South Korea's Virtual Asset User Protection Act has moved well beyond its launch phase.
The law took effect on July 19, 2024 and added a dedicated user-protection and market-conduct layer on top of the country's earlier virtual asset service provider registration and anti-money-laundering framework.
Its core protections are concrete.
Customer cash deposits must be managed separately through banks. Virtual asset service providers must actually hold the types and quantities of crypto entrusted by users. At least 80% of the economic value of customer virtual assets must be maintained in cold storage. Providers also need insurance, mutual-aid arrangements or reserves for specified incidents such as hacking and system failures.
The law also created a much stronger market-abuse regime covering conduct such as insider dealing, price manipulation and fraudulent transactions.
By July 2026, those provisions were no longer theoretical. Korean financial authorities reported that they had completed investigations into more than 40 suspected unfair-trading cases since the law took effect and had referred or reported more than 30 cases to investigative authorities.
That enforcement record makes the 2026 question different from the one investors asked in 2024.
It is no longer:
Will South Korea enforce the User Protection Act?
It is:
How do the custody rules work in practice, what does the 80% cold-storage requirement actually mean, and what protections do users have when trading activity or withdrawals become abnormal?
The User Protection Act is not South Korea's entire crypto framework
South Korea's crypto regulation has several layers.
The User Protection Act is one of them.
A simplified map looks like this:
| Regulatory layer | Main purpose |
|---|---|
| VASP registration under the Specified Financial Transaction Information Act | AML/CFT, customer identification and provider registration |
| Real-name banking requirements | KRW-market access and customer identification |
| Virtual Asset User Protection Act | Customer assets, custody, incident protection and unfair trading |
| Travel Rule / AML rules | Information and controls for virtual asset transfers |
| Future second-phase legislation | Broader issuer, stablecoin, exchange and market-structure rules still under development |
This distinction matters because a provider can satisfy one regulatory requirement without every other question being answered.
For example:
VASP registration
does not mean:
every listed token is approved as an investment.
Likewise:
compliance with the User Protection Act
does not mean:
the exchange cannot fail.
Each layer regulates a different problem.
Why South Korea needed a separate user-protection law
South Korea already had a VASP registration system before the User Protection Act.
The earlier framework was centered heavily on:
- anti-money laundering;
- customer identification;
- suspicious transaction controls;
- registration of virtual asset service providers.
Those rules help answer questions such as:
Who is using the service?
and:
Where did the money come from?
They do not fully answer:
Where are customer assets held?
What happens if the exchange is hacked?
What happens if someone manipulates the market?
What records must be preserved?
The Virtual Asset User Protection Act was designed to address those gaps.
Its two most important pillars are:
- protection of customer money and virtual assets;
- prevention and enforcement of unfair trading.
- insider misconduct;
- poor key management;
- recovery failures;
- inaccurate internal records;
- operational mistakes;
- legal disputes;
- market losses.
- the cause of loss;
- policy terms;
- reserve amount;
- responsibility of the provider;
- the type of incident.
- a user sending crypto to a scam address;
- a token collapsing in price;
- a separate DeFi protocol failure;
- loss caused by the user's compromised personal wallet.
- insolvency;
- account disputes;
- investigations;
- reconciliation failures.
- blockchain maintenance;
- security incidents;
- unusual transaction review;
- network upgrades;
- legal or compliance requirements.
- misuse of material non-public information;
- price manipulation;
- fraudulent trading activity.
- trading patterns;
- order placement;
- related accounts;
- fund flows;
- public statements;
- issuer relationships;
- cross-exchange activity.
- price changes abnormally;
- trading volume changes abnormally;
- news or rumors likely to affect price appear;
- suspicious order patterns occur.
- completed investigations into more than 40 cases;
- referred or reported more than 30 cases to investigative authorities;
- identified 25 suspects across the referred cases;
- found average illicit gains of roughly KRW 1.4 billion per case.
