to DL News, the FSS was not notified until more than six hours after the breach was detected internally, a delay that drew criticism.
The Regulatory Process and Its Legal Problem
The FSS spent approximately seven months conducting its investigation before issuing an inspection opinion letter to Dunamu in July 2026. According to a report by The Block, citing Korean-language media, that letter triggers a formal sequence: review by the FSS Sanctions Review Committee, referral to the Securities and Futures Commission, and then a final penalty determination. No timeline for a resolution has been announced.
The process faces a structural obstacle. South Korea's Virtual Asset User Protection Act, which took effect in July 2024, established rules on cold wallet storage minimums (80 percent of customer assets must be held offline), liability insurance requirements (exchanges must maintain coverage of at least 5 percent of hot wallet value, with a minimum of KRW 3 billion), and market manipulation prohibitions.
However, the law includes no explicit sanction provisions for hacking incidents or IT infrastructure failures at exchanges.
DL News reported that Seoul city officials described this gap as a "lack of ability to impose severe disciplinary measures." The attribution is notable: the characterization of a national financial regulator's enforcement capacity by municipal officials is institutionally unusual and may reflect a translation artifact or paraphrase in the original sourcing chain.
Legal experts and analysts watching the case note that it will test whether regulators can impose meaningful penalties under existing authority, or whether legislators will need to act first.
A Second Enforcement Track: AML Fines
South Korea's Financial Intelligence Unit (FIU) previously fined Dunamu 35.2 billion won, approximately $25 million, for 5.3 million cases of customer identity verification failures and 15 failures to report suspicious transactions. The FIU also imposed a three-month suspension on new customer virtual asset transfers beginning in February 2025.
A Seoul court partially overturned the transfer suspension in April 2026. Dunamu cited a relevant precedent in its challenge: a 2 billion won FIU fine against exchange Hanbitco, which involved roughly 200 users, was fully overturned by the same court.
Responding to the FIU fine, a Dunamu spokesperson said the company was "conducting a careful internal review, including an assessment of the accuracy of the sanction's findings."
Upbit is not alone in facing regulatory pressure. South Korea's FIU investigated all five major licensed domestic exchanges, Upbit, Bithumb, Coinone, Korbit, and GOPAX, and found violations across the board. Bithumb received a fine of approximately 36.8 billion won and a partial six-month business suspension in March 2026. Coinone was fined roughly 5.2 billion won with a three-month suspension in April 2026. Penalty details for Korbit and GOPAX were not available at publication time.
Why This Matters Beyond South Korea
Upbit controls roughly 65 to 72 percent of South Korea's domestic crypto trading volume, serves approximately 4.53 million monthly active users, and processed approximately 833 trillion won, around $642 billion, in trading volume during the first half of 2025 alone.
Analysts note that a security failure at that scale of market concentration carries systemic implications, both for South Korea's domestic financial system and for the broader regional regulatory environment.
For regulators in South Asia and Africa currently drafting or refining virtual asset frameworks, the Dunamu case offers a concrete lesson in legislative design. South Korea's law established meaningful structural safeguards: a requirement that 80 percent of customer assets be held in cold storage, mandatory liability insurance floors, and market manipulation prohibitions. What it did not establish was any explicit enforcement mechanism for exchange-level security failures or IT infrastructure breaches. The absence of binding incident-response reporting timelines compounds the problem, as the six-hour delay in notifying the FSS drew criticism but faced no clear legal consequence. That combination of omissions is now the central obstacle to accountability in this case.
India's pending digital asset legislation, Pakistan's Securities and Exchange Commission crypto framework, Nigeria's advancing virtual asset rules, Kenya's emerging crypto oversight regime, South Africa's Financial Sector Conduct Authority framework, Ghana's developing digital asset policies, and the frameworks taking shape in Bangladesh and Sri Lanka all face the same foundational question South Korea confronted in 2024: whether to include explicit enforcement clauses for exchange-level security failures, binding incident-response reporting timelines, and minimum liability insurance requirements. The Upbit case illustrates the risk of leaving that question unanswered.
The breach also carries specific implications for developers and users across the Solana ecosystem. Several of the stolen tokens, including BONK, JUP, RAY, RENDER, ORCA, and PYTH, are central to Solana's DeFi and application layers, and the identified hot wallet vulnerability points to infrastructure risks that extend beyond any single exchange.
South Korea has signalled intent to treat crypto exchanges more like banks following the breach, according to TradingView and CryptoNews, though no legislative amendment had been confirmed as of publication.
The outcome of the FSS sanctions process will, whenever it concludes, constitute what analysts regard as a significant test of the country's current regulatory architecture. The central question is whether the Virtual Asset User Protection Act can support meaningful penalties for security failures its drafters did not explicitly address.