July 19, 2026 ChainGPT

FSS Opens Sanctions Probe Against Dunamu After Upbit Solana Hack; Legal Gaps Cloud Enforcement

FSS Opens Sanctions Probe Against Dunamu After Upbit Solana Hack; Legal Gaps Cloud Enforcement
Headline: South Korea’s FSS opens formal sanctions process against Dunamu after Upbit Solana hack — legal gaps complicate enforcement South Korea’s Financial Supervisory Service (FSS) has launched a formal sanctions process against Dunamu, the operator of crypto exchange Upbit, following the major wallet breach reported on November 27, 2025. The move caps a months-long inspection into whether Upbit met its obligations under the country’s Virtual Asset User Protection Act. What happened - The November attack targeted Solana-based assets on Upbit. Early industry estimates put losses near $36 million; South Korean authorities now quantify the damage at 44.5 billion won (about $32 million at current exchange rates). - Upbit says it immediately moved remaining assets to cold wallets, suspended deposits and withdrawals, traced the stolen funds, and pledged to cover customer losses from company funds. - Regulators have since probed both the technical security failure and the timing and completeness of Upbit’s public disclosure. Regulatory action and legal uncertainty - The FSS sent Dunamu an inspection opinion letter — a formal step that gives the company an opportunity to respond before any penalties are proposed. Any proposed measures would then move through multiple review stages, including the sanctions review committee, the Securities and Futures Commission and the Financial Services Commission. - A complicating factor: South Korea’s current Virtual Asset User Protection Act empowers regulators on custody, unfair trading and customer protection, but it does not impose direct penalties specifically for hacks or computer system failures. That gap creates uncertainty about how far the FSS can go in sanctioning Dunamu under existing law. - Authorities are weighing Dunamu’s reply and considering tougher, more explicit rules for hacking and technology failures in the next phase of digital-asset legislation. Context: prior enforcement and legal scrutiny - The inspection comes amid sustained regulatory attention on Dunamu. Earlier this year the Financial Intelligence Unit fined the company 35.2 billion won for alleged anti-money-laundering and customer verification shortcomings. - That earlier enforcement drew court scrutiny: a court later canceled a three-month partial suspension after finding weaknesses in the legal basis for the sanction — illustrating how current legal gaps can blunt enforcement. Business impact and next steps - The sanctions process does not automatically block Dunamu’s ongoing corporate plans. The company is proceeding with a planned share swap with Naver Financial that was pushed to December 31 because some regulatory approvals remain outstanding. - The FSS has not disclosed any proposed sanction level in the hacking case. Dunamu still has the opportunity to contest the inspection findings before regulators reach a final decision. Why it matters This case could become a pivotal test of how South Korea’s current legal framework applies to crypto exchange failures — and it may accelerate legislative efforts to give regulators clearer powers to penalize hacks and system breakdowns. For exchanges operating in South Korea, the outcome will signal how aggressively authorities can act under today’s rules and what protections — and liabilities — new laws might introduce. Read more AI-generated news on: undefined/news