- concentrated high-frequency orders;
- false or non-genuine orders;
- pump-and-dump behavior;
- use of API keys;
- issuer-linked activity;
- coordinated trading with overseas exchanges;
- false information distributed through social media.
- investigation;
- referral;
- administrative sanctions;
- financial penalties.
- rapid manipulation;
- abnormal order groups;
- suspicious trading intervals.
- genuine demand;
- low liquidity;
- a listing announcement;
- project news;
- speculation.
- falls sharply;
- receives an investment warning;
- loses liquidity;
- is delisted.
- FSC recommends the token;
- FSS guarantees the token;
- the project is free of fraud;
- liquidity will remain available.
- transaction support;
- warning designations;
- delisting practices;
- common user-protection standards.
- customer assets;
- provider conduct;
- unfair trading.
- issuer licensing;
- reserve composition;
- redemption rights;
- issuance limits.
- stablecoin regulation;
- stronger exchange internal controls;
- liability for operational failures;
- broader market structure.
- enhanced VASP registration review;
- stronger customer due diligence;
- risk-based treatment of transfers involving overseas VASPs and private wallets;
- additional reporting requirements for certain large transfers.
- overseas VASPs;
- digital wallet service providers;
- private wallets.
- high-risk customers;
- high-risk products;
- high-risk services.
- wallet ownership;
- destination;
- transaction purpose;
- source of funds.
- seed phrase;
- private key.
- bank-managed customer deposits;
- segregation of customer crypto;
- actual asset-holding requirements;
- 80% cold storage;
- insurance or reserve arrangements;
- market surveillance.
- business losses;
- cyber incidents;
- internal fraud;
- operational mistakes;
- legal disputes;
- liquidity problems.
- market loss;
- operational restriction;
- compliance review;
- possible misconduct.
- blockchain network maintenance;
- exchange wallet maintenance;
- AML review;
- fraud detection;
- Travel Rule verification;
- security incident.
- when it began;
- the stated reason;
- the expected end date;
- whether trading remains open.
- custody controls;
- reconciliation;
- transaction controls;
- internal approval processes.
- fiat deposits;
- withdrawals;
- customer eligibility.
- customer cash;
- crypto segregation;
- cold-wallet controls;
- incident insurance or reserves.
- blockchain network;
- deposit status;
- withdrawal status;
- delisting notices.
- segregating customer assets;
- calculating cold-wallet ratios;
- monitoring hot-wallet exposure;
- maintaining insurance or reserves;
- reconciling customer assets;
- monitoring abnormal trading;
- reporting suspicious market conduct.
- stablecoin issuance;
- token issuance;
- exchange internal controls;
- business conduct;
- disclosure;
- market structure.
- FSC — Virtual Asset User Protection Act commencement
- FSC — Final supervisory regulation
- FSC — Implementation Q&A for the Act
- FSC — Framework and enforcement decree explanation
- FSC — Legislative objectives of the Virtual Asset User Protection Act
- FSC — Two-year unfair-trading enforcement review, July 2026
- FSC — 2026 Virtual Asset Committee and Phase 2 policy discussion
- FSC — Clarification that Phase 2 stablecoin details were not finalized
- FSC — 2026 AML / Travel Rule reform
- FSC — August 2026 revised Specified Financial Transaction Information Act enforcement rules
The law took effect on July 19, 2024
The timeline is straightforward:
| Date | Development |
|---|---|
| March 2021 | VASP registration framework introduced under the earlier financial-information regime |
| July 18, 2023 | Virtual Asset User Protection Act enacted |
| July 19, 2024 | Act and major implementing rules took effect |
| 2025–2026 | Investigations, inspections and enforcement expanded |
| July 2026 | FSC published a two-year unfair-trading enforcement review |
| 2026 | Government continued work on separate second-phase digital asset legislation |
The July 2023 enactment date should not be confused with the July 2024 commencement date.
