
Dunamu Faces Sanction Proceedings 8 Months After $36 Million Hack
South Korea's Financial Supervisory Service has begun official sanction procedures against Dunamu, the operator of Upbit, regarding a $36 million hack that occurred last November. This action is expected to set a significant precedent amid a regulatory vacuum concerning security responsibilities in the virtual asset market.
In July 2026, the South Korean Financial Supervisory Service (FSS) launched formal sanctions proceedings against Dunamu, the operator of the country's largest virtual asset exchange, Upbit. This action comes approximately eight months after a hot wallet hack involving about $36 million occurred in November 2025. Regulatory authorities are demonstrating their commitment to holding virtual asset service providers strictly accountable for security management through this process.
The initiation of these sanctions proceedings by the FSS marks a significant turning point for South Korean regulators in holding virtual asset service providers directly accountable for IT security failures.
Currently, the FSS has not finalized the specific level of sanctions but is reported to have notified Dunamu of the investigation results and provided an opportunity for explanation. Dunamu can contest the findings or explain its security enhancement measures during the upcoming committee deliberation process. This case is expected to serve as an important precedent as the regulatory framework for the virtual asset market is established.
The November 2025 Breach: A $36 Million Outflow
The security incident that occurred on November 27, 2025, precisely targeted Upbit's hot wallet, resulting in the theft of Solana-based assets worth approximately 44.5 billion KRW (valued at about $36 million at the time). Investigations revealed that the attackers used methods such as seizing or impersonating administrator privileges, showing a pattern similar to a hack that occurred in 2019. Security experts and authorities have identified the Lazarus Group, a North Korean hacking organization, as the entity behind the attack.
- November 27, 2025, 4:42 AM: Hacking begins and initial unauthorized leak detected
- 5:00 AM: Emergency meeting of Upbit officials convened
- 5:27 AM: Suspension of Solana network deposits and withdrawals
- End of business day: Official public announcement regarding the hacking incident
Upbit has been embroiled in a "delayed disclosure" controversy due to the gap between the time the hacking was recognized and the time it was actually announced to the public. In particular, the core of the criticism is that the hacking announcement was made after a major business event related to Naver Financial had concluded. Regulatory authorities are closely examining whether this disclosure timing violates investor protection principles.
It is pointed out as a regulatory hurdle that South Korea's current virtual asset-related laws lack explicit provisions to directly sanction hacking or IT security failures. The Virtual Asset Framework Act, which will be fully implemented starting in 2026, plans to introduce the principle of strict liability for digital asset accidents, but this Dunamu case is proceeding during a legal vacuum. Accordingly, the Financial Supervisory Service plans to hold them accountable by making the most of existing supervisory regulations.
Impact on Corporate Operations and Management
Since Dunamu is not currently classified as a financial company under Korean law, it is highly likely that the five-year employment restriction for sanctioned executives will not directly apply. As a result, there is a structural peculiarity where management, including CEO Lee Sir-goo, can maintain their positions or seek reappointment regardless of the sanction results. However, friction with regulatory authorities is expected to act as a significant burden on the company's future external credibility and business expansion.
In particular, the share swap transaction with Naver Financial that Dunamu is pursuing could be affected by the outcome of these sanction proceedings. Both companies have extended the completion deadline for the transaction to December 31, 2026, and several stages of regulatory approval procedures remain. Analysis suggests that while this security incident investigation may not be a direct reason for determining the approval of the transaction, it could be considered a negative factor during the review process.
In conclusion, the sanction proceedings against Dunamu are evaluated as an opportunity to raise the transparency and security level of the Korean virtual asset market by one step. In the process of regulatory overhaul that will continue until the end of 2026, this case will serve as a benchmark for setting the level of punishment and the scope of responsibility for similar accidents that may occur in the future. Investors are paying attention to how the regulatory authorities' final decision will affect the restoration of market trust.



This content is for information and commentary only and is not investment advice.
Join the reader conversation
Read reactions to this article and leave your own note.