Skip to main content

South Korean Regulator Starts Sanctions Review of Dunamu Over Cyber Case



South Korea’s Financial Supervisory Service (FSS) has reportedly begun a formal sanctions process related to the November 2025 $36 million exploit on Upbit, the country’s major crypto exchange operated by Dunamu. According to Yonhap News, the regulator has sent Dunamu an inspection opinion letter following a review of the incident.


The letter effectively opens the next stage of enforcement. It also gives Dunamu an opportunity to respond to the inspection findings before the FSS moves to notify the company of any proposed sanctions.



Key takeaways



  • The FSS has reportedly issued an inspection opinion letter to Dunamu, kicking off a sanctions procedure after Upbit’s November 2025 $36 million hack.

  • Yonhap reported that regulators are assessing whether Upbit violated the Virtual Asset User Protection Act, even though the law reportedly lacks direct penalties for cyberattacks and computer hacks.

  • Upbit previously said it reimbursed affected customers using its own balance sheet funds and froze certain assets after the breach.

  • Authorities are also weighing changes to South Korea’s Digital Asset Basic Act to add sanctions and compensation provisions for hacking and system failures.

  • Upbit said it upgraded its wallet infrastructure after the incident and later introduced an automatic onchain tracing service intended to support recovery efforts.



FSS inspection letter launches enforcement step


Yonhap News reported Sunday that the FSS recently sent Dunamu an inspection opinion letter connected to the $36 million exploit that affected Upbit in late November 2025. The report frames the letter as the formal start of a sanctions process, with Dunamu able to respond to the findings before the regulator issues details of any proposed penalties.


The FSS is assessing whether the exchange breached the Virtual Asset User Protection Act. However, Yonhap noted that the statute does not provide direct sanctions provisions specifically for cyberattacks or computer hacking incidents.


This creates a compliance pressure point for exchanges and operators in South Korea: even when losses originate from security failures outside traditional financial market conduct, regulators are still attempting to map the incident to existing consumer protection obligations.



Criticism focused on delayed disclosure


Yonhap said Upbit faced criticism for delaying its announcement of the $36 million hack. The breach reportedly lasted about 54 minutes, beginning at 4:42 a.m. KST on November 27, but Upbit did not publicly disclose the incident until the end of the day.


The timing of the public disclosure, according to Yonhap, coincided with a merger-related event involving Naver Financial, after which the exchange finally announced the exploit. The regulatory review described in the report suggests that disclosure timing—along with incident handling—may be a key part of the FSS’s evaluation under the user protection framework.


Cointelegraph said it approached Dunamu for comment on the matter. No further response is included in the provided text.



Regulatory gap and proposed legislative changes


Yonhap also reported that South Korean authorities are considering how to address the current legal gap. The outlet said officials plan to add sanctions and compensation provisions for hacking and computer system failures into the second phase of the Digital Asset Basic Act.


For market participants, the significance is practical: a clearer statutory basis could shift enforcement from interpretive reviews—such as whether a hack violates broader user-protection obligations—to direct, incident-specific penalties and compensation duties. In other words, the likely focus may expand from “did the operator comply with existing rules?” to “did the operator meet explicit standards designed for cyber incidents?”


Until those amendments take effect, operators may remain exposed to enforcement theories rooted in consumer protection and operational responsibility, even where the law lacks cyberattack-specific sanction language.



Upbit’s response: reimbursements, wallet overhaul, and tracing


Upbit’s public response to the November 2025 exploit emphasized customer reimbursement and infrastructure changes. In a statement released after the incident, the exchange said it froze roughly 2.3 billion won (about $1.5 million) worth of funds. Upbit also said it would fully reimburse affected customers using its own balance sheet assets.


Separately, Upbit said it initiated an overhaul of its crypto wallet architecture after the exploit and migrated all assets from the wallets implicated in the incident. The exchange’s stated objective was to reduce exposure to potential vulnerabilities that could allow similar attacks to succeed.


