Seoul's crypto cop is closing the loophole it never wrote
Two years into the Virtual Asset User Protection Act, South Korea's financial regulator has opened 40 manipulation cases and is moving against Dunamu, but the law still does not name the offence at the centre of the threat it was built to stop.

On 19 July 2026, South Korea's Financial Services Commission (FSC) began formal sanctions proceedings against Dunamu, operator of the country's largest crypto exchange Upbit. The move comes two days after FSC Chair Lee Eog-won published a figure on the second anniversary of the Virtual Asset User Protection Act that, on its face, reads as a reassuring enforcement tally: 40 cases of suspected market manipulation opened in two years. Read against the same week's Dunamu action, the number looks more like a confession of latency.
The two facts travel together because they expose a structural gap at the heart of Seoul's crypto rulebook. The Virtual Asset User Protection Act, in force since July 2024, gave the FSC new powers over insider trading, price manipulation, and unfair trading practices on registered virtual asset venues. It did not, however, write a sanctions clause specific to hacking or to computer-system intrusion, the offences behind several of the most damaging breaches South Korean retail users have endured. The regulator is now moving against a domestic heavyweight anyway, on what authorities describe as a case-by-case application of existing unfair-trading and information-system provisions. Whether that will hold up is the open question underneath the headline.
Forty cases, two years, one loophole
Lee's anniversary disclosure, reported on 20 July, frames the 40 manipulation investigations as evidence that the 2024 act is working. Forty is a small number against the volume of trading Upbit alone clears daily, and small against the size of the South Korean retail crypto market, which has historically ranked among the most active per capita in the world. The figure is also a clean signal of regulatory intent: the FSC is willing to publish a tally, which is itself a constraint on the political space for turning a blind eye.
The gap sits one level down. Domestic reporting cited by Cointelegraph notes that the Virtual Asset User Protection Act lacks an explicit sanctions article tied to hacking and computer-system incidents. The drafting choice matters because South Korea's worst crypto retail losses of recent years have been thefts, not front-running. When the principal harm is the loss of customer assets to an external intruder, the regulator must reach for whichever clause in the existing toolkit is closest, and argue from there. That is what the Dunamu action appears to do.
The Dunamu proceeding, and what is actually being charged
Dunamu runs Upbit, the venue through which a large share of Korean won-denominated crypto trades clear. A formal sanctions process against the operator is the heaviest administrative move the FSC has launched under the 2024 framework to date, and the optics matter: it puts the dominant platform on notice that the anniversary statistics are not just a press release.
The unresolved piece, on the evidence available, is the legal hook. If the proceeding rests on the unfair-trading provisions of the 2024 act, it implies that the conduct under examination is being framed as a market-integrity failure rather than a system-security failure. If it draws on broader information-system or financial-services statutes, the 2024 act is being used as the venue for a case that older law is doing the work in. Korean coverage frames the sanctions process as deliberate but legally uncertain, which is the read this publication finds most consistent with the public record. Two years of enforcement have produced a count of manipulation cases; the more dangerous category of incident, computer intrusion, is still being prosecuted through whatever fits.
A market that scaled faster than its rulebook
The structural frame is straightforward. South Korea's retail crypto market grew through the 2017–2021 cycle on the back of a domestic exchange oligopoly, aggressive app-driven onboarding, and a won-rail that made it easy to move from bank balance to exchange in minutes. That growth outran two distinct regulatory projects: a licensing and supervisory regime for exchanges, and a consumer-protection statute that names offences and attaches penalties. The Virtual Asset User Protection Act, two years in, has delivered on the first project more visibly than on the second. Insider-trading and manipulation cases are tractable: they require evidence of intent, sequence, and price impact, all of which exchanges generate as a byproduct of running order books. Hacks and security failures require a different evidentiary chain, centred on system architecture, key management, and incident response, and the statute has not been amended to build that chain explicitly.
The countervailing view, heard in Seoul industry circles, is that retro-fitting existing unfair-trading provisions is a feature, not a bug: it lets the regulator act without waiting for a parliamentary cycle and signals that no category of harm is off-limits. The structural objection is that signal is not substitute. An enforcement record built on the closest-fit clause is easier to challenge, and a challenge that succeeds sets the rulebook back further than a slow amendment would have.
Stakes for users, exchanges, and the next amendment cycle
For retail users, the immediate question is whether assets held on Upbit and on the smaller domestic venues will be subject to a recovery framework that is actually written down. The FSC's recent public posture suggests yes, in principle; the statute, on present reading, is silent on the operational details. For exchanges, the Dunamu proceeding is the first credible test of how far Seoul will stretch the 2024 act when a large domestic player is in the dock. A successful action on the unfair-trading hook narrows the universe of acceptable conduct but leaves the security-incident question open. A failed action resets the agenda.
For the next parliamentary cycle, the most likely outcome is a targeted amendment that adds a computer-intrusion article with named penalties, sitting alongside the manipulation and insider-trading provisions already in force. The anniversary disclosure is, in that reading, a political precondition: the regulator has now put a number on its record, and the case against Dunamu gives it a stage on which to argue that the number, while respectable, is incomplete. The Korean crypto market will, in the meantime, continue to operate inside a rulebook that names every form of trading misconduct it prosecutes, except the one most likely to cost a user their balance.
What the public record does not yet resolve is the specific conduct at issue in the Dunamu proceeding, the timetable for a decision, and whether the FSC will publish the legal basis of its action in detail. Those gaps are worth watching: a regulator that has to explain which clause it used is a regulator that is also telling the next legislature exactly where to write.
*Desk note: Monexus is treating the Cointelegraph wires on the FSC's 40-case tally and the Dunamu sanctions process as the anchor for this read. The structural critique, that the 2024 act is well-tooled for manipulation cases and under-tooled for security incidents, is drawn from the gap those two facts jointly expose, not from any single named source.