Japan’s Financial Services Agency (FSA) advanced its regulatory march this week with a new set of rules on how it expects crypto exchanges to report cyberattacks and handle withdrawals flagge
Japan’s Financial Services Agency (FSA) advanced its regulatory march this week with a new set of rules on how it expects crypto exchanges to report cyberattacks and handle withdrawals flagged for scams.
Per local reports, the latest recommendations that the regulator is pushing include a single form format for exchanges, as well as other tech sectors, to escalate breaches to the proper channels. The other involves how platforms move Japanese users’ funds, especially when they carry fraud red flags.
Japan is slowing down how stolen money moves
Japan’s National Police Agency and the FSA listed out 11 anti-fraud steps in an August 6 directive to members of the Japan Virtual and Crypto Assets Exchange Association (JVCEA), the industry’s self-regulatory body.
The instructions contained actions targeting accounts implicated in fraud proceedings and their ability to send out funds.
First, exchanges need to allow funds sit in a flagged account for a set amount of time before withdrawals can start to go through. Also, funds can only be sent to destination addresses that have been registered in advance. The account operator would need to wait through a cooldown period before transfers can be processed into newly added addresses.
The agencies also asked the exchanges to set withdrawal limits based on customers’ holdings and risk profiles.
Other requirements, such as multi-factor authentication and matching names on incoming bank transfers, were also proposed when phishing or impersonation attempts are suspected.
Monitoring would tighten too, with faster freezes when a transaction looks fraudulent and quicker information-sharing with prefectural police.
Each exchange has discretion over how it applies these recommendations based on its own operations and exposure, the FSA said.
Why Japanese regulators want to slow down withdrawals
The FSA wants to throw hurdles into the fast lane that currently exists between criminals acquiring and moving funds off platforms under its oversight.
According to the agency’s statement, it is tackling “growing losses among crypto exchange users and cases where funds obtained through fraudulent schemes are being transferred to exchange accounts.”
Once funds are off-ramped from exchanges and parked in wallets outside Japanese jurisdiction, the chances of a plummet are near zero.
A day later, on August 7, the FSA published a separate draft revision to its supervisory guidelines that would standardize how firms report cyberattacks and system failures. Crypto asset exchange providers are among 17 sectors covered, CoinPost reported.
Until now, a shared reporting template existed only for DDoS attacks and ransomware. The revision adds a new “Common Template for Other Cyberattack Incidents” to capture everything else, following a May 2025 amendment to an inter-ministerial agreement.
Firms can keep using the old format during a transitional period that runs to the end of March 2027, and the FSA is taking public comment until 5 p.m. on September 7.
Part of a wider crypto overhaul
The two moves land as Japan reworks its whole approach to digital assets. On August 6, the FSA also stood up a dedicated Crypto Assets and Stablecoins Division under a new supervisory bureau, Cryptopolitan reported, replacing the scattered office-level units that had handled the sector.
That sits alongside a law passed in July that reclassifies crypto as a financial product under the Financial Instruments and Exchange Act, cuts the top tax on trading gains to a flat 20% from January 1, 2028, and lays the groundwork for domestic spot ETFs. Taken together, the week’s actions read as Japan folding crypto further into mainstream financial supervision.
Don’t just read crypto news. Understand it. Subscribe to our newsletter. It's free.