South Korean regulators begin sanctions process over Upbit after 44.5 billion won hack

South Korean regulators begin sanctions process over Upbit after 44.5 billion won hack

Authorities have opened sanctions procedures against Dunamu over Upbit’s response to the November hack as Seoul moves to draft compensation and penalty rules under a Digital Asset Basic Act.

Fact Check
The primary Yonhap News report and corroborating Cointelegraph and Bloomingbit articles all confirm that South Korea's Financial Supervisory Service sent an inspection opinion letter to Dunamu (Upbit's operator), formally beginning a sanctions process over the 44.5 billion won hack. All sources confirm the highlighted legal gap: the current Virtual Asset User Protection Act lacks explicit penalties for hacking incidents. They also confirm authorities reviewed Upbit's response (delayed disclosure) and customer reimbursement (full compensation from Upbit's own funds). The 44.5 billion won hack figure is independently confirmed by Reuters and Korea Times.
Summary

South Korea’s Financial Supervisory Service has formally started sanctions proceedings against Dunamu, the operator of Upbit, after a November 2025 hack drained about 44.5 billion won, or roughly $30 million, from the exchange. Most of the losses were covered with company funds, while some stolen assets were frozen and recovered. Authorities suspect Lazarus was behind the attack. The case has drawn attention to gaps in South Korea’s current crypto framework, which does not provide direct penalties for hacks or system failures, prompting plans to establish sanctions and compensation rules under a Digital Asset Basic Act.

Terms & Concepts
  • Lazarus: A hacking group suspected by authorities in this case and widely associated with cyberattacks targeting crypto platforms and financial institutions.
  • Digital Asset Basic Act: A proposed South Korean law intended to set broader rules for digital-asset markets, including sanctions and compensation standards.