South Korea Virtual Asset User Protection Act: Safeguards and Market Abuse

摘要:South Korea’s Virtual Asset User Protection Act now has two years of enforcement behind it. This guide explains the 80% cold-storage rule, deposit safeguards, insurance, market-abuse cases and how 2026 AML reforms fit alongside the law.

South Korea's Virtual Asset User Protection Act has moved well beyond its launch phase.

The law took effect on July 19, 2024 and added a dedicated user-protection and market-conduct layer on top of the country's earlier virtual asset service provider registration and anti-money-laundering framework.

Its core protections are concrete.

Customer cash deposits must be managed separately through banks. Virtual asset service providers must actually hold the types and quantities of crypto entrusted by users. At least 80% of the economic value of customer virtual assets must be maintained in cold storage. Providers also need insurance, mutual-aid arrangements or reserves for specified incidents such as hacking and system failures.

The law also created a much stronger market-abuse regime covering conduct such as insider dealing, price manipulation and fraudulent transactions.

By July 2026, those provisions were no longer theoretical. Korean financial authorities reported that they had completed investigations into more than 40 suspected unfair-trading cases since the law took effect and had referred or reported more than 30 cases to investigative authorities.

That enforcement record makes the 2026 question different from the one investors asked in 2024.

It is no longer:

Will South Korea enforce the User Protection Act?

It is:

How do the custody rules work in practice, what does the 80% cold-storage requirement actually mean, and what protections do users have when trading activity or withdrawals become abnormal?

The User Protection Act is not South Korea's entire crypto framework

South Korea's crypto regulation has several layers.

The User Protection Act is one of them.

A simplified map looks like this:

Regulatory layerMain purpose
VASP registration under the Specified Financial Transaction Information ActAML/CFT, customer identification and provider registration
Real-name banking requirementsKRW-market access and customer identification
Virtual Asset User Protection ActCustomer assets, custody, incident protection and unfair trading
Travel Rule / AML rulesInformation and controls for virtual asset transfers
Future second-phase legislationBroader issuer, stablecoin, exchange and market-structure rules still under development

This distinction matters because a provider can satisfy one regulatory requirement without every other question being answered.

For example:

VASP registration

does not mean:

every listed token is approved as an investment.

Likewise:

compliance with the User Protection Act

does not mean:

the exchange cannot fail.

Each layer regulates a different problem.

Why South Korea needed a separate user-protection law

South Korea already had a VASP registration system before the User Protection Act.

The earlier framework was centered heavily on:

  • anti-money laundering;
  • customer identification;
  • suspicious transaction controls;
  • registration of virtual asset service providers.

Those rules help answer questions such as:

Who is using the service?

and:

Where did the money come from?

They do not fully answer:

Where are customer assets held?

What happens if the exchange is hacked?

What happens if someone manipulates the market?

What records must be preserved?

The Virtual Asset User Protection Act was designed to address those gaps.

Its two most important pillars are:

  • protection of customer money and virtual assets;
  • prevention and enforcement of unfair trading.
  • The law took effect on July 19, 2024

    The timeline is straightforward:

    DateDevelopment
    March 2021VASP registration framework introduced under the earlier financial-information regime
    July 18, 2023Virtual Asset User Protection Act enacted
    July 19, 2024Act and major implementing rules took effect
    2025–2026Investigations, inspections and enforcement expanded
    July 2026FSC published a two-year unfair-trading enforcement review
    2026Government continued work on separate second-phase digital asset legislation

    The July 2023 enactment date should not be confused with the July 2024 commencement date.

    And the continuing discussion of “Phase 2” legislation should not be interpreted as evidence that the User Protection Act is still pending.

    The first-stage user-protection framework is already in force.

    Customer cash and customer crypto are protected differently

    The Act distinguishes customer money from customer virtual assets.

    That is important because the risks are different.

    Customer cash deposits

    Money deposited by users in connection with virtual asset trading must be managed through a designated custodian institution.

    The implementing framework designates banks for this role.

    Customer deposits must be segregated from the exchange's own money.

    The bank may manage those deposits only through relatively safe assets permitted under the framework, including specified government-backed instruments.

    Customer virtual assets

    The exchange must also separate customer virtual assets from its own assets.

