FSS opens sanctions process against Dunamu over $30M hack
South Korea’s Financial Supervisory Service has opened sanction procedures against Dunamu over a roughly $30 million Solana asset theft from Nov. 27.
South Korea’s Financial Supervisory Service has initiated formal sanction procedures against Dunamu, the operator of crypto exchange Upbit, over a theft of Solana-based assets that occurred on Nov. 27. The regulator has provided Dunamu with an inspection report after an inquiry that began about seven months ago.
Around 4:42 a.m. local time on Nov. 27, about 44.5 billion won was transferred from Upbit to an external wallet over roughly 54 minutes. Dunamu covered 38.6 billion won in customer losses from its own reserves and has frozen 2.6 billion won of the stolen funds while seeking further recovery. The company initially reported freezing 2.3 billion won in the days after the breach.
The FSS has been examining whether the incident violated the Virtual Asset User Protection Act, which addresses user protection and unfair trading. That law does not contain explicit provisions for sanctioning exchanges over hacks or IT failures, leaving uncertainty over the scope of penalties available to regulators.
Lawmakers intend to add rules on sanctions and compensation for hacking and IT incidents in the second phase of crypto legislation, known as the Digital Asset Basic Act. The FSS plans to notify Dunamu of a proposed sanction level after a clarification process. Final penalties will be determined through deliberations by the regulator’s Sanctions Review Committee, the Securities and Futures Commission and the Financial Services Commission.
Upbit drew criticism for the timing of its disclosure because the exchange announced the breach only after a corporate event tied to a proposed stock-swap merger with a fintech affiliate had ended. The merger was delayed and is now scheduled for Dec. 31, meaning the sanction process will continue while the deal remains pending.
South Korean authorities have publicly indicated a belief that the Lazarus Group, a North Korea-linked hacking collective, may be involved, but neither Dunamu nor regulators have issued formal attribution. The FSS has also completed a separate inspection of rival exchange Bithumb over a misallocated bitcoin incident and plans to begin sanction procedures there once legal reviews are finished. The regulator will pause its inspections for three weeks and resume in mid-August.
Lee Chan-jin, governor of the Financial Supervisory Service, told a December briefing that “sanctions under the Virtual Asset User Protection Act have limits, but the hack was not something the regulator could simply pass over.”
The content on The Coinomist is for informational purposes only and should not be interpreted as financial advice. While we strive to provide accurate and up-to-date information, we do not guarantee the accuracy, completeness, or reliability of any content. Neither we accept liability for any errors or omissions in the information provided or for any financial losses incurred as a result of relying on this information. Actions based on this content are at your own risk. Always do your own research and consult a professional. See our Terms, Privacy Policy, and Disclaimers for more details.