And the continuing discussion of “Phase 2” legislation should not be interpreted as evidence that the User Protection Act is still pending.
The first-stage user-protection framework is already in force.
Customer cash and customer crypto are protected differently
The Act distinguishes customer money from customer virtual assets.
That is important because the risks are different.
Customer cash deposits
Money deposited by users in connection with virtual asset trading must be managed through a designated custodian institution.
The implementing framework designates banks for this role.
Customer deposits must be segregated from the exchange's own money.
The bank may manage those deposits only through relatively safe assets permitted under the framework, including specified government-backed instruments.
Customer virtual assets
The exchange must also separate customer virtual assets from its own assets.
More importantly, it must actually hold the corresponding types and quantities of virtual assets entrusted by users.
This is a stronger requirement than simply displaying an account balance on an internal database.
The regulatory principle is:
The exchange's records should correspond to real customer assets.
What happens to customer cash if the exchange fails?
The deposit-protection structure has a particularly useful feature.
If a VASP becomes bankrupt or its registration is cancelled, the bank holding customer deposits can return the relevant money directly to users after completing the required notice and verification procedures.
This means customer cash is not intended to be treated simply as ordinary operating money of the exchange.
That does not make the exchange equivalent to a bank.
It means the user-deposit structure is designed to preserve a clearer path for returning customer money if the VASP itself fails.
Users receive deposit-use fees on customer cash
The framework also requires VASPs to pay users a deposit-use fee based on the return generated from customer deposits after relevant costs.
This should not be confused with crypto staking or stablecoin yield.
The underlying object is customer money deposited with the exchange, not BTC, ETH or another virtual asset balance.
A useful distinction is:
KRW deposit-use payment
versus:
crypto investment return
They arise from different legal and economic relationships.
An exchange paying a user a return on safeguarded KRW deposits is not promising yield on every cryptoasset held in the same account.
The 80% cold-storage rule is based on economic value
One of South Korea's most visible crypto safeguards is the cold-storage requirement.
VASPs must keep at least:
80% of the economic value of customer virtual assets
in cold wallets.
The rule is not based simply on the number of coins.
It uses an economic-value calculation.
For each type of virtual asset, the provider considers:
quantity held × applicable KRW valuation
and aggregates the result across customer assets.
The regulatory calculation uses historical KRW conversion data under the supervisory rules.
That matters because 80% of the number of wallet addresses would be meaningless.
The requirement is designed around the economic value of customer holdings.
The 80% ratio must be maintained continuously
The rule is not only checked once each month.
FSC implementation guidance says the required cold-wallet ratio needs to be maintained on an ongoing basis, supported by internal controls and daily monitoring.
The calculation uses the provider's current holdings and the prescribed valuation methodology.
That means an exchange cannot satisfy the rule by moving assets offline only on the day before an inspection and then returning most of them to hot wallets immediately afterward.
The framework expects the storage ratio to be continuously maintained.
80% cold storage does not mean only 20% can be lost
This is an important misconception.
The rule does not mean:
“Only 20% of customer assets are exposed to risk.”
Cold storage reduces specific online attack risks.
It does not eliminate:
A cold wallet can also be compromised if key-management procedures fail.
The 80% requirement is therefore one layer of risk control.
It is not a mathematical maximum-loss guarantee.
Hot-wallet assets create additional protection requirements
The remaining portion of customer crypto can be held in online environments to support normal deposits, withdrawals and trading operations.
Because hot wallets have greater exposure to online attacks, the supervisory framework also requires VASPs to maintain insurance, mutual-aid coverage or reserves for specified incidents.
The baseline calculation is tied to the economic value of customer virtual assets not held in cold storage.
FSC guidance describes the required amount as at least 5% of the relevant hot-wallet economic value, subject to minimum amounts defined by provider type.
The requirement is recalculated periodically, and providers must increase insurance limits or reserves when necessary.
This creates a layered structure:
Cold storage requirement
plus
incident-loss protection for the online portion.
