Upbit Under Fire as Regulators Probe $36M Crypto Security Breach
Regulations

Upbit Under Fire as Regulators Probe $36M Crypto Security Breach

By Samuel

South Korea’s FSS probes Upbit over its $36M Solana hack, scrutinizing disclosure timing and crypto security controls.

Upbit is back in the regulatory spotlight after South Korea’s Financial Supervisory Service moved to open sanctions proceedings against Dunamu, the exchange operator. 

The case stems from a Solana hot-wallet breach that Upbit disclosed last November. A post by That Martini Guy on X pointed to the inspection letter, and local reports later confirmed the regulator had sent Dunamu an opinion notice. 

The move gives the company a formal window to respond before penalties are set. 

FSS Opens Sanctions Review

The FSS said it sent an inspection report to Dunamu after finishing a months-long review of the breach. SBS reported that the regulator first opened its inspection about seven months earlier. 

The review centers on whether Upbit met its duties under South Korea’s Virtual Asset User Protection Act. 

The law covers user protection and unfair trading, but it does not spell out direct penalties for hacks or IT failures. 

That legal gap matters now. The FSS must move through its sanctions process before it can settle on any final punishment, and the decision still runs through several review stages. 

The timing also keeps attention on Upbit’s internal controls. Regulators are looking at how the exchange handled the breach, and how fast it told the public and authorities. 

Upbit Hack Timeline and Losses

Upbit said the breach hit its Solana hot wallet on November 27, 2025. SBS reported that the withdrawals ran for about 54 minutes, from 4:42 a.m. to 5:36 a.m. KST. 

The total loss came to 44.5 billion won, or about $36 million based on Upbit’s disclosure and later coverage. 

The stolen assets were not limited to one token. Reports said the haul included SOL and a mix of Solana ecosystem tokens. 

Upbit also faced criticism over when it disclosed the incident. Local reporting said the exchange announced the hack only after a merger-related event with Naver Financial had ended that same day.

The exchange moved to contain the damage fast. SBS reported that Dunamu froze 2.6 billion won of the affected assets and covered 38.6 billion won in user losses with company funds. 

Read Also:

South Korea Cracks Down on Crypto Whales as BOK Pushes Tokenized Bonds

Legal Gaps Shape the Crypto Regulation Response

This is not Upbit’s first hot-wallet breach. The Block both noted that the exchange also suffered a major hack in 2019. 

That history now sits beside a broader policy push in Seoul. SBS reported that authorities plan to address hacking and IT failure penalties in the Digital Asset Basic Act, which would give regulators clearer sanctioning powers. 

For now, the FSS is still in the response stage. Dunamu can answer the inspection findings before the regulator sets a proposed penalty level, then the case moves through the review committees.

The case puts fresh pressure on crypto exchanges that rely on hot wallets for liquidity. It also shows how fast a security breach can turn into a legal test for crypto compliance in South Korea.

Samuel

About the Author

Samuel

Leave a Reply