South Korea Opens Dunamu Sanction Process Over Upbit Breach

BTCC


Set as Google Preferred SourceFollow on Google News

TLDR

  • South Korea’s FSS has started sanction procedures against Dunamu over Upbit’s $30 million hack.
  • The regulator sent Dunamu an inspection report nearly eight months after the November 27 breach.
  • Hackers transferred 44.5 billion won in Solana-based assets to an external wallet within 54 minutes.
  • Upbit used its reserves to repay 38.6 billion won in affected customer assets.
  • The exchange has frozen 2.6 billion won of the stolen funds and continues recovery efforts.

Upbit parent Dunamu faces a regulatory sanction process nearly eight months after a $30 million cryptocurrency theft, SBS reported Sunday. South Korea’s Financial Supervisory Service recently delivered an inspection report covering the November breach and the exchange’s response. The action moves Dunamu toward formal penalties, although existing law may limit the regulator’s available measures.

Regulator advances review after lengthy inspection

The FSS opened its inspection after hackers removed 44.5 billion won in Solana-based assets from Upbit on November 27. According to SBS, the transfers continued for about 54 minutes and sent the assets to an external wallet. Dunamu received the inspection findings about seven months after regulators began examining the incident.

The exchange reimbursed 38.6 billion won in affected customer assets from its own reserves after identifying the losses. It has also frozen 2.6 billion won of the stolen funds and continues efforts to recover additional assets. Dunamu had initially reported freezing 2.3 billion won shortly after the security breach.

Regulators also reviewed the timing of Upbit’s public disclosure and its handling of information during the incident. The exchange announced the breach after a merger event with Naver Financial had ended on the same day. Dunamu continues pursuing that stock-swap transaction, although the parties recently delayed completion until December 31.

Existing law could restrict possible penalties

The FSS examined whether the breach involved violations of South Korea’s Virtual Asset User Protection Act. However, the law mainly addresses customer safeguards and unfair trading rather than hacking or technology failures. That legal gap could narrow the sanctions available against Dunamu under the current framework.

Authorities plan to address such incidents through the proposed Digital Asset Basic Act, which forms the next legislative phase. The planned law would add clearer rules covering sanctions and compensation after hacks and major information technology failures. Until lawmakers approve those provisions, regulators must work within the narrower existing statute.

FSS Governor Lee Chan-jin acknowledged those limits during a December 1 press conference about the breach. He said sanctions under the current law have limits, but regulators could not simply pass over the incident. The FSS will allow Dunamu to submit explanations before setting its proposed sanction level.


Zuna


Final decision will follow regulatory deliberations

Several regulatory bodies will review the proposed action before South Korean authorities issue any final penalty. The Sanctions Review Committee will consider the case, followed by the Securities and Futures Commission and Financial Services Commission. Dunamu could face administrative measures, but SBS did not report the likely scope or timing.

Authorities have suspected North Korea’s Lazarus Group, although Upbit and regulators have not publicly confirmed responsibility. The attribution remains separate from the regulator’s examination of exchange controls, customer protection, and incident management. Meanwhile, the FSS completed another inspection involving Bithumb’s misallocated Bitcoin and its internal risk procedures.

The regulator plans to pause inspections for three weeks from Monday and resume activity in mid-August. The clarification process will continue before authorities notify Dunamu of any proposed sanction or penalty. Dunamu now awaits formal deliberations nearly eight months after the hack, while the merger remains unfinished.



Source link

Bybit

Be the first to comment

Leave a Reply

Your email address will not be published.


*