South Korea’s Financial Supervisory Service has sent an inspection opinion letter to Dunamu, the operator of Upbit, formally launching the administrative sanctions process over the exchange’s 44.5 billion won hack from November last year. Yonhap reported on Sunday that the document marks the close of the on-site inspection stage and the start of formal disciplinary proceedings.
Sanctions process begins nearly eight months after the breach
Nearly eight months after Upbit was hacked, South Korean regulators have taken their first concrete step toward accountability. According to Yonhap, the Financial Supervisory Service, or FSS, recently delivered the inspection opinion letter to Dunamu. In South Korea’s regulatory process, that document is the formal paper sent after an inspection is completed and serves as the starting point for administrative punishment procedures.
Dunamu must first submit its response to the inspection findings. The FSS will then issue a sanctions opinion notice that lays out the proposed level of punishment. After that, the matter must pass through deliberation by the sanctions review committee, the Securities and Futures Commission, and the Financial Services Commission before any final penalty is confirmed.
No final sanction has been decided yet. What has changed is that the case has now moved into the formal punishment track.
Hack lasted about 54 minutes and involved 44.5 billion won in assets
The report said the breach took place between 4:42 a.m. and 5:36 a.m. on Nov. 27, 2025. During that roughly 54-minute window, hackers transferred Solana-network assets described as about 100 billion tokens to an external wallet. The stolen assets were valued at 44.5 billion won, or about $30.4 million.
The timing of the disclosure drew criticism as well. On the day of the incident, Dunamu was holding a merger-related event with Naver Financial. The company disclosed the hack only after the event ended, prompting complaints that the announcement had been delayed.
2.6 billion won frozen, remaining user losses fully reimbursed
Upbit later said 2.6 billion won of the stolen 44.5 billion won had been frozen and placed into recovery procedures, equal to about $1.78 million. The remaining 38.6 billion won in affected user assets, about $26.4 million, was fully compensated by Upbit using its own funds.
As part of its response, the exchange said it had repaired its wallet structure. It also launched the Onchain AI Tracer System in December 2025 to automatically track the flow of stolen funds on-chain and assist with recovery efforts.
Current law leaves uncertainty over what regulators can punish
The biggest open question is not whether the process has started, but what penalties are actually available and how far regulators can go.
The FSS has been reviewing whether Upbit violated the Virtual Asset User Protection Act. But that law is focused on user protection and unfair trading practices. It does not include direct sanction provisions for hacking incidents or computer system failures, leaving uncertainty over whether Dunamu can face heavy punishment in this case.
Yonhap said South Korean authorities are planning to address that gap in the second phase of legislation through the Digital Asset Basic Act, which would add sanction and compensation provisions tied to hacking incidents and system failures. At the end of last year, the head of the FSS said the agency’s sanctioning authority in this case was “relatively limited,” but added that it was not the kind of matter that could simply be ignored.
That makes the Dunamu case a likely reference point for how South Korean regulators handle exchange hacking cases going forward.
Bithumb case is also in line for sanctions review
Yonhap also said the FSS has completed its inspection into Bithumb’s bitcoin misdelivery incident. Once its legal review is finished, that case will also move into the sanctions process.
The FSS is set to enter a three-week inspection recess starting next week and will resume inspection work in mid-August, according to the report.
Dunamu was already fined 35.2 billion won over KYC and AML failures
The latest case comes after Dunamu was fined 35.2 billion won, or about $24 million, in November 2025 by the Financial Intelligence Unit, or FIU, over deficiencies in KYC and anti-money laundering controls. The report described that penalty as the most expensive fine in South Korean crypto history.
The outcome of the Upbit hack case is also expected to affect the next steps in the $9.9 billion share-swap merger deal between Naver and Dunamu, according to the report.

