Overview of Sanctions Against Dunamu
The Financial Supervisory Service (FSS) of South Korea has initiated a formal sanctions procedure against Dunamu, which runs the popular cryptocurrency exchange Upbit. This move follows a comprehensive investigation that began after Upbit reported a significant security breach in November 2025. The incident raised concerns regarding the exchange’s compliance with the country’s Virtual Asset User Protection Act, designed to safeguard the interests of cryptocurrency users.
Details of the Security Breach
According to a report by SBS, the FSS has recently issued an inspection opinion letter to Dunamu, affording the company an opportunity to respond prior to any penalties being finalized. This process will undergo multiple stages of regulatory review before any formal actions are taken.
The breach, which occurred on November 27, primarily impacted Solana-based cryptocurrencies in Upbit’s holdings. Initial estimates from crypto news outlets suggested losses of approximately $36 million; however, recent reports from South Korean sources indicated that the total affected amount could be around 44.5 billion won, equating to about $32 million based on current currency valuations.
Response and Regulatory Scrutiny
In response to the breach, Upbit temporarily ceased all deposits and withdrawals, transferred its assets to cold wallets, and launched an investigation into the movement of the stolen funds. The exchange has assured its customers that any losses incurred will be compensated through its own resources. In light of these events, authorities are scrutinizing both the lapse in security measures and the timing of Upbit’s notification to the public.
The Virtual Asset User Protection Act empowers regulators to oversee issues related to custody, unfair trading, and customer safeguarding. However, it currently lacks specific sanctions for incidents such as hacking or operational failures, leading to uncertainty about the extent of the FSS’s authority in this scenario.
Future Implications and Regulatory Developments
Before any action is finalized, the regulator will carefully evaluate Dunamu’s response. Proposed sanctions will be subjected to additional reviews by the sanctions review committee, the Securities and Futures Commission, and the Financial Services Commission. In conjunction with these developments, South Korean officials are contemplating more stringent regulations concerning hacking and technological failures as part of future legislation regarding digital assets.
This hacking incident emerges during heightened regulatory surveillance of Dunamu. Previously, the Financial Intelligence Unit had slapped a hefty fine of 35.2 billion won on the firm due to violations related to anti-money laundering and customer identification protocols. Following legal pressures, a court recently reversed a temporary suspension of sanctions against Dunamu, underscoring vulnerabilities in the legal foundations used for the original sanctions.
As the sanctions process unfolds, Dunamu is concurrently navigating a share swap agreement with Naver Financial, which has been postponed to December 31, pending necessary regulatory approvals. Although the current inspection does not halt this deal, Dunamu faces multiple layers of regulatory examination as South Korea takes steps toward more comprehensive digital asset legislation. No specific sanction amounts have been announced in relation to the hacking case, and Dunamu retains the right to contest the findings of the inspection before a final decision is made.