
The FSS is testing the boundaries of South Korea's crypto law after a 44.5 billion won hack. The outcome could set a precedent for how regulators handle exchange breaches.
South Korea's financial watchdog has started formal sanctions proceedings against Dunamu, the operator of Upbit, over a 2025 hacking incident that cost 44.5 billion won ($32 million).
The Financial Supervisory Service spent seven months investigating the breach before issuing an inspection opinion letter. A sanctions review committee will weigh in next, followed by the Securities and Futures Commission, before any penalties are imposed.
South Korea's Virtual Asset User Protection Act does not include explicit sanctions provisions for hacking incidents or computer system breaches. That legal gap leaves the scope of potential penalties uncertain.
This is not the first enforcement action against Dunamu. The company already faces a proposed fine of 35.2 billion won ($25 million) for anti-money laundering violations uncovered separately from the hacking probe. Regulators also imposed a suspension on new customer transfers in February 2025. A court partially overturned that suspension in April 2026.
The FSS is testing what the law allows. If regulators impose meaningful sanctions for a hack under a statute that does not address hacking, it would signal broad interpretation of their powers. If the legal ambiguity limits action, it would expose a gap in South Korea's oversight of the crypto market.
The sanctions review committee is expected to meet in the coming weeks.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.