Japan's Financial Services Agency (FSA) advanced its regulatory strategy this week by introducing a new set of rules governing how cryptocurrency exchanges must report cyberattacks and handle withdrawals flagged as fraudulent.
According to local media reports, the regulator's latest guidelines include a unified form for exchanges, as well as other technology sectors, to submit information about breaches to the relevant authorities. Another guideline addresses the procedure for moving users' funds by platforms, particularly in cases where there are signs of fraud.
Japan Slows Down the Movement of Stolen Funds
Japan's National Police Agency and the Financial Services Agency (FSA), in a directive dated August 6th to members of the Japan Virtual and Crypto Assets Exchange Association (JVCEA), the industry's self-regulatory body, listed 11 fraud prevention measures.
The instructions contained measures targeting accounts involved in fraudulent schemes and their ability to transfer funds.
First, exchanges must allow funds to remain in a flagged account for a specified period before withdrawal transactions begin. Furthermore, funds can only be sent to recipient addresses registered in advance. The account operator will need to wait through a holding period before transfers to newly added addresses are processed.
The agencies also requested exchanges to set withdrawal limits based on customers' asset volume and their risk profile.
In cases of suspected phishing or impersonation attempts, other requirements were proposed, such as multi-factor authentication and matching the names on incoming bank transfers.
Monitoring will also be enhanced: transactions will be blocked faster if they appear fraudulent, and information will be promptly relayed to the prefectural police.
As stated by the FSA, each exchange has the discretion to apply these guidelines based on the specifics of its operations and risks.
Why Japanese Regulators Want to Slow Down the Withdrawal Process
The Financial Services Agency (FSA) wants to create hurdles for criminals to quickly access the platforms it supervises and move funds beyond them.
According to an agency statement, it is combating "growing losses among users of crypto asset exchanges and instances of transferring fraudulently obtained funds to exchange accounts".
Once funds are withdrawn from exchanges and placed in wallets outside Japanese jurisdiction, the chances of recovery practically drop to zero.
Unified Reporting Form for 17 Sectors
A day later, on August 7th, the Financial Services Agency (FSA) released a separate draft of revised oversight rules that standardize how companies report cyberattacks and system failures. As reported by CoinPost, among the 17 sectors subject to these rules are crypto asset exchange service providers.
Until now, there was a unified template for reporting only DDoS attacks and ransomware. The updated version adds a new "General Template for Other Cyberattacks" that will cover all other cases, in line with an amendment to an inter-agency agreement from May 2025.
During a transitional period lasting until the end of March 2027, companies can continue using the old format, and the Financial Services Agency (FSA) is accepting public comments until 5:00 PM on September 7th.
Part of a Broader Cryptocurrency Reform
These two steps are being taken against the backdrop of Japan's complete overhaul of its approach to digital assets. As Cryptopolitan reported, on August 6th, the Financial Services Agency (FSA) also established a dedicated crypto assets and stablecoins unit within a new supervisory bureau, replacing disparate office-level units that previously handled the sector.
This follows a law enacted in July that reclassifies cryptocurrency as a financial product under the Financial Instruments and Exchange Act, reduces the maximum tax on trading profits to a fixed 20% from January 1, 2028, and lays the groundwork for domestic spot ETFs. Collectively, the actions taken this week indicate a further integration of cryptocurrency into Japan's mainstream financial oversight framework.
end-content




