South Korea’s Financial Supervisory Service (FSS) has sent an investigation notice to Dunamu, the parent company of crypto exchange Upbit, and started administrative sanction proceedings over a security incident that hit the platform on Nov. 27 last year.
The move comes after nearly seven months of investigation into the case.
Probe launched under the Virtual Asset User Protection Act
The FSS reviewed the Upbit security breach in which hackers illegally transferred Solana (SOL) assets worth about 44.5 billion won, or roughly $30 million, in less than 54 minutes.
Dunamu used the exchange’s own reserve funds to compensate affected customers for about 38.6 billion won, equivalent to around $26 million. As of now, the company has frozen about 2.6 billion won, or about $1.7 million.
South Korean regulators investigated Dunamu under the Virtual Asset User Protection Act. The report said current regulations do not set out specific punishment clauses for hacking intrusions or information system failures, leaving regulators with limited room for enforcement.
FSS Governor Lee Chan-Jin said authorities would not leave this type of incident unattended. Any final disciplinary action will be reviewed jointly by the Sanctions Review Committee, the Securities and Futures Commission, and the Financial Services Commission.
Naver-related merger delay overlaps with sanction process
According to South Korean broadcaster SBS, Upbit disclosed the hacking incident only after merger-related activity involving Naver Financial had ended, prompting questions in the market over the timing of that disclosure.
A share-swap merger between Dunamu and a fintech company under Naver is still under way. The deal was postponed earlier this month to Dec. 31, meaning the regulator’s administrative sanction process is set to continue before the transaction is formally completed.
Lawmakers plan amendments to address hacking penalties
South Korea’s legislature is preparing to address gaps in the current framework in the second phase of the Digital Asset Basic Act. The planned revisions would add penalty and compensation provisions for hacking attacks and information security incidents affecting systems.
Earlier reports said authorities suspected North Korean hacking group Lazarus Group may have been involved in the case, but neither Upbit nor regulators have publicly confirmed that claim.
FSS also completed a separate Bithumb investigation
Beyond the Upbit case, the FSS has also completed an investigation into a Bitcoin misplacement incident at another exchange, Bithumb, and reviewed its internal risk-control systems. The report said regulators plan to begin related sanctions after that review process is finished.

