TLDR
- South Korea’s FSS sent Donamo a formal inspection opinion letter, starting the process of imposing sanctions over the Upbit hack in November 2025.
- The breach affected Solana-based assets worth approximately $32 million and lasted approximately 54 minutes
- The current law does not include direct penalties for piracy, making the extent of potential penalties unclear
- Upbit compensated affected customers using company funds and repaired its wallet systems
- South Korea plans to fill the legal gap in the next phase of digital asset legislation
South Korea’s financial watchdog has begun the process of imposing formal sanctions against Dunamu, the company behind cryptocurrency exchange Upbit, over the wallet hack that occurred in November 2025.
🚨South Korea launches sanctions measures against UPBIT operator DUNAMU!
South Korea’s financial watchdog has initiated sanctions proceedings against Donamo, the operator of Upbit, over a 44.5 billion won (about $32 million) hacking incident from last year.
the… pic.twitter.com/LRvG1yLBRU
— Crypto Banter (@crypto_banter) July 19, 2026
The FSB sent Dunamo a letter of opinion regarding the inspection, the first official step in the sanctions process. The letter gives Donamo a chance to respond before regulators decide on any sanctions.
Penetration
The attack occurred on November 27, 2025, at 4:42 a.m. local time and lasted approximately 54 minutes. It targeted Solana-based assets owned by Upbit.
Initial reports estimated losses at about $36 million. South Korean authorities now estimate the figure at 44.5 billion won, equivalent to about $32 million at current exchange rates.
Obit It sparked criticism over how long it took for the breach to be made public. The stock exchange only revealed the hack at the end of that day, after the end of a joint event in which Naver Financial had already participated.
After detecting abnormal transfers, Upbit moved assets to cold wallets and stopped deposits and withdrawals. The exchange told clients that it would cover all losses using the company’s funds.
In December 2025, Upbit launched an automated on-chain tracking tool called Onchain AI Tracer System to trace the trail of stolen funds.
Legal gap complicates penalties
The current Virtual Assets User Protection Act does not include direct penalties for hacking or computer system failure. This makes it unclear how far the FSS can go on this issue.
Regulators will review this Donamo Respond before issuing any advance notice of the proposed penalty. Any final action would also require review by the Sanctions Review Committee, the Securities and Futures Commission, and the Financial Services Commission.
South Korean authorities said they plan to add piracy and compensation provisions in the second phase of the Digital Assets Basic Law.
This is not the first time that Donamo has faced regulatory action. The Financial Intelligence Unit previously fined the company 35.2 billion won for anti-money laundering and failure to verify customers. The court later canceled part of that penalty after finding loopholes in the legal basis used.
Dunamu is also in the middle of a planned stock swap with Naver Financial, although that deal has been postponed to December 31 pending regulatory approvals. The current sanctions process does not automatically block the transaction.
The Financial Supervision Authority has not yet announced the proposed level of penalties, and Donamo still has the opportunity to appeal the inspection results before any final decision is made.