    More importantly, it must actually hold the corresponding types and quantities of virtual assets entrusted by users.

    This is a stronger requirement than simply displaying an account balance on an internal database.

    The regulatory principle is:

    The exchange's records should correspond to real customer assets.

    What happens to customer cash if the exchange fails?

    The deposit-protection structure has a particularly useful feature.

    If a VASP becomes bankrupt or its registration is cancelled, the bank holding customer deposits can return the relevant money directly to users after completing the required notice and verification procedures.

    This means customer cash is not intended to be treated simply as ordinary operating money of the exchange.

    That does not make the exchange equivalent to a bank.

    It means the user-deposit structure is designed to preserve a clearer path for returning customer money if the VASP itself fails.

    Users receive deposit-use fees on customer cash

    The framework also requires VASPs to pay users a deposit-use fee based on the return generated from customer deposits after relevant costs.

    This should not be confused with crypto staking or stablecoin yield.

    The underlying object is customer money deposited with the exchange, not BTC, ETH or another virtual asset balance.

    A useful distinction is:

    KRW deposit-use payment

    versus:

    crypto investment return

    They arise from different legal and economic relationships.

    An exchange paying a user a return on safeguarded KRW deposits is not promising yield on every cryptoasset held in the same account.

    The 80% cold-storage rule is based on economic value

    One of South Korea's most visible crypto safeguards is the cold-storage requirement.

    VASPs must keep at least:

    80% of the economic value of customer virtual assets

    in cold wallets.

    The rule is not based simply on the number of coins.

    It uses an economic-value calculation.

    For each type of virtual asset, the provider considers:

    quantity held × applicable KRW valuation

    and aggregates the result across customer assets.

    The regulatory calculation uses historical KRW conversion data under the supervisory rules.

    That matters because 80% of the number of wallet addresses would be meaningless.

    The requirement is designed around the economic value of customer holdings.

    The 80% ratio must be maintained continuously

    The rule is not only checked once each month.

    FSC implementation guidance says the required cold-wallet ratio needs to be maintained on an ongoing basis, supported by internal controls and daily monitoring.

    The calculation uses the provider's current holdings and the prescribed valuation methodology.

    That means an exchange cannot satisfy the rule by moving assets offline only on the day before an inspection and then returning most of them to hot wallets immediately afterward.

    The framework expects the storage ratio to be continuously maintained.

    80% cold storage does not mean only 20% can be lost

    This is an important misconception.

    The rule does not mean:

    “Only 20% of customer assets are exposed to risk.”

    Cold storage reduces specific online attack risks.

    It does not eliminate:

    • insider misconduct;
    • poor key management;
    • recovery failures;
    • inaccurate internal records;
    • operational mistakes;
    • legal disputes;
    • market losses.

    A cold wallet can also be compromised if key-management procedures fail.

    The 80% requirement is therefore one layer of risk control.

    It is not a mathematical maximum-loss guarantee.

    Hot-wallet assets create additional protection requirements

    The remaining portion of customer crypto can be held in online environments to support normal deposits, withdrawals and trading operations.

    Because hot wallets have greater exposure to online attacks, the supervisory framework also requires VASPs to maintain insurance, mutual-aid coverage or reserves for specified incidents.

    The baseline calculation is tied to the economic value of customer virtual assets not held in cold storage.

    FSC guidance describes the required amount as at least 5% of the relevant hot-wallet economic value, subject to minimum amounts defined by provider type.

    The requirement is recalculated periodically, and providers must increase insurance limits or reserves when necessary.

    This creates a layered structure:

    Cold storage requirement

    plus

    incident-loss protection for the online portion.

    Insurance and reserves are not unlimited compensation

    The existence of an insurance policy or reserve fund can easily be overstated.

    It does not mean:

    Every customer loss will always be reimbursed in full.

    Coverage depends on factors such as:

    • the cause of loss;
    • policy terms;
    • reserve amount;
    • responsibility of the provider;
    • the type of incident.

    A hacking incident affecting the exchange's systems is different from:

    • a user sending crypto to a scam address;
    • a token collapsing in price;
    • a separate DeFi protocol failure;
    • loss caused by the user's compromised personal wallet.

