Lcx
Dunamu Faces Sanctions After $30 Million Upbit Hack Linked to Lazarus Group
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
South Korea's Financial Supervisory Service (FSS) has initiated sanction procedures against Dunamu, the operator of Upbit, following a $30 million hack that occurred on November 27, 2025. The breach involved the theft of approximately 44.5 billion won in Solana-based assets, which were drained to an external wallet over 54 minutes. Dunamu has since frozen 2.6 billion won ($1.7 million) of the stolen funds and compensated affected users using its own reserves. The FSS's investigation, which lasted seven months, is examining potential violations of the Virtual Asset User Protection Act, although current regulations lack specific provisions for sanctions related to hacking incidents. Authorities suspect that the North Korean hacking group, Lazarus, may be behind the attack. The FSS plans to notify Dunamu of the proposed sanctions after a clarification process, with final decisions pending review by multiple financial authorities. This incident marks the second significant breach of Upbit's hot wallet in six years, raising concerns about the exchange's security measures.
Key Points: • Dunamu is facing sanctions after a $30 million hack of Upbit's Solana wallet. • The hack occurred on November 27, 2025, and involved the theft of 44.5 billion won. • Authorities suspect North Korea's Lazarus Group was behind the attack.