South Korea’s Financial Supervisory Service has formally kicked off sanctions proceedings against Dunamu, the company behind crypto exchange Upbit, following a November 2025 hack that drained roughly $30 million from a Solana-based hot wallet. The FSS sent an inspection opinion letter to Dunamu around July 18-19, marking the official start of what could become a landmark regulatory action in Asia’s most active crypto market.
What happened and what the investigation found
The breach took place on November 27, 2025, when attackers compromised Upbit’s Solana hot wallet. The total damage came to approximately 44.5 billion won, roughly $30 to $37 million depending on exchange rates at the time. About 38.6 billion won of that was customer assets.
The FSS spent seven months investigating the incident, finding security failures at the exchange level and problems with how quickly Upbit disclosed the breach to the public.
Upbit has committed to covering customer losses from its own funds. The exchange also managed to trace and freeze approximately 2.3 billion won, about $1.5 million, of the stolen assets.
South Korean authorities suspect the Lazarus Group, the North Korean state-linked hacking operation, was behind the attack.
A regulatory framework with gaps
South Korea’s existing crypto regulations don’t include specific statutory penalties for security breaches at virtual asset exchanges. Any sanctions against Dunamu will need to pass through a sanctions committee and be reviewed by related financial authorities.
This is also the second time Upbit has suffered a major hot wallet breach in six years.
Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

19 hours ago
3
















English (US) ·