Japan's Financial Supervisory Authority Tightens Rules for Cryptocurrency Exchanges Regarding Fraud and Cybersecurity

cryptonews.ruPublished on 2026-08-07Last updated on 2026-08-07

Abstract

Japan's Financial Services Agency (FSA) has introduced stricter rules for crypto exchanges to combat fraud and cybersecurity threats. Key measures include a mandatory waiting period for withdrawals from flagged accounts, pre-registered withdrawal addresses, and withdrawal limits based on user risk profiles. Exchanges must also implement enhanced security like multi-factor authentication and swiftly report suspicious transactions to police. Separately, the FSA has standardized cyberattack reporting across 17 sectors, including crypto asset exchanges, using a new unified template. Companies have a transition period until March 2027 to adopt the new format. These moves are part of a broader regulatory overhaul in Japan, which recently reclassified crypto as a financial product, established a dedicated crypto and stablecoin supervisory unit, and paved the way for spot crypto ETFs. The actions aim to integrate cryptocurrency more firmly into Japan's mainstream financial regulatory framework.

Japan's Financial Services Agency (FSA) advanced its regulatory strategy this week by introducing a new set of rules governing how cryptocurrency exchanges must report cyberattacks and handle withdrawals flagged as fraudulent.

According to local media reports, the regulator's latest guidelines include a unified form for exchanges, as well as other technology sectors, to submit information about breaches to the relevant authorities. Another guideline addresses the procedure for moving users' funds by platforms, particularly in cases where there are signs of fraud.

Japan Slows Down the Movement of Stolen Funds

Japan's National Police Agency and the Financial Services Agency (FSA), in a directive dated August 6th to members of the Japan Virtual and Crypto Assets Exchange Association (JVCEA), the industry's self-regulatory body, listed 11 fraud prevention measures.

The instructions contained measures targeting accounts involved in fraudulent schemes and their ability to transfer funds.

First, exchanges must allow funds to remain in a flagged account for a specified period before withdrawal transactions begin. Furthermore, funds can only be sent to recipient addresses registered in advance. The account operator will need to wait through a holding period before transfers to newly added addresses are processed.

The agencies also requested exchanges to set withdrawal limits based on customers' asset volume and their risk profile.

In cases of suspected phishing or impersonation attempts, other requirements were proposed, such as multi-factor authentication and matching the names on incoming bank transfers.

Monitoring will also be enhanced: transactions will be blocked faster if they appear fraudulent, and information will be promptly relayed to the prefectural police.

As stated by the FSA, each exchange has the discretion to apply these guidelines based on the specifics of its operations and risks.

Why Japanese Regulators Want to Slow Down the Withdrawal Process

The Financial Services Agency (FSA) wants to create hurdles for criminals to quickly access the platforms it supervises and move funds beyond them.

According to an agency statement, it is combating "growing losses among users of crypto asset exchanges and instances of transferring fraudulently obtained funds to exchange accounts".

Once funds are withdrawn from exchanges and placed in wallets outside Japanese jurisdiction, the chances of recovery practically drop to zero.

Unified Reporting Form for 17 Sectors

A day later, on August 7th, the Financial Services Agency (FSA) released a separate draft of revised oversight rules that standardize how companies report cyberattacks and system failures. As reported by CoinPost, among the 17 sectors subject to these rules are crypto asset exchange service providers.

Until now, there was a unified template for reporting only DDoS attacks and ransomware. The updated version adds a new "General Template for Other Cyberattacks" that will cover all other cases, in line with an amendment to an inter-agency agreement from May 2025.

During a transitional period lasting until the end of March 2027, companies can continue using the old format, and the Financial Services Agency (FSA) is accepting public comments until 5:00 PM on September 7th.

Part of a Broader Cryptocurrency Reform

These two steps are being taken against the backdrop of Japan's complete overhaul of its approach to digital assets. As Cryptopolitan reported, on August 6th, the Financial Services Agency (FSA) also established a dedicated crypto assets and stablecoins unit within a new supervisory bureau, replacing disparate office-level units that previously handled the sector.

This follows a law enacted in July that reclassifies cryptocurrency as a financial product under the Financial Instruments and Exchange Act, reduces the maximum tax on trading profits to a fixed 20% from January 1, 2028, and lays the groundwork for domestic spot ETFs. Collectively, the actions taken this week indicate a further integration of cryptocurrency into Japan's mainstream financial oversight framework.

end-content

Related Questions

QWhat is the primary goal of the new guidelines issued by Japan's Financial Services Agency (FSA) for cryptocurrency exchanges?

AThe primary goal is to combat fraud and enhance cybersecurity. The guidelines introduce measures to slow down the withdrawal of suspicious funds and standardize the reporting process for cyberattacks.

QWhat specific measure did the FSA and National Police Agency propose to delay the movement of funds suspected to be from fraud?

AThey proposed that exchanges should allow funds to remain in a flagged account for a specific period before withdrawal, require pre-registered recipient addresses for withdrawals, and enforce waiting periods for transfers to newly added addresses.

QHow many sectors will be covered by the FSA's revised standardised reporting rules for cyberattacks and system failures?

AThe revised standardized reporting rules will cover 17 sectors, including cryptocurrency asset exchange service providers.

QWhat broader legislative change in Japan supports the FSA's recent regulatory actions on cryptocurrency?

AA law enacted in July reclassifies cryptocurrency as a financial product under the Financial Instruments and Exchange Act, reduces the maximum capital gains tax to a flat 20% from 2028, and lays the groundwork for domestic spot ETFs.

QWhat internal organizational change did the FSA make to better supervise the crypto sector?

AThe FSA established a dedicated crypto-asset and stablecoin unit within a new supervisory bureau, replacing the scattered office-level units that previously handled the sector.

Related Reads

Trading

Spot
活动图片