South Korea’s Financial Supervisory Service (FSS) sent Dunamu, operator of crypto exchange Upbit, an inspection opinion letter and opened a formal sanctions process on July 19, 2026. The case stems from the 44.5 billion won ($32 million) hack that hit the exchange last year.
Key Takeaways
- The FSS sent Dunamu an inspection opinion letter and began sanctions procedures seven months after opening its inquiry, according to Yonhap News.
- Hackers drained 44.5 billion won ($32 million) in Solana-network assets from Upbit in the hack now under regulatory review.
- The stolen assets saw 2.6 billion won ($1.9 million) enter freezing and recovery procedures, according to Dunamu, while 38.6 billion won ($27.8 million) was fully covered with Upbit’s own funds.
- South Korea’s Virtual Asset User Protection Act contains no direct penalty provisions for hacking and system failures, according to Bloomingbit, leaving the severity of any sanctions uncertain.
- FSS Gov. Lee Chan-jin warned in December that the breach and Upbit’s inadequate response “cannot be treated lightly”, according to The Korea Herald, months before the formal process opened.
What Happened?
The inspection opinion letter arrived seven months after the FSS opened its inquiry into the breach, the standard step ahead of formal discipline. The FSS has been reviewing whether Dunamu violated the Virtual Asset User Protection Act since the hack occurred, the law that sets custody and disclosure duties for Korean exchanges.
The regulator plans to give Dunamu advance notice of its sanctions recommendation once the company completes its response process. Final sanctions then require deliberations by the sanctions review committee, the Securities and Futures Commission and the Financial Services Commission before taking effect, a three-body chain that keeps Dunamu’s exposure undefined for now.
South Korea’s FSS Opens Sanctions Case Against Upbit’s Dunamu.
— CoinLaw (@coinlaw_io) July 20, 2026
South Korea’s Financial Supervisory Service opened a formal sanctions process against Dunamu over last year’s @Official_Upbit hack, even though current law has no direct penalty for exchange security failures. pic.twitter.com/LphM2vGd3d
The Enforcement Gap: No Statute for Hacks
The sanctions case tests a law that was not built for this. Current law does not contain direct penalty provisions for hacking and system failures, so it remains unclear whether the case will result in severe sanctions even if the FSS finds a violation.
FSS Gov. Lee Chan-jin told a December press conference that the Virtual Asset User Protection Act’s first phase, implemented in July 2024, does not provide sufficient legal grounds to hold service providers fully accountable for such incidents. “System security is the lifeline of virtual assets,” said Lee Chan-jin, Governor of the Financial Supervisory Service. Lee said the law’s second phase will introduce a regulatory structure comparable to the Capital Markets Act, the framework regulators are counting on to close the gap the FSS is running into now.
That leaves the FSS able to document a violation before it can fully punish one. Korean platforms already show up heavily in cryptocurrency fraud trackers, which makes the missing penalty clause more than a technicality.
From December Warning to a Naver Overhang
Lee also warned in December about the planned merger between Dunamu and Naver, the internet platform giant, saying big tech companies are expanding at a scale the existing financial regulatory framework may struggle to handle. Naver Financial, the fintech arm of Naver, has a share-swap agreement in place to acquire full ownership of Dunamu.
The companies were expected to submit a registration statement for the share swap in February or March, on a timeline that now overlaps the open sanctions review. That timing overlap sharpens the exact scale mismatch Lee flagged as regulators’ own blind spot.
CoinLaw’s Takeaway
The sanctions letter shows a regulator willing to open a case it cannot yet fully punish under the law it enforces, a sequencing problem more than a legal defeat. Dunamu covering 38.6 billion won ($27.8 million) of the stolen funds from Upbit’s own balance sheet bought the exchange goodwill with users, not immunity from the FSS review. The $32 million hack still opened a sanctions case regardless of who paid the bill.
The more useful signal is the mismatched clock: the Naver share swap filing and the FSS sanctions review now run in parallel at the same exchange rather than in sequence. For operators outside Korea, the durable risk is one of timing. A security lapse can resurface in a regulatory review long after the balance sheet damage looks fixed.