    Users should therefore ask:

    What event does the protection cover?

    rather than only:

    Does the exchange have insurance?

    Exchanges must maintain customer asset records

    South Korea's framework requires providers to maintain records that allow customer virtual asset holdings and transaction history to be verified.

    The law also requires long-term retention of relevant virtual asset transaction records.

    This matters during:

    • insolvency;
    • account disputes;
    • investigations;
    • reconciliation failures.

    Blockchain records can show that a wallet transaction occurred.

    They do not automatically show which customer was entitled to which portion of an omnibus exchange wallet.

    The provider's internal records remain critical.

    Withdrawal suspensions are also regulated

    The Act addresses situations in which deposits or withdrawals are blocked.

    FSC guidance says users should generally receive prior notice explaining the reason and expected period of a restriction.

    The exact method can depend on the circumstances, and limited exceptions can apply.

    This is important because not every withdrawal suspension is evidence of insolvency.

    A restriction can result from:

    • blockchain maintenance;
    • security incidents;
    • unusual transaction review;
    • network upgrades;
    • legal or compliance requirements.

    But the exchange should still have a defined basis and communication process.

    For users, preserving the notice is valuable evidence.

    South Korea's framework also targets market manipulation

    The second major pillar of the Act is market conduct.

    The law prohibits unfair trading including:

    • misuse of material non-public information;
    • price manipulation;
    • fraudulent trading activity.

    VASPs are also required to monitor for abnormal trading.

    The regulatory focus extends beyond isolated suspicious orders.

    Authorities can examine:

    • trading patterns;
    • order placement;
    • related accounts;
    • fund flows;
    • public statements;
    • issuer relationships;
    • cross-exchange activity.

    This is particularly important in crypto markets, where prices can move rapidly on relatively small markets.

    Exchanges must monitor abnormal trading

    Korean exchanges maintain systems for continuous monitoring of abnormal transactions.

    Examples can include situations where:

    • price changes abnormally;
    • trading volume changes abnormally;
    • news or rumors likely to affect price appear;
    • suspicious order patterns occur.

    When activity appears connected with possible unfair trading, the exchange can be required to review it and report relevant suspicions to the authorities.

    This changes the exchange's role.

    A regulated exchange is not only matching buy and sell orders.

    It is also part of the market-surveillance system.

    2026 enforcement shows the regime is active

    The strongest evidence that the law is operational comes from the FSC's July 2026 two-year review.

    As of July 20, 2026, financial authorities reported that they had:

    • completed investigations into more than 40 cases;
    • referred or reported more than 30 cases to investigative authorities;
    • identified 25 suspects across the referred cases;
    • found average illicit gains of roughly KRW 1.4 billion per case.

    Most referred cases involved price manipulation, although fraudulent trading cases were also identified.

    These figures are much more useful than saying merely:

    “South Korea may enforce against market manipulation.”

    Enforcement is already happening.

    Regulators have targeted crypto-specific manipulation patterns

    The FSC's 2026 review described several patterns seen in investigations.

    These included very short-term manipulation strategies designed around features of crypto markets, as well as more sustained schemes.

    Examples included conduct involving:

    • concentrated high-frequency orders;
    • false or non-genuine orders;
    • pump-and-dump behavior;
    • use of API keys;
    • issuer-linked activity;
    • coordinated trading with overseas exchanges;
    • false information distributed through social media.

    This illustrates why crypto surveillance cannot simply copy stock-market tools.

    Crypto trades continuously and can involve fragmented liquidity across multiple venues.

    The enforcement framework also uses financial penalties

    The law allows authorities to impose financial penalties linked to illicit gains, alongside criminal enforcement.

    The FSC's 2026 review noted cases where administrative penalties were imposed above the amount of illicit gains.

    This adds another deterrent mechanism.

    The regulatory system is therefore not limited to:

    Detect → Report to police

    It can also involve:

    • investigation;
    • referral;
    • administrative sanctions;
    • financial penalties.

    The exact procedural stage should still be reported carefully.

    A referral is not the same as a conviction.

    AI is now being used in surveillance and investigations

    The FSC said in its two-year review that authorities have been improving market-surveillance capabilities using AI.

