South Korean Regulator Targets Dunamu with Sanctions Over $36 Million Hack
The Financial Supervisory Service (FSS) in South Korea has initiated a formal sanctions process against Dunamu, the operator of Upbit, following a $36 million exploit on the exchange in November 2025.
According to Yonhap News, the FSS sent an inspection opinion letter to Dunamu, which marks the beginning of a sanctions procedure. The regulator is assessing whether Upbit violated the Virtual Asset User Protection Act, but this law lacks direct penalties for cyberattacks and computer hacks.
The incident occurred on November 27, 2025, when hackers breached Upbit's system, resulting in a $36 million loss. Although the exchange reimbursed affected customers using its own balance sheet funds, regulators are scrutinizing the timing of the public disclosure, which coincided with a merger-related event involving Naver Financial.
The FSS is also considering adding sanctions and compensation provisions for hacking and computer system failures into the second phase of the Digital Asset Basic Act. This move aims to address the current regulatory gap in South Korea's crypto market.




