Upbit parent Dunamu faces sanction process nearly eight months after $30 million hack: report

概要:South Korea's Financial Supervisory Service has initiated sanction procedures against Dunamu, Upbit's operator, over a $30 million hack last November, sending an inspection report that marks the first formal step. While Dunamu covered most customer losses and froze some stolen funds, the scope of potential sanctions remains uncertain because the current Virtual Asset User Protection Act lacks direct provisions for punishing exchanges over hacks or IT failures. Regulators plan to address this gap in a future Digital Asset Basic Act. The FSS is also concluding a separate inspection of rival exchange Bithumb over a misallocated bitcoin incident.

Quick Take

  • The Financial Supervisory Service sent an inspection report to Dunamu over the 44.5 billion won ($30 million) hack of Upbit last November, the first formal step in the regulators sanction process, according to local broadcaster SBS.
  • The severity of any sanctions remains unclear because South Koreas current crypto law contains no direct sanction provisions for hacking or IT failures.

South Korea's Financial Supervisory Service has begun sanction procedures against Dunamu, the operator of crypto exchange Upbit, over the roughly $30 million hack the platform suffered last November, local broadcaster SBS reported Sunday.

The FSS recently sent Dunamu an inspection report covering the incident, according to the report, which cited financial authorities and industry sources. The step comes about seven months after the regulator opened its inspection of the exchange.

Upbit, South Korea's largest crypto exchange by trading volume, was hacked for 44.5 billion won (about $30 million) in Solana-based assets on Nov. 27 last year. The funds were drained to an external wallet over roughly 54 minutes starting at 4:42 a.m. local time, per SBS.

Dunamu covered the 38.6 billion won ($26 million) in affected customer assets using Upbit's own reserves. The company has frozen 2.6 billion won ($1.7 million) of the stolen funds and is working to recover them, SBS reported, up from the 2.3 billion won Upbit said it had frozen in the days after the breach.

The exchange drew criticism at the time for its disclosure timing, as it announced the hack only after a merger event with Naver Financial held the same day had concluded, according to SBS. Dunamu's stock-swap merger with the Naver fintech arm is still pending and was pushed back to Dec. 31 earlier this month, meaning the sanction process will play out while the deal awaits completion.

The FSS has reportedly been examining whether the incident involved violations of the Virtual Asset User Protection Act. The law focuses on user protection and unfair trading, however, and contains no direct provisions for sanctioning exchanges over hacks or IT failures, leaving the scope of any sanctions uncertain.

Authorities plan to address that gap in the Digital Asset Basic Act, the second phase of South Korea's crypto legislation, by adding rules on sanctions and compensation for hacking and IT incidents, per SBS.

Lee Chan-jin, governor of the Financial Supervisory Service, said at a Dec. 1 press conference that sanctions under the Virtual Asset User Protection Act have limits, but that the hack was not something the regulator could simply pass over.

The FSS plans to notify Dunamu of its proposed sanction level after a clarification process. Final sanctions or penalties will be decided through deliberations by the regulator's Sanctions Review Committee, the Securities and Futures Commission and the Financial Services Commission.

South Korean authorities have suspected North Korea's Lazarus Group of being behind the theft, The Block previously reported, though neither Upbit nor regulators have publicly confirmed attribution.

The FSS has also concluded a separate inspection of rival exchange Bithumb over an incident involving misallocated bitcoin and plans to begin sanction procedures there once legal reviews wrap up, per SBS. That probe had examined Bithumb's internal controls and risk management.

The regulator will pause inspections for three weeks starting Monday and resume in mid-August, according to the report.

免責事項

このコンテンツの見解は筆者個人的な見解を示すものに過ぎず、当社の投資アドバイスではありません。当サイトは、記事情報の正確性、完全性、適時性を保証するものではなく、情報の使用または関連コンテンツにより生じた、いかなる損失に対しても責任は負いません。
前へ

「暗号資産の送金ミス」を終わらせる?ムーンペイが大型買収 “橋渡し不要”でウォレット入金が激変へ

次へ

テザーが南米を“札束攻勢”で攻略へ アルゼンチンのネット銀行ウアラに約32億円投資

規制中5-10年間 7.59規制中5-10年間 8.15