The Korea Financial Supervisory Service (FSS) has recently served Dunamu, the operator of Upbit, with an “inspection opinion letter,” formally starting the administrative penalty process. This comes nearly 8 months after the incident and about 7 months after the FSS launched an on-site inspection. The FSS is assessing whether Dunamu violated the “Virtual Asset User Protection Act,” but the law currently does not include direct penalty provisions for hacker attacks or system accidents, leaving the final penalty amount unknown.
From 4:42 a.m. to 5:36 a.m. on November 27, 2025, Upbit was hacked for about 54 minutes. A Solana blockchain network set of assets totaling about 100 billion tokens, valued at 44.5 billion KRW (about $30.4 million), was transferred to an external wallet. On the day of the incident, Dunamu was carrying out merger-related activities with Naver Financial; the company did not announce the hack to the public until after the event ended, drawing criticism for “delayed disclosure.”
In terms of compensation: of the stolen 44.5 billion KRW, 2.6 billion KRW (about $1.78 million) has been frozen and placed into a recovery process. The remaining 38.6 billion KRW (about $26.4 million) of users’ damaged assets was fully compensated by Upbit using its own funds. In December 2025, Upbit launched an on-chain tracking system, the Onchain AI Tracer System, which automatically traces the flow of stolen funds to support subsequent recovery.
An “inspection opinion letter” is the official document the FSS submits to the inspected company after completing its on-site inspection, and it marks the starting point of the administrative penalty process. Once this document is delivered, it signifies that the on-site inspection phase has ended. The subsequent penalty process is as follows:
· Dunamu submits its defense: provides a written explanation of the inspection results
· FSS issues a “sanctions opinion letter”: states the recommended penalty level, with advance notice to the inspected company
· The sanctions review committee makes a decision: the review is conducted by an internal committee within the FSS
· The Securities and Futures Commission makes a decision
· The Financial Services Commission makes a decision
· Final penalty is approved: after the entire process is completed, the penalty decision is formally confirmed
A key variable in this case is that the “Virtual Asset User Protection Act,” which focuses on protecting users and combating unfair transactions, does not set direct penalty provisions for hacker attacks or computer system incidents. As a result, whether Dunamu could face a heavy penalty remains unclear. The FSS chief previously said the case involves “relatively limited sanctioning authority,” but “it’s not the kind of situation where you can simply let it go.”
Korean authorities have planned, under the second phase of legislation—the “Digital Asset Basic Act”—to add provisions for sanctions and compensation related to hackers and system incidents. Industry participants view the outcome of this case as a benchmark for how South Korea regulates exchange hacking incidents.
According to Yonhap News Agency, the FSS has also completed an on-site inspection of Bithumb’s “bitcoin erroneous payout incident.” After the legal review is completed, it will initiate the administrative penalty process in a similar manner. Starting next week, the FSS will enter a three-week inspection suspension period, with inspection work resuming in mid-August.
As background, Dunamu was fined 35.2 billion KRW (about $24.0 million) in November 2025 by South Korea’s financial intelligence unit (FIU) for shortcomings in KYC and anti-money laundering—described as the largest fine in South Korea’s cryptocurrency history. The outcome of this hacking theft case may also affect the subsequent progress of Naver and Dunamu’s $9.9 billion share-swap and acquisition deal.
Under South Korea’s administrative penalty procedure, the next step is for Dunamu to submit a defense regarding the inspection results. After that, the FSS issues a “sanctions opinion letter” specifying the recommended penalty level. Then the matter is decided step by step by the sanctions review committee, the Securities and Futures Commission, and the Financial Services Commission before a final decision is made. As of the time of reporting, the final penalty has not been issued.
The “Virtual Asset User Protection Act” focuses on protecting users and combating unfair transactions, and it does not include direct penalty provisions specifically for hacker attacks or computer system incidents. The FSS chair has previously acknowledged that “sanctioning authority is relatively limited,” and Korean authorities plan to add relevant provisions in the second phase of the “Digital Asset Basic Act.”
The total theft amount was 44.5 billion KRW (about $30.4 million). Of that, 2.6 billion KRW (about $1.78 million) has already been frozen and placed into the recovery process. The remaining 38.6 billion KRW (about $26.4 million) in users’ damaged assets has been fully compensated by Upbit using its own assets, so users did not suffer direct losses.