In December 2025, Upbit said it developed an automatic onchain tracking service called the Onchain AI Tracer System, intended to trace the path of stolen funds and support recovery efforts.


These operational updates matter in the regulator’s context because they may influence how authorities assess whether Upbit took adequate steps both immediately after the breach and in the subsequent months. Even when reimbursement addresses direct user losses, regulators may still consider whether changes demonstrate robust incident prevention, transparent communication, and effective post-incident controls.



Upbit also ranks among the larger spot crypto exchanges in South Korea and globally, according to CoinMarketCap’s exchange rankings, which use scoring that includes traffic, liquidity, and trading volume.



Going forward, the key development to watch is Dunamu’s response to the FSS inspection opinion letter, since it will shape what sanctions—if any—are ultimately proposed. At the same time, traders and users should monitor the legislative process around the Digital Asset Basic Act’s next phase, because any move toward explicit hacking-related sanctions and compensation could materially alter how compliance is judged after major security incidents.



https://www.cryptobreaking.com/south-korean-regulator-starts-sanctions/?utm_source=blogger%20&utm_medium=social_auto&utm_campaign=South%20Korean%20Regulator%20Starts%20Sanctions%20Review%20of%20Dunamu%20Over%20Cyber%20Case%20

Comments

Popular posts from this blog

Mastercard Launches AI Agent Pay System With Ripple and Solana Help

Mastercard has launched Agent Pay for Machines, a payments system built for autonomous software agents. The service allows AI agents to send and receive payments without direct human action. It brings Ripple, Coinbase, and Solana Foundation into Mastercard’s push for automated digital commerce. Ripple Brings XRPL and RLUSD to Mastercard’s Agent Pay System Mastercard introduced Agent Pay for Machines on June 10 as a tool for machine-led payments. The system targets high-volume and low-value transactions across business and consumer use cases. It also supports automated settlement between software agents and connected machines. Ripple will support the system through the XRP Ledger and its RLUSD stablecoin. The company said that settlement will become more important as automated commerce grows. It also sees blockchain rails as useful for fast and rule-based payments. RippleX senior vice president Markus Infanger said XRPL and RLUSD support enterprise-grade agent payments. He said the tool...

Coinbase's x402 launches AI agents app store for payments

Coinbase-backed x402 has unveiled Agentic.market, a dedicated marketplace aimed at increasing the usefulness of AI agents by aggregating thousands of apps and services that agents can access without any API keys. The rollout positions the platform as a central hub for agents to discover, evaluate, and deploy capabilities across a standardized payments layer. Coinbase product lead Nick Prince described Agentic.market in a video posted on X as a storefront for discovering, comparing, and using x402 services. The marketplace is designed to give both humans and their AI agents access to a wide range of tools—from data feeds to consumer apps—without the friction of managing API credentials. A storefront for discovering, comparing, and using x402 services. Thousands of services. Zero API keys. Powered by x402. Prince added that the market offers a web interface for humans to browse and assess services, alongside a programming layer that lets AI agents autonomously search, filter, and integra...

Top Cryptocurrencies to Watch: BTC, ETH, BNB, XRP, Solana, Dogecoin & More

Market Analysis and Price Predictions for Key Cryptocurrencies Recent market dynamics reveal a cautious sentiment across the cryptocurrency landscape, with Bitcoin struggling to maintain levels above $90,000 and many major altcoins facing downward pressure. Indicators point toward reduced participation from both institutional and retail investors, raising concerns about a potential consolidation phase after notable gains earlier in the year. Bitcoin has fallen below $87,000, reflecting waning demand at higher price points. Institutional fund flows into BTC and ETH ETFs have turned negative, indicating a period of subdued market activity. Active addresses and Binance deposit/withdrawal activities are at annual lows, suggesting market indecision. Most leading altcoins are approaching support levels, with some poised for potential breakdowns. Tickers mentioned: Bitcoin, Ethereum, Binance Coin, XRP, Solana, Dogecoin, Cardano, Bitcoin Cash, Chainlink, Hyperliquid Sentiment: Neutral to Sli...