Insurance and reserves are not unlimited compensation
The existence of an insurance policy or reserve fund can easily be overstated.
It does not mean:
Every customer loss will always be reimbursed in full.
Coverage depends on factors such as:
A hacking incident affecting the exchange's systems is different from:
Users should therefore ask:
What event does the protection cover?
rather than only:
Does the exchange have insurance?
Exchanges must maintain customer asset records
South Korea's framework requires providers to maintain records that allow customer virtual asset holdings and transaction history to be verified.
The law also requires long-term retention of relevant virtual asset transaction records.
This matters during:
Blockchain records can show that a wallet transaction occurred.
They do not automatically show which customer was entitled to which portion of an omnibus exchange wallet.
The provider's internal records remain critical.
Withdrawal suspensions are also regulated
The Act addresses situations in which deposits or withdrawals are blocked.
FSC guidance says users should generally receive prior notice explaining the reason and expected period of a restriction.
The exact method can depend on the circumstances, and limited exceptions can apply.
This is important because not every withdrawal suspension is evidence of insolvency.
A restriction can result from:
But the exchange should still have a defined basis and communication process.
For users, preserving the notice is valuable evidence.
South Korea's framework also targets market manipulation
The second major pillar of the Act is market conduct.
The law prohibits unfair trading including:
VASPs are also required to monitor for abnormal trading.
The regulatory focus extends beyond isolated suspicious orders.
Authorities can examine:
This is particularly important in crypto markets, where prices can move rapidly on relatively small markets.
Exchanges must monitor abnormal trading
Korean exchanges maintain systems for continuous monitoring of abnormal transactions.
Examples can include situations where:
When activity appears connected with possible unfair trading, the exchange can be required to review it and report relevant suspicions to the authorities.
This changes the exchange's role.
A regulated exchange is not only matching buy and sell orders.
It is also part of the market-surveillance system.
2026 enforcement shows the regime is active
The strongest evidence that the law is operational comes from the FSC's July 2026 two-year review.
As of July 20, 2026, financial authorities reported that they had:
Most referred cases involved price manipulation, although fraudulent trading cases were also identified.
These figures are much more useful than saying merely:
“South Korea may enforce against market manipulation.”
Enforcement is already happening.
Regulators have targeted crypto-specific manipulation patterns
The FSC's 2026 review described several patterns seen in investigations.
These included very short-term manipulation strategies designed around features of crypto markets, as well as more sustained schemes.
Examples included conduct involving:
This illustrates why crypto surveillance cannot simply copy stock-market tools.
Crypto trades continuously and can involve fragmented liquidity across multiple venues.
The enforcement framework also uses financial penalties
The law allows authorities to impose financial penalties linked to illicit gains, alongside criminal enforcement.
The FSC's 2026 review noted cases where administrative penalties were imposed above the amount of illicit gains.
This adds another deterrent mechanism.
The regulatory system is therefore not limited to:
Detect → Report to police
It can also involve:
The exact procedural stage should still be reported carefully.
A referral is not the same as a conviction.
AI is now being used in surveillance and investigations
The FSC said in its two-year review that authorities have been improving market-surveillance capabilities using AI.
The system is intended to help identify suspicious patterns such as:
This is significant because Korean crypto exchanges operate 24 hours a day.
Automated detection can help regulators and exchanges process the volume of orders and identify patterns that would be difficult to review manually.
AI detection does not itself establish guilt.
It is a tool for identifying activity that may require investigation.
Unusual price action does not automatically prove manipulation
This distinction remains important.
A token can rise 100% because of:
A large move is not itself proof of illegal conduct.
Likewise, high trading volume does not automatically prove wash trading.
Authorities need evidence connecting the trading behavior with the prohibited conduct.
For public reporting, distinguish:
unusual market behavior
from
suspected misconduct
from
regulatory finding
from
criminal conviction.
Those are different procedural stages.
