Japan's Financial Services Agency and National Police Agency have jointly requested that crypto exchanges implement non-binding safeguards, including withdrawal delays and mandatory address pre-registration, to combat rising fraud and user losses. The move coincides with a broader regulatory overhaul, including the creation of a dedicated Crypto Assets and Stablecoins Division and a standardized cyberattack reporting framework across 17 sectors.
FSA withdrawal delay requirements
- ▪Japan's Financial Services Agency and the National Police Agency jointly requested that crypto exchanges introduce withdrawal delays and other safeguards to combat rising fraud
- ▪The joint request by Japanese authorities was submitted on August 6, 2026 to the Japan Virtual and Crypto Assets Exchange Association, the industry's self-regulatory body
- ▪The proposed safeguards include customer-specific withdrawal limits, phishing-resistant multi-factor authentication, and checks matching bank remitter names with crypto account holders
- ▪The guidelines request that exchanges require users to pre-register withdrawal addresses and enforce a waiting period before newly added addresses can be used
- ▪The FSA stated that the anti-fraud measures are not binding rules, and individual exchanges have discretion over how to implement them based on their operations
- ▪The proposed measures ask crypto exchanges to restrict withdrawals for a specified period after customers deposit fiat currency or purchase digital assets
Rising crypto fraud in Japan
- ▪Japanese authorities issued the anti-fraud directive due to growing losses among crypto exchange users and increasingly sophisticated criminal methods transferring fraudulent funds
- ▪The FSA noted that once fraudulent funds are off-ramped from Japanese exchanges to external wallets, the chances of recovering the assets are extremely low
Standardized cyberattack reporting framework
- ▪The FSA's draft revision introduces a 'Common Template for Other Cyberattack Incidents' to capture breaches beyond DDoS and ransomware attacks
- ▪On August 7, 2026, the FSA published a draft revision to standardize how firms across 17 sectors, including crypto exchanges, report cyberattacks and system failures
- ▪Firms can use the old reporting format during a transitional period ending March 2027, with the FSA accepting public comments on the draft until September 7, 2026
Japan crypto regulatory overhaul
- ▪On August 6, 2026, the FSA established a dedicated Crypto Assets and Stablecoins Division under a new supervisory bureau to consolidate its regulatory oversight
- ▪A Japanese law passed in July 2026 reclassifies crypto as a financial product, cuts the top tax on trading gains to 20% starting January 1, 2028, and enables domestic spot ETFs
Story comments
Loading comments…