Japan's FSA Tightens Crypto Exchange Rules on Fraud Prevention and Cybersecurity Reporting
Key Takeaways
- •The FSA and National Police Agency issued 11 anti-fraud directives to the JVCEA on August 6, including mandatory holding periods for flagged accounts and pre-registration requirements for withdrawal addresses.
- •A draft revision published on August 7 proposes a standardized cyberattack reporting template covering all attack types across 17 sectors, including crypto exchanges.
- •The FSA noted that each exchange retains discretion over how it implements the anti-fraud recommendations based on its operational structure and risk exposure.
- •The FSA established a dedicated Crypto Assets and Stablecoins Division on August 6, consolidating oversight previously handled by dispersed office-level units.
- •Legislation passed in July reclassifies cryptocurrency as a financial product, reduces the top tax rate on trading gains to a flat 20% starting January 2028, and lays groundwork for domestic spot ETFs.

Japan's Financial Services Agency (FSA) has moved forward with new regulatory measures this week, setting out rules for how cryptocurrency exchanges should report cyberattacks and process withdrawals that raise fraud concerns.
According to local reports, the regulator's latest recommendations include a standardized reporting form for exchanges and other technology sectors to escalate security breaches through proper channels. A second set of guidelines addresses how platforms handle Japanese users' funds, particularly when transactions exhibit red flags associated with fraudulent activity.
Slowing the Movement of Stolen Funds
On August 6, Japan's National Police Agency and the FSA issued a directive to the Japan Virtual and Crypto Assets Exchange Association (JVCEA) — the industry's self-regulatory body — outlining 11 anti-fraud measures.
The directive targets accounts implicated in fraud proceedings and restricts their ability to transfer funds. Under the recommendations, exchanges must hold funds in flagged accounts for a designated period before withdrawals can be processed. Additionally, funds may only be sent to destination addresses that have been pre-registered. Account holders would be required to wait through a cooldown period before transfers to newly added addresses can be executed.
The agencies also called on exchanges to establish withdrawal limits based on customers' asset holdings and risk profiles. Further proposed requirements include multi-factor authentication and name-matching on incoming bank transfers when phishing or impersonation attempts are suspected.
Monitoring protocols would also be strengthened, enabling faster account freezes for transactions that appear fraudulent and expedited information-sharing with prefectural police.
The FSA noted that each exchange retains discretion over how it implements these recommendations, depending on its operational structure and risk exposure.
Regulatory Rationale
The FSA's objective is to introduce friction into the rapid movement of illicitly obtained funds off platforms under its jurisdiction. According to the agency's statement, it is addressing "growing losses among crypto exchange users and cases where funds obtained through fraudulent schemes are being transferred to exchange accounts."
Once funds leave exchanges and are stored in wallets outside Japanese jurisdiction, the probability of recovery approaches zero. The emphasis on building delays and verification steps into withdrawal workflows reflects lessons from earlier incidents in Japan's crypto market, where high-profile exchange breaches — including the 2014 collapse of Mt. Gox and the 2018 Coincheck hack — prompted lawmakers to tighten operational standards and spurred the creation of the JVCEA as an industry self-regulatory body.
Unified Reporting Across 17 Sectors
On August 7, the FSA published a separate draft revision to its supervisory guidelines that would standardize how firms report cyberattacks and system failures. Crypto asset exchange providers are among 17 sectors covered, according to CoinPost.
Previously, a shared reporting template existed only for DDoS attacks and ransomware incidents. The revision introduces a new "Common Template for Other Cyberattack Incidents" to cover all other attack types, following a May 2025 amendment to an inter-ministerial agreement.
Firms may continue using the previous format during a transitional period extending through the end of March 2027. The FSA is accepting public comment on the draft until 5 p.m. on September 7.
Part of a Broader Crypto Overhaul
These measures arrive as Japan undertakes a comprehensive overhaul of its digital asset framework. On August 6, the FSA also established a dedicated Crypto Assets and Stablecoins Division within a new supervisory bureau, as reported by Cryptopolitan, replacing the dispersed office-level units that had previously overseen the sector.
This follows legislation passed in July that reclassifies cryptocurrency as a financial product under the Financial Instruments and Exchange Act, reduces the top tax rate on trading gains to a flat 20% effective January 1, 2028, and establishes the foundation for domestic spot ETFs. The tax reduction and ETF framework place Japan alongside a small group of jurisdictions — including the United States, Hong Kong, and Australia — that have moved to lower barriers to retail and institutional crypto participation through regulatory clarity and product approval pathways. Collectively, the week's actions signal Japan's continued integration of cryptocurrency oversight into mainstream financial supervision.