The Dunamu, the company responsible for the cryptocurrency exchange Upbit, has begun facing sanctions proceedings in South Korea as a result of the hacker attack that led to the theft of approximately US$ 30 milhões in digital assets at the end of 2025. The measure was initiated by the Financial Supervisory Service (FSS), which concluded an inspection into the incident and recently forwarded a report to the company.
The investigation comes about eight months after the attack that hit the country's largest cryptocurrency exchange by trading volume. At the time, criminals managed to divert 44,5 bilhões de won, equivalent to about US$ 30 million, in assets based on the cryptocurrency Solana (SOL). According to the information disclosed, the transfers were made to an external wallet over approximately 54 minutes.
After identifying the breach, Upbit used its own resources to reimburse affected customers. The company reported that it covered about 38,6 bilhões de won in losses and managed to freeze approximately 2,6 bilhões de won of the stolen assets, while it continues working to recover part of the diverted amounts.
In addition to the attack itself, the exchange was also criticized for how it communicated the incident to the market. The disclosure occurred only after the end of an event related to the merger between Dunamu and Naver Financial, a deal that still depends on completion and was postponed until the end of December this year.
The regulator is analyzing whether there was a violation of the Virtual Asset User Protection Act, the main legislation aimed at the cryptocurrency market in South Korea. However, experts point out that the rule has limitations, since its focus is on user protection and unfair business practices, without establishing specific penalties for cyberattacks or technological infrastructure failures.
Given this gap, South Korean authorities are studying the inclusion of new rules in the future Basic Digital Assets Act. The proposal aims to create specific provisions to hold exchanges accountable in cases of hacker attacks, in addition to defining criteria for sanctions and compensation resulting from incidents involving information technology.
The governor of the Financial Supervisory Service, Lee Chan-jin, had previously indicated that, although the current legislation has limitations, the episode could not be ignored by the regulator. After the clarification period granted to Dunamu, the FSS is expected to inform the proposed level of sanction. The final decision will be the responsibility of the Sanctions Review Committee, the Securities and Futures Commission, and the Financial Services Commission.
Meanwhile, the investigations are still ongoing. South Korean authorities still suspect the involvement of the Lazarus Group, linked to North Korea, although responsibility for the attack has not been officially confirmed by Upbit or by the regulatory bodies.
In parallel, the regulator also concluded an inspection at the exchange Bithumb, related to an incident involving the incorrect allocation of bitcoins. Procedures for possible sanctions are expected to begin after the conclusion of the legal analyses, while the FSS resumes its regular inspections in mid-August.

