Dunamu Faces Sanctions Process Over ₩44.5B Hack
South Korea’s Financial Supervisory Service has begun a sanctions process against Dunamu, the operator of crypto exchange Upbit, after a 44.5 billion won hack in November 2025.
The regulator sent Dunamu an inspection opinion letter after a seven-month review. The document starts the enforcement process but does not impose a penalty or determine that the company violated the law.
Solana-Linked Assets Left Upbit in 54 Minutes
Upbit detected unauthorized transfers of Solana-network assets to an external wallet on November 27. The withdrawals occurred between 4:42 a.m. and 5:36 a.m., giving the attacker about 54 minutes to move the funds.
Dunamu initially estimated the loss at 54 billion won before revising it to 44.5 billion won. The company said customer assets accounted for 38.6 billion won of the total and were fully reimbursed using Upbit’s own reserves. Another 5.9 billion won represented Upbit’s corporate loss.
Dunamu Froze ₩2.6B and Rebuilt Wallets
The exchange has frozen 2.6 billion won of the stolen assets and is pursuing recovery. Dunamu said it rebuilt parts of its wallet system after identifying a weakness that could allow attackers to infer private keys by analyzing publicly visible wallet transactions.
The company’s response will now form part of the regulator’s review of its security controls and incident handling.
FSS Reviews Controls and Disclosure Timing
The FSS has been reviewing whether Dunamu breached the Virtual Asset User Protection Act. Upbit also faced criticism because it disclosed the attack only after a Naver Financial merger event held later on the day of the breach.
No evidence has been published showing that the timing caused additional customer losses. The disclosure issue may still affect the regulator’s assessment of Dunamu’s incident response and internal controls.
Lazarus Attribution Remains Unconfirmed
South Korean authorities have suspected North Korea-linked attackers, including the Lazarus Group. Neither Upbit nor regulators have formally confirmed attribution.
That leaves the sanctions process focused on Dunamu’s security controls, disclosure timing and legal obligations rather than a confirmed attacker identity.
Current Law Leaves Sanctions Outcome Uncertain
The Virtual Asset User Protection Act focuses on customer assets and unfair trading but contains no direct sanctions for exchange hacks or IT system failures. That gap could limit the severity of any sanction imposed on Dunamu.
Authorities plan to add hacking, system-failure and compensation provisions to South Korea’s proposed Digital Asset Basic Act.
Dunamu will first receive an opportunity to respond. The FSS will then issue a proposed sanction before the case proceeds through its Sanctions Review Committee, the Securities and Futures Commission and the Financial Services Commission for a final decision.