    The system is intended to help identify suspicious patterns such as:

    • rapid manipulation;
    • abnormal order groups;
    • suspicious trading intervals.

    This is significant because Korean crypto exchanges operate 24 hours a day.

    Automated detection can help regulators and exchanges process the volume of orders and identify patterns that would be difficult to review manually.

    AI detection does not itself establish guilt.

    It is a tool for identifying activity that may require investigation.

    Unusual price action does not automatically prove manipulation

    This distinction remains important.

    A token can rise 100% because of:

    • genuine demand;
    • low liquidity;
    • a listing announcement;
    • project news;
    • speculation.

    A large move is not itself proof of illegal conduct.

    Likewise, high trading volume does not automatically prove wash trading.

    Authorities need evidence connecting the trading behavior with the prohibited conduct.

    For public reporting, distinguish:

    unusual market behavior

    from

    suspected misconduct

    from

    regulatory finding

    from

    criminal conviction.

    Those are different procedural stages.

    Registration is not investment approval

    South Korea's earlier VASP registration framework and the User Protection Act regulate the service provider.

    They do not mean regulators endorse every token listed on that exchange.

    A registered Korean exchange can list a token that later:

    • falls sharply;
    • receives an investment warning;
    • loses liquidity;
    • is delisted.

    The existence of regulated custody does not change the economics of the asset.

    Users should separate:

    Exchange regulation

    from

    Token investment risk.

    Listing is not a government guarantee either

    A listing decision means that the exchange has decided to support trading under its own listing and review procedures.

    It does not mean:

    • FSC recommends the token;
    • FSS guarantees the token;
    • the project is free of fraud;
    • liquidity will remain available.

    This distinction becomes particularly important for smaller assets.

    A token can trade on a major regulated exchange and still carry extreme market risk.

    DAXA and exchange-level reviews sit alongside statutory regulation

    South Korea's major virtual asset exchanges participate in industry coordination through DAXA.

    Industry-level processes can address matters such as:

    • transaction support;
    • warning designations;
    • delisting practices;
    • common user-protection standards.

    These mechanisms operate alongside government regulation.

    They should not be confused with a government licence for an individual token.

    A DAXA action and an FSC enforcement action are different things.

    The User Protection Act is not a complete stablecoin law

    The Act focuses on:

    • customer assets;
    • provider conduct;
    • unfair trading.

    It does not by itself create a comprehensive stablecoin issuer framework equivalent to regimes specifically built around:

    • issuer licensing;
    • reserve composition;
    • redemption rights;
    • issuance limits.

    South Korea has been discussing broader second-phase legislation that would address additional parts of the digital asset market, including stablecoins.

    As of September 2026, those Phase 2 rules should not be written as if they are already law.

    Phase 2 legislation remains under development

    In March 2026, the FSC's Virtual Asset Committee discussed a government review proposal for a broader Digital Asset Basic Act, commonly described as Phase 2 legislation.

    Topics under discussion included areas such as:

    • stablecoin regulation;
    • stronger exchange internal controls;
    • liability for operational failures;
    • broader market structure.

    The FSC had already warned in January 2026 that key stablecoin details reported in the media had not been finalized.

    That distinction should be preserved.

    The correct status is:

    Policy and legislative development underway

    not:

    New stablecoin regime already enacted.

    The 2026 AML changes are a separate legal layer

    Another important 2026 development came from the Specified Financial Transaction Information Act framework, not from the User Protection Act itself.

    Amendments taking effect in August 2026 strengthened VASP AML and transfer controls.

    These changes include:

    • enhanced VASP registration review;
    • stronger customer due diligence;
    • risk-based treatment of transfers involving overseas VASPs and private wallets;
    • additional reporting requirements for certain large transfers.

    These rules should not be mixed into the User Protection Act as though they were one statute.

    For users, however, both frameworks can affect the same withdrawal.

    A transfer can simultaneously involve:

    User Protection Act custody rules

    and

    AML / Travel Rule controls.

    The old KRW 1 million Travel Rule threshold is no longer the full story

    Under the revised AML framework, South Korea moved toward a risk-based model for transfers involving:

    • overseas VASPs;
    • digital wallet service providers;
    • private wallets.

