Japan FSA requires crypto exchanges to add withdrawal delays for fraud prevention
Japan's Financial Services Agency and National Police Agency have jointly requested that crypto exchanges implement non-binding safeguards, including withdrawal delays and mandatory address pre-registration, to combat rising fraud and user losses. The move coincides with a broader regulatory overhaul, including the creation of a dedicated Crypto Assets and Stablecoins Division and a standardized cyberattack reporting framework across 17 sectors.
FSA withdrawal delay requirements
▪Japan's Financial Services Agency and the National Police Agency jointly requested that crypto exchanges introduce withdrawal delays and other safeguards to combat rising fraud.
▪The joint request by Japanese authorities was submitted on August 6, 2026 to the Japan Virtual and Crypto Assets Exchange Association, the industry's self-regulatory body.
▪The proposed safeguards include customer-specific withdrawal limits, phishing-resistant multi-factor authentication, and checks matching bank remitter names with crypto account holders.
▪The guidelines request that exchanges require users to pre-register withdrawal addresses and enforce a waiting period before newly added addresses can be used.
▪The FSA stated that the anti-fraud measures are not binding rules, and individual exchanges have discretion over how to implement them based on their operations.
▪The proposed measures ask crypto exchanges to restrict withdrawals for a specified period after customers deposit fiat currency or purchase digital assets.
Rising crypto fraud in Japan
▪Japanese authorities issued the anti-fraud directive due to growing losses among crypto exchange users and increasingly sophisticated criminal methods transferring fraudulent funds.
▪The FSA noted that once fraudulent funds are off-ramped from Japanese exchanges to external wallets, the chances of recovering the assets are extremely low.
Standardized cyberattack reporting framework
▪The FSA's draft revision introduces a 'Common Template for Other Cyberattack Incidents' to capture breaches beyond DDoS and ransomware attacks.
▪On August 7, 2026, the FSA published a draft revision to standardize how firms across 17 sectors, including crypto exchanges, report cyberattacks and system failures.
▪Firms can use the old reporting format during a transitional period ending March 2027, with the FSA accepting public comments on the draft until September 7, 2026.
Japan crypto regulatory overhaul
▪On August 6, 2026, the FSA established a dedicated Crypto Assets and Stablecoins Division under a new supervisory bureau to consolidate its regulatory oversight.
▪A Japanese law passed in July 2026 reclassifies crypto as a financial product, cuts the top tax on trading gains to 20% starting January 1, 2028, and enables domestic spot ETFs.
Story comments
Loading comments…