TLDR
- South Korean financial authorities delivered inspection findings to Dunamu regarding the Upbit breach that cost $30 million.
- Regulators transmitted their inspection report approximately eight months following the November 27 security incident.
- Attackers drained 44.5 billion won worth of Solana-based tokens to an external address in under an hour.
- The exchange deployed its own reserves to compensate customers for 38.6 billion won in losses.
- Authorities have secured 2.6 billion won of the stolen digital assets while recovery operations continue.
South Korean financial authorities have initiated formal proceedings against Dunamu, the parent company of Upbit, nearly eight months following a cryptocurrency theft valued at $30 million, SBS reported Sunday. South Korea’s Financial Supervisory Service transmitted an official inspection document addressing the November security incident and the platform’s subsequent actions. This development positions Dunamu for potential regulatory consequences, though current legislation may constrain enforcement options.
Financial authorities advance enforcement after extended investigation
The FSS launched its formal examination after attackers withdrew 44.5 billion won in Solana-based digital assets from Upbit on November 27. According to SBS, the unauthorized transfers persisted for approximately 54 minutes, directing the tokens to an external address. Dunamu received the comprehensive inspection findings roughly seven months after authorities initiated their investigation.
The platform compensated customers for 38.6 billion won in compromised assets using its corporate reserves following loss verification. Authorities have successfully frozen 2.6 billion won of the misappropriated funds while Dunamu pursues additional asset recovery. The company had previously announced securing 2.3 billion won immediately following the security compromise.
Investigators scrutinized the timeline of Upbit’s public announcement and information management throughout the crisis. The platform disclosed the security breach following the conclusion of a merger event with Naver Financial on the same date. Dunamu maintains its pursuit of the stock-swap arrangement, though both entities recently extended the completion deadline to December 31.
Current legislation may constrain enforcement options
The FSS investigated potential violations of South Korea’s Virtual Asset User Protection Act. The legislation primarily focuses on customer protection measures and market manipulation rather than cybersecurity incidents or infrastructure failures. This legislative scope could limit enforcement actions available to regulators under existing legal frameworks.
Officials intend to strengthen oversight capabilities through the forthcoming Digital Asset Basic Act, representing the next regulatory evolution. The proposed legislation would introduce comprehensive provisions governing enforcement actions and customer compensation following security breaches and significant technology disruptions. Pending legislative approval, regulators must operate within the current statute’s boundaries.
FSS Governor Lee Chan-jin recognized these constraints during a December 1 media briefing addressing the incident. He stated that while enforcement options under present regulations face limitations, authorities could permit the matter to proceed without scrutiny. The FSS will provide Dunamu an opportunity to present explanations before determining its recommended enforcement measures.
Multiple regulatory bodies will assess proposed actions
Various oversight entities will evaluate the recommended measures before South Korean authorities finalize any enforcement decision. The Sanctions Review Committee will examine the matter, followed by assessments from the Securities and Futures Commission and Financial Services Commission. Dunamu may encounter administrative consequences, though SBS did not specify potential severity or implementation timeline.
Investigators have linked the incident to North Korea’s Lazarus Group, though Upbit and regulatory bodies have withheld official confirmation. This attribution remains distinct from the regulator’s evaluation of platform security protocols, customer safeguards, and crisis response. Concurrently, the FSS concluded another examination concerning Bithumb’s mishandled Bitcoin and internal control mechanisms.
The regulatory body intends to suspend examinations for three weeks starting Monday, resuming operations in mid-August. The review process will proceed before officials communicate any proposed enforcement measures to Dunamu. The company awaits formal deliberations approximately eight months after the security compromise, while the corporate merger remains incomplete.