Registration is not investment approval
South Korea's earlier VASP registration framework and the User Protection Act regulate the service provider.
They do not mean regulators endorse every token listed on that exchange.
A registered Korean exchange can list a token that later:
The existence of regulated custody does not change the economics of the asset.
Users should separate:
Exchange regulation
from
Token investment risk.
Listing is not a government guarantee either
A listing decision means that the exchange has decided to support trading under its own listing and review procedures.
It does not mean:
This distinction becomes particularly important for smaller assets.
A token can trade on a major regulated exchange and still carry extreme market risk.
DAXA and exchange-level reviews sit alongside statutory regulation
South Korea's major virtual asset exchanges participate in industry coordination through DAXA.
Industry-level processes can address matters such as:
These mechanisms operate alongside government regulation.
They should not be confused with a government licence for an individual token.
A DAXA action and an FSC enforcement action are different things.
The User Protection Act is not a complete stablecoin law
The Act focuses on:
It does not by itself create a comprehensive stablecoin issuer framework equivalent to regimes specifically built around:
South Korea has been discussing broader second-phase legislation that would address additional parts of the digital asset market, including stablecoins.
As of September 2026, those Phase 2 rules should not be written as if they are already law.
Phase 2 legislation remains under development
In March 2026, the FSC's Virtual Asset Committee discussed a government review proposal for a broader Digital Asset Basic Act, commonly described as Phase 2 legislation.
Topics under discussion included areas such as:
The FSC had already warned in January 2026 that key stablecoin details reported in the media had not been finalized.
That distinction should be preserved.
The correct status is:
Policy and legislative development underway
not:
New stablecoin regime already enacted.
The 2026 AML changes are a separate legal layer
Another important 2026 development came from the Specified Financial Transaction Information Act framework, not from the User Protection Act itself.
Amendments taking effect in August 2026 strengthened VASP AML and transfer controls.
These changes include:
These rules should not be mixed into the User Protection Act as though they were one statute.
For users, however, both frameworks can affect the same withdrawal.
A transfer can simultaneously involve:
User Protection Act custody rules
and
AML / Travel Rule controls.
The old KRW 1 million Travel Rule threshold is no longer the full story
Under the revised AML framework, South Korea moved toward a risk-based model for transfers involving:
The revised rules also require specified higher-value transfers to overseas providers or wallet services to be reported to KoFIU.
This means a user should not assume that:
“Below KRW 1 million means no compliance checks.”
The regulatory model is becoming more risk-based.
Exchange withdrawal procedures can therefore ask for information even when a transaction appears small in nominal value.
Customer due diligence is also becoming stricter
The August 2026 AML changes clarified that VASPs should verify the accuracy of customer identification information rather than merely collect it.
Enhanced due diligence can also apply to:
This reinforces the broader direction of Korean crypto regulation.
The system is moving from:
registration + basic KYC
toward:
continuous risk assessment + asset protection + market surveillance.
Self-custody is not prohibited
Stronger AML controls should not be misreported as a ban on personal wallets.
Users can still transfer assets to self-custody subject to the exchange's compliance obligations.
The provider may request information about:
That is different from requiring the user to surrender control of the wallet.
A legitimate provider should never need the user's:
Those credentials control the assets themselves and should not be disclosed as ordinary KYC information.
The law does not guarantee exchange solvency
South Korea's safeguards are substantial.
They include:
None of those is a guarantee that a VASP can never fail.
Risks can still arise from:
The framework reduces and manages particular risks.
It does not eliminate them.
The law does not protect against token price losses
The same principle applies to investments.
If a user buys a token at KRW 10,000 and it falls to KRW 1,000, the cold-storage requirement has worked perfectly if the exchange still holds the correct quantity of tokens.
Custody protection preserves the asset.
It does not preserve the asset's market value.
This is one of the most important distinctions in crypto regulation.
Users should preserve records during a dispute
When something goes wrong, evidence matters.