    The revised rules also require specified higher-value transfers to overseas providers or wallet services to be reported to KoFIU.

    This means a user should not assume that:

    “Below KRW 1 million means no compliance checks.”

    The regulatory model is becoming more risk-based.

    Exchange withdrawal procedures can therefore ask for information even when a transaction appears small in nominal value.

    Customer due diligence is also becoming stricter

    The August 2026 AML changes clarified that VASPs should verify the accuracy of customer identification information rather than merely collect it.

    Enhanced due diligence can also apply to:

    • high-risk customers;
    • high-risk products;
    • high-risk services.

    This reinforces the broader direction of Korean crypto regulation.

    The system is moving from:

    registration + basic KYC

    toward:

    continuous risk assessment + asset protection + market surveillance.

    Self-custody is not prohibited

    Stronger AML controls should not be misreported as a ban on personal wallets.

    Users can still transfer assets to self-custody subject to the exchange's compliance obligations.

    The provider may request information about:

    • wallet ownership;
    • destination;
    • transaction purpose;
    • source of funds.

    That is different from requiring the user to surrender control of the wallet.

    A legitimate provider should never need the user's:

    • seed phrase;
    • private key.

    Those credentials control the assets themselves and should not be disclosed as ordinary KYC information.

    The law does not guarantee exchange solvency

    South Korea's safeguards are substantial.

    They include:

    • bank-managed customer deposits;
    • segregation of customer crypto;
    • actual asset-holding requirements;
    • 80% cold storage;
    • insurance or reserve arrangements;
    • market surveillance.

    None of those is a guarantee that a VASP can never fail.

    Risks can still arise from:

    • business losses;
    • cyber incidents;
    • internal fraud;
    • operational mistakes;
    • legal disputes;
    • liquidity problems.

    The framework reduces and manages particular risks.

    It does not eliminate them.

    The law does not protect against token price losses

    The same principle applies to investments.

    If a user buys a token at KRW 10,000 and it falls to KRW 1,000, the cold-storage requirement has worked perfectly if the exchange still holds the correct quantity of tokens.

    Custody protection preserves the asset.

    It does not preserve the asset's market value.

    This is one of the most important distinctions in crypto regulation.

    Users should preserve records during a dispute

    When something goes wrong, evidence matters.

    Useful records include:

    AreaEvidence to keep
    AccountLegal entity, user agreement and account UID
    DepositBank confirmation or blockchain transaction hash
    TradingOrder IDs, execution prices and timestamps
    WithdrawalAddress, network, amount, status and transaction ID
    RestrictionExchange notice, reason and expected duration
    SupportTicket number, emails and formal replies
    Market concernAnnouncements, screenshots and trading records
    Protection claimInsurance or reserve disclosure and date

    These records do not prove liability by themselves.

    They make it easier to distinguish among:

    • market loss;
    • operational restriction;
    • compliance review;
    • possible misconduct.

    Withdrawal restrictions should be read carefully

    A withdrawal delay can arise for several reasons.

    Examples include:

    • blockchain network maintenance;
    • exchange wallet maintenance;
    • AML review;
    • fraud detection;
    • Travel Rule verification;
    • security incident.

    Users should first determine:

    Is the restriction platform-wide, asset-specific or account-specific?

    Then record:

    • when it began;
    • the stated reason;
    • the expected end date;
    • whether trading remains open.

    This is particularly important if an asset continues trading while deposits or withdrawals are suspended.

    Local prices can diverge sharply when arbitrage becomes difficult.

    The 2026 Bithumb incident shows why operational risk matters

    South Korea's regulatory debate in 2026 was influenced by a major operational incident involving Bithumb.

    A reward-processing error in February created erroneous internal BTC balances for hundreds of users.

    The incident was not an external blockchain hack, but it highlighted a different category of risk:

    internal ledger and operational-control failure.

    In March, the Virtual Asset Committee discussed stronger internal controls and potential liability mechanisms as part of the broader Phase 2 policy work.

    The lesson is relevant beyond one exchange.

    Cold-wallet requirements protect against some custody risks.

    They do not prevent every internal accounting or system error.

    Custody risk and ledger risk are different

    A centralized exchange has at least two important accounting layers.

    Blockchain custody

    What assets does the exchange actually control on-chain?

