South Korea's financial regulator has drafted a bill that would fine hacked crypto exchanges up to 10 percent of the assets stolen in a breach, a sharp escalation from the current penalty ceiling. The draft, drawn up by the Financial Services Commission and first reported by the South Korean newspaper Seoul Kyungjae, would reshape South Korea crypto exchange fines by tying penalties directly to customer losses, according to DL News.
The push for tougher South Korea crypto exchange fines signals that Seoul is no longer satisfied with the existing rules, under which the maximum fine an exchange can face is $456,000. The regulator's concern, as described in coverage of the draft, is that the cybersecurity and liability laws governing exchanges are too lax for platforms holding billions in investor assets. Upbit, the country's dominant exchange, suffered a breach worth $36 million in late November of last year. Had the draft rules been in force at the time, the exchange would have faced a fine of up to $3.6 million, roughly eight times the current maximum.
What the draft bill would change
The draft keeps the structure of existing enforcement but raises the ceiling dramatically. Instead of a fixed dollar cap, the penalty would scale with the size of the breach, meaning the largest hacks would draw the largest fines. The Financial Services Commission has argued that exchanges need security systems on par with those used by traditional financial institutions, and a fine tied to losses would give platforms a direct financial reason to invest in protection before an incident rather than absorb a small penalty afterward.
Independent security experts in Seoul have echoed that assessment. Gina Kim, an IT security specialist, told DL News that exchange security has improved in recent years but still falls short of industry gold standards. Her view reflects a broader worry among regulators that crypto platforms, while handling sums comparable to midsize banks, operate under lighter technical requirements than the banking sector does.
The proposal stops short of some of the tougher measures circulating in the country's policy debate. The draft would raise fines into the millions of dollars, but it is not the only plan on the table, and a rival proposal would go considerably further.
A competing proposal would go further
Days after the Upbit breach, the South Korean news agency Yonhap reported that regulators and National Assembly members were weighing a separate proposal: fining hacked exchanges up to 3 percent of their annual revenue. For Upbit, which reported revenue of $1.2 billion in 2024, that formula would have produced a fine of about $36 million, roughly ten times what the Financial Services Commission's draft would allow.
The two proposals could end up clashing if both advance, since they rest on different ideas of what a penalty should punish. The commission's draft ties the fine to the harm suffered by customers in a specific incident, while the revenue-based proposal would scale the penalty to the size of the business regardless of how much was stolen. Neither proposal is law yet, and both would push South Korea crypto exchange fines far above the current cap. The leaked status of the commission's draft suggests the details are still being negotiated behind closed doors.
The urgency behind both plans is visible in the numbers. Data from the Financial Supervisory Service showed 20 security incidents involving customer funds across Upbit, Bithumb, Coinone, Korbit, and GOPAX from January 2023 through September 2025. Six of those incidents took place at Upbit, affecting 616 people and producing losses of $2.2 million. Four occurred at Bithumb, where 326 customers were affected and losses topped $610,000.
Why regulators are acting now
The pattern those figures describe is one reason Seoul is moving beyond incremental enforcement. A single large breach now captures headlines, but the regulator's data shows a steady drumbeat of smaller incidents at the country's biggest platforms over nearly three years. Each one eroded customer funds while the maximum penalty stayed fixed at a level that large exchanges can absorb as a cost of doing business.
The commission's push also fits a wider run of crypto regulation news, from Europe's embrace of privacy-coin investment products to a five-year stablecoin push in the United States. Japan tightened exchange oversight after major hacks, and several jurisdictions have moved exchanges into bank-style supervisory frameworks. South Korea's proposal follows that logic, using the threat of scaled fines to force platforms to spend on security before a breach rather than pay a modest penalty after one.
Whether the draft survives in its current form will depend on the National Assembly, which will have to reconcile it with the competing revenue-based proposal and with industry lobbying. Neither Upbit nor Bithumb responded immediately to a DL News request for comment on the commission's plans, leaving the industry's formal position unclear. The era of small South Korea crypto exchange fines is drawing to a close, and platforms operating in the country will soon face fines measured in a share of what their customers lose.
Source: DL News
Comments 0
No comments yet. Be the first to share your thoughts!
Leave a comment
Share your thoughts. Your email will not be published.