Useful records include:
| Area | Evidence to keep |
|---|---|
| Account | Legal entity, user agreement and account UID |
| Deposit | Bank confirmation or blockchain transaction hash |
| Trading | Order IDs, execution prices and timestamps |
| Withdrawal | Address, network, amount, status and transaction ID |
| Restriction | Exchange notice, reason and expected duration |
| Support | Ticket number, emails and formal replies |
| Market concern | Announcements, screenshots and trading records |
| Protection claim | Insurance or reserve disclosure and date |
These records do not prove liability by themselves.
They make it easier to distinguish among:
Withdrawal restrictions should be read carefully
A withdrawal delay can arise for several reasons.
Examples include:
Users should first determine:
Is the restriction platform-wide, asset-specific or account-specific?
Then record:
This is particularly important if an asset continues trading while deposits or withdrawals are suspended.
Local prices can diverge sharply when arbitrage becomes difficult.
The 2026 Bithumb incident shows why operational risk matters
South Korea's regulatory debate in 2026 was influenced by a major operational incident involving Bithumb.
A reward-processing error in February created erroneous internal BTC balances for hundreds of users.
The incident was not an external blockchain hack, but it highlighted a different category of risk:
internal ledger and operational-control failure.
In March, the Virtual Asset Committee discussed stronger internal controls and potential liability mechanisms as part of the broader Phase 2 policy work.
The lesson is relevant beyond one exchange.
Cold-wallet requirements protect against some custody risks.
They do not prevent every internal accounting or system error.
Custody risk and ledger risk are different
A centralized exchange has at least two important accounting layers.
Blockchain custody
What assets does the exchange actually control on-chain?
Internal customer ledger
What assets does the exchange say each user owns?
Both need to be correct.
An exchange can have secure cold wallets while making a serious internal balance error.
Likewise, its internal accounting can be accurate while the underlying wallets are compromised.
User protection therefore requires:
The 2026 regulatory debate increasingly reflects that broader view.
How to evaluate a Korean exchange
A useful review follows several steps.
1. Identify the Korean legal entity
Check the customer agreement rather than only the brand.
A global group's Korean subsidiary may have different rules from its offshore affiliate.
2. Verify VASP registration
Check the relevant KoFIU / financial authority records for the entity.
Registration is a baseline, not an investment rating.
3. Check KRW banking access
For KRW-market exchanges, real-name bank-account arrangements affect:
4. Review customer asset protection
Look for disclosures covering:
5. Check withdrawal status before buying
For smaller assets, verify:
6. Understand AML transfer requirements
International exchanges and self-custody wallets can trigger additional verification.
7. Keep records
Preserve transaction and support evidence if a dispute occurs.
What the law means for exchanges
For exchanges, the User Protection Act creates ongoing operational obligations.
They need systems capable of:
This is not a once-a-year licensing exercise.
The rules affect daily exchange operations.
What the law means for users
For users, the framework gives more concrete questions to ask.
Instead of:
“Is this exchange regulated?”
ask:
Who holds my KRW?
Does the exchange actually hold my crypto?
How much customer value is in cold storage?
What protection exists for hacking or system failures?
Why was my withdrawal restricted?
Who monitors suspicious trading?
Which legal entity holds my account?
Those questions produce more useful answers than a regulatory badge by itself.
The next stage of Korean crypto regulation is still developing
South Korea's first-stage law focused on the most urgent user-protection and market-integrity issues.
The next legislative stage is intended to address a broader set of questions.
Potential areas include:
But the details remain part of the legislative and policy process.
Future articles should update those rules when they are actually enacted.
Until then, they should remain clearly separated from the current User Protection Act.
Conclusion
South Korea's Virtual Asset User Protection Act is no longer an early-stage regulatory experiment.
It has been in force since July 19, 2024.
The custody rules are operational.
The 80% cold-storage requirement is being applied.
Insurance and reserve requirements are in place.
Exchanges operate abnormal-trading surveillance systems.