    Internal customer ledger

    What assets does the exchange say each user owns?

    Both need to be correct.

    An exchange can have secure cold wallets while making a serious internal balance error.

    Likewise, its internal accounting can be accurate while the underlying wallets are compromised.

    User protection therefore requires:

    • custody controls;
    • reconciliation;
    • transaction controls;
    • internal approval processes.

    The 2026 regulatory debate increasingly reflects that broader view.

    How to evaluate a Korean exchange

    A useful review follows several steps.

    1. Identify the Korean legal entity

    Check the customer agreement rather than only the brand.

    A global group's Korean subsidiary may have different rules from its offshore affiliate.

    2. Verify VASP registration

    Check the relevant KoFIU / financial authority records for the entity.

    Registration is a baseline, not an investment rating.

    3. Check KRW banking access

    For KRW-market exchanges, real-name bank-account arrangements affect:

    • fiat deposits;
    • withdrawals;
    • customer eligibility.

    4. Review customer asset protection

    Look for disclosures covering:

    • customer cash;
    • crypto segregation;
    • cold-wallet controls;
    • incident insurance or reserves.

    5. Check withdrawal status before buying

    For smaller assets, verify:

    • blockchain network;
    • deposit status;
    • withdrawal status;
    • delisting notices.

    6. Understand AML transfer requirements

    International exchanges and self-custody wallets can trigger additional verification.

    7. Keep records

    Preserve transaction and support evidence if a dispute occurs.

    What the law means for exchanges

    For exchanges, the User Protection Act creates ongoing operational obligations.

    They need systems capable of:

    • segregating customer assets;
    • calculating cold-wallet ratios;
    • monitoring hot-wallet exposure;
    • maintaining insurance or reserves;
    • reconciling customer assets;
    • monitoring abnormal trading;
    • reporting suspicious market conduct.

    This is not a once-a-year licensing exercise.

    The rules affect daily exchange operations.

    What the law means for users

    For users, the framework gives more concrete questions to ask.

    Instead of:

    “Is this exchange regulated?”

    ask:

    Who holds my KRW?

    Does the exchange actually hold my crypto?

    How much customer value is in cold storage?

    What protection exists for hacking or system failures?

    Why was my withdrawal restricted?

    Who monitors suspicious trading?

    Which legal entity holds my account?

    Those questions produce more useful answers than a regulatory badge by itself.

    The next stage of Korean crypto regulation is still developing

    South Korea's first-stage law focused on the most urgent user-protection and market-integrity issues.

    The next legislative stage is intended to address a broader set of questions.

    Potential areas include:

    • stablecoin issuance;
    • token issuance;
    • exchange internal controls;
    • business conduct;
    • disclosure;
    • market structure.

    But the details remain part of the legislative and policy process.

    Future articles should update those rules when they are actually enacted.

    Until then, they should remain clearly separated from the current User Protection Act.

    Conclusion

    South Korea's Virtual Asset User Protection Act is no longer an early-stage regulatory experiment.

    It has been in force since July 19, 2024.

    The custody rules are operational.

    The 80% cold-storage requirement is being applied.

    Insurance and reserve requirements are in place.

    Exchanges operate abnormal-trading surveillance systems.

    And by July 2026, authorities had completed more than 40 unfair-trading investigations and referred or reported more than 30 cases.

    The strongest way to understand the Korean framework is therefore to keep several concepts separate.

    VASP registration is not investment approval.

    Cold storage protects custody, not token prices.

    Insurance and reserves do not reimburse every possible loss.

    A withdrawal compliance check is not automatically an insolvency event.

    AML transfer rules and the User Protection Act are separate legal layers.

    Phase 2 stablecoin and market-structure legislation is still under development.

    For users, regulation provides stronger custody, conduct and enforcement tools.

    It does not replace the need to understand the exchange, token and transaction being used.

    Frequently asked questions

    When did South Korea's Virtual Asset User Protection Act take effect?

    The Act took effect on July 19, 2024.

    It had been enacted on July 18, 2023, but enactment and commencement are different milestones.

    What does the 80% cold-storage rule mean?

    VASPs must keep at least 80% of the economic value of customer virtual assets in cold wallets.

