We use cookies for analytics and marketing to improve your experience and measure content. You can accept or decline non-essential cookies.
Dunamu, the parent of Upbit, is under a sanction process nearly eight months after a $30 million hack, but South Korea’s crypto law offers no direct penalties for hacking or IT failures, leaving the severity of any sanctions unclear.
The Crypto Frontiers Editorial Desk · Published July 19, 2026 at 9:00 PM UTC · Updated July 19, 2026 at 9:00 PM UTC
The week starting July 20 brings significant developments in U.S. regulatory updates and earnings, alongside the ECB rate decision, which may impact the crypto market.

South Korea’s financial regulator announced that 40 crypto manipulation investigations were conducted in the past two years, underscoring heightened enforcement under the Virtual Asset User Protection Act.
Dunamu, the company that owns the Upbit exchange, is currently navigating a sanction process that began almost eight months after a $30 million cyber‑theft.
In early 2026, Upbit suffered a cyber‑attack that resulted in the loss of approximately $30 million. The incident prompted scrutiny of the exchange’s security practices and raised questions about the accountability of its parent company, Dunamu. The hack’s financial impact and the timing—nearly eight months before the current sanction process began—provide the factual backdrop for the regulatory response.
South Korean authorities have opened a sanction process against Dunamu, reflecting the seriousness with which the government views breaches of crypto‑exchange security. The process was launched almost eight months after the hack, indicating a measured but decisive response. While the exact nature of the sanctions has not been disclosed, the initiation of formal proceedings underscores the regulatory focus on protecting investors and maintaining market integrity.
The core issue highlighted by the source material is that South Korea’s existing crypto law does not contain direct sanction provisions for incidents such as hacking or IT system failures. This legislative omission means that regulators lack a clear statutory basis to impose specific penalties for the Upbit breach. Consequently, the severity of any sanctions that may be levied against Dunamu remains unclear, as authorities must operate within a broader legal context that does not explicitly address cyber‑theft in the crypto sector.
The absence of explicit sanction rules creates uncertainty for both market participants and regulators. Without defined penalties, the authorities may resort to general administrative measures, which could vary in intensity. The outcome of Dunamu’s sanction process will likely influence future regulatory reforms, potentially prompting lawmakers to introduce targeted provisions for hacking and IT failures within the crypto regulatory framework. Stakeholders should monitor any developments closely, as they may signal shifts in how South Korea enforces compliance and protects investors in the digital asset space.
In summary, while Dunamu is under sanction scrutiny following a substantial hack, the lack of specific legal provisions in South Korea’s crypto law leaves the exact consequences ambiguous. The resolution of this case may shape the regulatory landscape for crypto‑related security incidents moving forward.