South Korea moves against Upbit's parent, eight months after the hack

iEXExchanger
South Korea moves against Upbit's parent, eight months after the hack

South Korea's financial watchdog has formally opened sanctions proceedings against Dunamu, Upbit's parent, over a $30 million hot-wallet hack from November. The law on punishing such breaches isn't even written yet.

For seven months South Korea's financial watchdog stayed quiet. Now it's finally asking Upbit's parent company to explain itself. The Financial Supervisory Service sent Dunamu a formal notice opening sanctions proceedings — nearly eight months after hackers drained roughly 44.5 billion won, about $30 million, in Solana-based assets from Upbit's hot wallet.

The breach happened in the early hours of November 27, 2025, and lasted just 54 minutes. North Korea's Lazarus Group is the suspected culprit, though nothing has been confirmed officially. Dunamu covered most of the damage, around 38.6 billion won, from its own reserves and managed to freeze roughly 2.3 to 2.6 billion won of the stolen funds. The bigger blow to its reputation came from timing: Upbit disclosed the hack only after wrapping up a same-day merger announcement with Naver Financial, a sequence regulators and users read as an attempt to keep the deal news clean.

Seven months of FSS review turned up both security gaps at the exchange and delays in how the breach was disclosed. What's holding back an actual penalty is a gap in the law itself: South Korea's Virtual Asset User Protection Act has no direct provisions for punishing exchanges over hacks or system failures. A second phase of the country's Digital Asset Basic Act is meant to close that hole, but it's still being drafted. Until then, any sanction has to clear a review committee, the securities regulator and the Financial Services Commission, so a quick fine isn't coming.

This is already the second major hot-wallet breach at Upbit in six years, and it's still South Korea's largest exchange by volume. The FSS is running a parallel review of rival Bithumb over bitcoin allocation issues. How this case ends could set the first real precedent for how hard Korea is willing to come down on exchanges over security failures — there hasn't been one until now.

Questions and answers

Frequently asked questions about this article

What happened in the Upbit hack?

On November 27, 2025, hackers drained roughly 44.5 billion won (~$30 million) in Solana-based assets from Upbit's hot wallet in just 54 minutes. North Korea's Lazarus Group is suspected, though not officially confirmed.

What does Dunamu now face?

The FSS sent Dunamu an inspection opinion letter, formally opening sanctions proceedings. The final penalty still needs sign-off from a review committee, the securities regulator and the Financial Services Commission, so this will take time.

Why doesn't South Korea have a law punishing exchanges for hacks yet?

The current Virtual Asset User Protection Act was written mainly to cover market manipulation and misappropriation, not cyberattacks. Direct provisions on penalties for hacks or system failures are meant to come from a second phase of the Digital Asset Basic Act, which is still being drafted.

Is this the first time Upbit was hacked?

No. This is already the second major hot-wallet breach at Upbit in six years, even though it remains South Korea's largest exchange by trading volume.