    The requirement is based on the regulatory valuation methodology and must be maintained on an ongoing basis.

    Does 80% cold storage mean only 20% of customer crypto can be lost?

    No.

    The rule concerns storage method.

    Cold storage reduces particular online hacking risks but does not eliminate key-management, operational, legal or market risks.

    Does a Korean exchange have to hold the crypto customers bought?

    Yes.

    The framework requires VASPs to actually hold the types and quantities of virtual assets entrusted by users, alongside customer asset segregation requirements.

    How is customer KRW protected?

    Customer deposits must be managed separately through designated banks.

    If a VASP becomes bankrupt or loses its registration, the bank can return safeguarded deposits directly to users through the required process.

    Why do exchanges pay interest-like amounts on KRW deposits?

    The framework requires providers to pay users a deposit-use fee based on returns from safeguarded customer deposits after relevant costs.

    This is not staking yield on cryptoassets.

    Do Korean exchanges need insurance?

    VASPs must maintain insurance, mutual-aid arrangements or reserves for specified incidents such as hacking and system failures.

    The required level is linked to the economic value of customer assets outside cold storage, subject to regulatory minimums.

    Does insurance guarantee every customer loss?

    No.

    Coverage depends on the type and cause of the loss, applicable limits and the protection structure.

    It should not be treated as unlimited account insurance.

    Is market manipulation illegal under the Act?

    Yes.

    The law prohibits forms of unfair trading including misuse of material non-public information, price manipulation and fraudulent transactions.

    Is enforcement active?

    Yes.

    In its July 2026 review, the FSC said authorities had completed more than 40 investigations and referred or reported more than 30 cases to investigative authorities since the law took effect.

    Does exchange registration mean every listed token is approved?

    No.

    Registration regulates the service provider.

    It does not mean regulators guarantee or endorse every cryptoasset listed by the exchange.

    Has South Korea already enacted its Phase 2 Digital Asset Basic Act?

    Not as of September 2026.

    The government and Virtual Asset Committee have been discussing the broader second-phase framework, but key details should not be treated as final law until legislation is enacted.

    Did South Korea ban self-custody wallets?

    No.

    Regulated exchanges can apply AML and wallet-verification procedures to transfers involving personal wallets.

    That does not mean individuals are prohibited from controlling their own wallets.

    Are the 2026 Travel Rule changes part of the User Protection Act?

    No.

    The strengthened transfer and AML requirements come from South Korea's separate Specified Financial Transaction Information Act framework.

    The rules can affect the same user withdrawal, but they are a separate legal layer.

    What should I check before using a Korean exchange?

    Use this sequence:

    Brand → Korean Legal Entity → VASP Registration → KRW Banking Status → Customer Asset Protection → Withdrawal / AML Rules → Customer Agreement

    Do not stop after confirming that the exchange is registered.

    Official sources

    • FSC — Virtual Asset User Protection Act commencement
    • FSC — Final supervisory regulation
    • FSC — Implementation Q&A for the Act
    • FSC — Framework and enforcement decree explanation
    • FSC — Legislative objectives of the Virtual Asset User Protection Act
    • FSC — Two-year unfair-trading enforcement review, July 2026
    • FSC — 2026 Virtual Asset Committee and Phase 2 policy discussion
    • FSC — Clarification that Phase 2 stablecoin details were not finalized
    • FSC — 2026 AML / Travel Rule reform
    • FSC — August 2026 revised Specified Financial Transaction Information Act enforcement rules
    • Disclaimer: This article is for regulatory research and informational purposes only. It is not legal or investment advice. VASP registration, AML transfer requirements, Phase 2 legislation and customer protection rules can change, so current information should be verified against FSC, KoFIU and the applicable customer agreement before use.

免责声明

本文观点仅代表作者个人观点,不构成本平台的投资建议,本平台不对文章信息准确性、完整性和及时性作出任何保证,亦不对因使用或信赖文章信息引发的任何损失承担责任
上一篇

AAVE 暴涨的最大阻碍:未来 473 天的收入,或无法反哺币价

下一篇

WikiBit跑路风险榜第36期GXT:X账号被清空、跑路姿势已摆出,这个“交易所”的寿命比牛奶还短