South Korea Initiates Sanctions Against Upbit Operator Dunamu Following 2025 Security Breach and Disclosure Delay

Hack timeline and disclosure delay: the Upbit breach began at 4:42 a.m. KST on November 27, 2025 and lasted about 54 minutes, with Upbit not publicly disclosing the incident until later that day after a merger-related event involving Naver Financial.
Sanction scope may include warnings, operational restrictions, or suspension, and penalties can be targeted at specific business units or senior managers; a hearing will determine the type and scope of regulatory action.
Sanctions process steps include an inspection opinion letter, a chance for Dunamu to respond, followed by advance notice and final measures that must be reviewed by the sanctions review committee, the Securities and Futures Commission, and the Financial Services Commission.
Cross-border regulatory activity in Asia has intensified since April 2026, with joint statements on transaction reporting standards and stablecoins signaling broader crackdown affecting exchanges.
Regulators note the Virtual Asset User Protection Act lacks explicit sanctions for hacks and computer system failures, prompting Phase 2 of the Digital Asset Basic Act to add sanctions and compensation provisions.
South Korea's Financial Supervisory Service has launched formal sanctions proceedings against Dunamu, the operator of crypto exchange Upbit, over a $36 million hack that struck in November 2025, according to Crypto News. The regulator issued an inspection opinion letter — the first step in a multi-stage process — giving Dunamu a chance to respond before any penalties are set.
At the center of the case is not just the breach itself, but how long Upbit waited to tell the public. Finance Feeds reports the hack began at 4:42 a.m. KST on November 27, 2025 and lasted roughly 54 minutes, targeting Solana-based assets. Upbit did not disclose the incident until later that day — after a separate merger-related event involving Naver Financial had already concluded.
The sanctions process moves through several layers before anything is final. After Dunamu submits its response, regulators issue advance notice, then convene a sanctions review committee. The case then goes to the Securities and Futures Commission and, finally, the Financial Services Commission for a decision, according to Crypto.news.
Penalties could range from a formal warning to operational restrictions or even a suspension of specific business units. Sanctions can also be targeted at senior managers personally — not just the company. A hearing will determine the exact type and scope of any action, Finance Feeds reported.
One major problem is that South Korea's current law may not cover this situation cleanly. The Virtual Asset User Protection Act — the main rulebook for crypto exchanges — does not include explicit sanctions for hacks or computer system failures, according to Crypto News. That means regulators are working with limited tools.
Officials say the fix is coming. Phase 2 of the Digital Asset Basic Act is expected to add new sanctions and compensation rules specifically for security incidents like this one. Until that law passes, though, the FSS must work around the gap — making the Dunamu case a test of what current rules can actually do, LCX noted.
Dunamu has not stayed silent. The company says it reimbursed all affected users using its own corporate reserves after the hack, which was initially valued at around $36 million — later reported as roughly 32 to 44.5 billion Korean won. Upbit also says it moved assets to cold storage and rebuilt its wallet architecture from the ground up, according to Eritv News.
The company says it is cooperating fully with investigators. But regulators are still focused on the delayed public disclosure. The key question is whether Upbit's slow response put users at greater risk — and whether that delay alone warrants a penalty, even if users ultimately got their money back.
The Dunamu case is not happening in a vacuum. Since April 2026, regulators across Asia have ramped up cross-border coordination on crypto oversight. Joint statements on transaction reporting standards and stablecoins have signaled a broader crackdown — and South Korea is among the most aggressive, according to Crypto News.
South Korea is pushing stricter anti-money-laundering rules and stronger investor protections for digital assets. The Upbit sanctions process, even if it ends in just a warning, sends a clear message: exchanges will be held responsible for how they handle breaches — and how fast they tell users about them, Finance Feeds reported.
Publishers
13
Articles
17
Reach
30