
The FSS began sanctions against Dunamu after a November 2025 hack drained $30M from Upbit's Solana hot wallet. Upbit covered customer losses. Next: a sanctions committee review.
South Korea's Financial Supervisory Service has formally started sanctions proceedings against Dunamu, the parent company of crypto exchange Upbit, after a $30 million hot wallet breach last November. The FSS sent an inspection opinion letter to Dunamu around July 18-19, kicking off what could become a landmark regulatory action in Asia's most active crypto market.
The breach hit on November 27, 2025, when attackers compromised Upbit's Solana hot wallet. The total damage came to roughly 44.5 billion won, or about $30 million to $37 million depending on the exchange rate. Customer assets accounted for 38.6 billion won of that.
The FSS spent seven months investigating the incident. It found security failures at the exchange level and problems with how quickly Upbit disclosed the breach to the public.
Upbit has committed to covering customer losses from its own funds. The exchange also traced and froze roughly 2.3 billion won, about $1.5 million, of the stolen assets.
South Korean authorities suspect the Lazarus Group, the North Korean state-linked hacking operation, was behind the attack.
South Korea's existing crypto regulations don't include specific statutory penalties for security breaches at virtual asset exchanges. Any sanctions against Dunamu will need to pass through a sanctions committee and be reviewed by related financial authorities.
This is the second time Upbit has suffered a major hot wallet breach in six years.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.