And by July 2026, authorities had completed more than 40 unfair-trading investigations and referred or reported more than 30 cases.
The strongest way to understand the Korean framework is therefore to keep several concepts separate.
VASP registration is not investment approval.
Cold storage protects custody, not token prices.
Insurance and reserves do not reimburse every possible loss.
A withdrawal compliance check is not automatically an insolvency event.
AML transfer rules and the User Protection Act are separate legal layers.
Phase 2 stablecoin and market-structure legislation is still under development.
For users, regulation provides stronger custody, conduct and enforcement tools.
It does not replace the need to understand the exchange, token and transaction being used.
Frequently asked questions
When did South Korea's Virtual Asset User Protection Act take effect?
The Act took effect on July 19, 2024.
It had been enacted on July 18, 2023, but enactment and commencement are different milestones.
What does the 80% cold-storage rule mean?
VASPs must keep at least 80% of the economic value of customer virtual assets in cold wallets.
The requirement is based on the regulatory valuation methodology and must be maintained on an ongoing basis.
Does 80% cold storage mean only 20% of customer crypto can be lost?
No.
The rule concerns storage method.
Cold storage reduces particular online hacking risks but does not eliminate key-management, operational, legal or market risks.
Does a Korean exchange have to hold the crypto customers bought?
Yes.
The framework requires VASPs to actually hold the types and quantities of virtual assets entrusted by users, alongside customer asset segregation requirements.
How is customer KRW protected?
Customer deposits must be managed separately through designated banks.
If a VASP becomes bankrupt or loses its registration, the bank can return safeguarded deposits directly to users through the required process.
Why do exchanges pay interest-like amounts on KRW deposits?
The framework requires providers to pay users a deposit-use fee based on returns from safeguarded customer deposits after relevant costs.
This is not staking yield on cryptoassets.
Do Korean exchanges need insurance?
VASPs must maintain insurance, mutual-aid arrangements or reserves for specified incidents such as hacking and system failures.
The required level is linked to the economic value of customer assets outside cold storage, subject to regulatory minimums.
Does insurance guarantee every customer loss?
No.
Coverage depends on the type and cause of the loss, applicable limits and the protection structure.
It should not be treated as unlimited account insurance.
Is market manipulation illegal under the Act?
Yes.
The law prohibits forms of unfair trading including misuse of material non-public information, price manipulation and fraudulent transactions.
Is enforcement active?
Yes.
In its July 2026 review, the FSC said authorities had completed more than 40 investigations and referred or reported more than 30 cases to investigative authorities since the law took effect.
Does exchange registration mean every listed token is approved?
No.
Registration regulates the service provider.
It does not mean regulators guarantee or endorse every cryptoasset listed by the exchange.
Has South Korea already enacted its Phase 2 Digital Asset Basic Act?
Not as of September 2026.
The government and Virtual Asset Committee have been discussing the broader second-phase framework, but key details should not be treated as final law until legislation is enacted.
Did South Korea ban self-custody wallets?
No.
Regulated exchanges can apply AML and wallet-verification procedures to transfers involving personal wallets.
That does not mean individuals are prohibited from controlling their own wallets.
Are the 2026 Travel Rule changes part of the User Protection Act?
No.
The strengthened transfer and AML requirements come from South Korea's separate Specified Financial Transaction Information Act framework.
The rules can affect the same user withdrawal, but they are a separate legal layer.
What should I check before using a Korean exchange?
Use this sequence:
Brand → Korean Legal Entity → VASP Registration → KRW Banking Status → Customer Asset Protection → Withdrawal / AML Rules → Customer Agreement
Do not stop after confirming that the exchange is registered.
Official sources
Disclaimer: This article is for regulatory research and informational purposes only. It is not legal or investment advice. VASP registration, AML transfer requirements, Phase 2 legislation and customer protection rules can change, so current information should be verified against FSC, KoFIU and the applicable customer agreement before use.

