South Korea’s Financial Supervisory Service has begun formal sanctions proceedings against Dunum, the operator of virtual currency exchange Upbit, over a large-scale wallet breach reported in November 2025.
The action follows a months-long examination of whether exchanges are meeting their obligations under the country’s Virtual Asset User Protection Act.
The FSS recently sent an inspection opinion to Dunham, SBS reported, citing financial authorities. The document gives the company an opportunity to respond before regulators decide what penalties, if any, to impose. The process then goes through several formal regulatory review stages.
FSS reviews Upbit’s response to 2025 data breach
The November 27 attack affected Solana-based assets held by Upbit. Early estimates varied, with crypto.news reporting a loss of approximately $36 million based on numbers available at the time. A South Korean report said the impact was 44.5 billion won, equivalent to about $32 million at current exchange rates.
Upbit said that after detecting the abnormal transfer, it moved the assets to a cold wallet, stopped deposits and withdrawals, and began tracking the stolen funds. The exchange said in an official customer notice that customer losses would be covered by company funds. Authorities subsequently investigated both the security flaws and the timing of Upbit’s disclosure.
Legal gaps cloud potential sanctions
The current Crypto Asset User Protection Act gives regulators powers regarding custody, unfair trade, and customer protection, but specifically does not provide direct penalties for hacking or computer system failure. In this case, there remains uncertainty as to the extent to which FSS can respond.
The regulator will consider Dunham’s response before issuing an advance notice of the proposed action. The final action will require further consideration by the Sanctions Review Board, the Securities and Futures Commission, and the Financial Services Commission. South Korean authorities are also considering tightening rules against hacking and technological failures in the next phase of the digital asset law.
Upbit faces broader regulatory pressure
The hack occurred during a period of close regulatory attention to Dunamu. As reported by crypto.news, South Korea’s Financial Intelligence Service previously fined the company 35.2 billion won for anti-money laundering and customer verification failures.
This initial enforcement action was later subject to court scrutiny. Crypto.news reported that the court revoked a three-month partial suspension against Dunamu after finding the legal basis used for the sanction to be flawed. The latest hacking incident could pose new challenges to how existing laws apply to the operations of cryptocurrency exchanges.
Dunam’s Naver contract is still under review
The sanctions process also comes as Dunham works on a share swap plan with Naver Financial. The companies recently postponed the closing of the transaction to December 31, as several regulatory approvals still remain.
Current checks do not automatically block the transaction. However, Dunam remains under multiple layers of regulatory scrutiny while South Korea prepares broader digital asset rules. The FSS has not yet announced the proposed sanction level for the hacking incident, and Dunham still has the opportunity to challenge the test results before making a final decision.

