- South Korea’s Financial Supervisory Service sent Dunamu an inspection opinion letter connected to Upbit’s November 2025 hack.
- The letter begins a formal review process and allows Dunamu to respond before regulators propose any penalties.
- Authorities are examining the hack, the timing of Upbit’s disclosure and legal gaps affecting enforcement.
South Korea’s financial regulator has moved the Upbit sanctions case into a formal review following the exchange’s $36 million hack in November 2025. Yonhap News reported that the Financial Supervisory Service sent an inspection opinion letter to Dunamu, the company operating Upbit, allowing it to respond before any proposed penalties are issued. The review covers the security incident, criticism over the timing of the exchange’s public disclosure and possible breaches of the Virtual Asset User Protection Act. However, the case also exposes uncertainty because the law does not clearly establish direct penalties for hacking or computer system failures. The outcome could therefore influence how South Korea handles similar incidents involving major crypto exchanges.
Upbit sanctions process enters formal stage
Yonhap News reported that the Financial Supervisory Service recently delivered an inspection opinion letter to Dunamu in connection with the November 2025 Upbit hack. The incident reportedly caused losses of about $36 million. By sending the letter, the regulator formally opened a process that could eventually lead to Upbit sanctions if authorities conclude that the exchange breached applicable obligations.
The letter does not represent a final penalty decision. Instead, it gives Dunamu an opportunity to review the regulator’s findings and submit a response before authorities issue any proposed sanctions. Cointelegraph said it contacted the company for comment, although the report did not include a response. The next stage will depend on how regulators assess Dunamu’s explanation and the legal basis available for enforcement.
Delayed disclosure draws regulatory attention
The timing of Upbit’s public disclosure has become an important part of the review. According to Yonhap, the breach began at 4:42 a.m. Korea Standard Time on Nov. 27 and continued for approximately 54 minutes. Despite the early-morning incident, the exchange reportedly did not announce the exploit publicly until near the end of the same day.
The report also said the announcement came after a merger-related event involving Naver Financial had concluded. That sequence has led to criticism that the exchange waited too long before informing the public. Regulators are therefore examining not only the technical cause and financial impact of the hack, but also whether Upbit handled the disclosure process appropriately and communicated the incident without unnecessary delay.
Legal gap could shape Upbit sanctions outcome
South Korean authorities are reviewing whether the exchange violated the Virtual Asset User Protection Act. However, the source report noted that the law does not contain clear provisions imposing direct sanctions for cyberattacks, hacking incidents or computer system failures. This creates uncertainty over which penalties, if any, regulators can apply specifically because of the security breach.
That gap may significantly influence the final Upbit sanctions outcome. Authorities reportedly plan to address the issue during the second phase of the Digital Asset Basic Act by introducing clearer sanctions and compensation provisions for hacking and system failures. The case may therefore become an example of the limits of the current framework while also supporting future legislation designed to define exchange responsibilities more precisely.
Upbit response includes reimbursements and wallet changes
After the November exploit, Upbit said it froze approximately 2.3 billion won, equivalent to about $1.5 million, connected to the stolen funds. The exchange also promised to reimburse affected customers fully using assets from its own balance sheet. Those measures were intended to limit customer losses while the company investigated the breach and traced the movement of the remaining funds.
Upbit also said it began restructuring its crypto wallet architecture to address potential vulnerabilities and transferred all assets away from the affected wallets. In December 2025, the company announced an automated onchain tracking service called the Onchain AI Tracer System. The tool was developed to follow stolen assets across blockchain networks and support efforts to identify, freeze or potentially recover funds linked to the hack.
Market position raises stakes of Upbit sanctions case
The review carries broader significance because Upbit is one of the largest crypto exchanges covered by the source reports. CoinMarketCap ranked the platform third among spot exchanges using factors such as traffic, liquidity and trading volume. A regulatory decision involving an exchange of that size could attract attention from customers, competitors and other virtual asset service providers operating in South Korea.
The case may also show how regulators respond when a major exchange suffers a serious security failure but the existing law does not clearly define direct penalties for the incident. Any Upbit sanctions decision could help establish expectations for disclosure, customer protection and technical controls, even if lawmakers still need to create more explicit rules for future hacks and computer system failures.
Conclusion
The inspection opinion letter has moved the Upbit sanctions case into a formal stage and gives Dunamu an opportunity to answer the regulator’s findings before any penalties are proposed. The review focuses on the November 2025 hack, the reported delay in disclosure and possible issues under the Virtual Asset User Protection Act. Upbit has highlighted its customer reimbursement plan, frozen funds, wallet restructuring and onchain tracking system as part of its response. At the same time, the lack of direct legal provisions for hacking incidents may limit or complicate the regulator’s options. The case could ultimately influence both the enforcement approach used now and the clearer sanctions framework South Korea plans to develop for future crypto security incidents.
Disclaimer
The information provided in this article is for informational purposes only and should not be considered financial advice. The article does not offer sufficient information to make investment decisions, nor does it constitute an offer, recommendation, or solicitation to buy or sell any financial instrument. The content is opinion of the author and does not reflect any view or suggestion or any kind of advise from CryptoNewsBytes.com. The author declares he does not hold any of the above mentioned tokens or received any incentive from any company.
Featured image created by AI

