TL;DR
- Japan’s FSA and National Police Agency asked crypto exchanges to delay withdrawals after fiat deposits or digital asset purchases to disrupt fraud.
- Exchanges were also urged to pre-register withdrawal addresses, impose waiting periods on new addresses, strengthen monitoring, and use phishing-resistant multifactor authentication.
- The measures are not binding rules, allowing each platform to tailor implementation to its services and risk exposure while authorities push for stronger safeguards against fraudulent transfers.
Japan’s financial regulator is urging cryptocurrency exchanges to make withdrawals deliberately slower, an unusual security approach aimed at disrupting scams before stolen funds disappear. The Financial Services Agency, working with the National Police Agency, asked platforms to introduce waiting periods after users deposit fiat currency or buy digital assets, as concerns continue to grow. The central idea is striking: adding friction could become a defense against fraud in a market built around speed. Authorities said losses among exchange users are increasing, while funds obtained through fraudulent schemes are being transferred into crypto exchange accounts.
Japan’s anti-fraud push targets multiple points of vulnerability
The request, submitted to the Japan Virtual and Crypto Assets Exchange Association, also targets the moment when users add withdrawal destinations. Exchanges were asked to require customers to register crypto addresses in advance and apply a waiting period before newly added addresses become usable under the proposed framework. Japan’s proposed safeguards effectively treat sudden withdrawal changes as a potential warning sign rather than a routine transaction. That could give platforms more time to detect suspicious activity before assets move beyond reach, although the regulator did not prescribe one mandatory technical model for every exchange.
Authorities also want exchanges to introduce customer-specific withdrawal limits, strengthen monitoring of transactions and access environments, and deploy multifactor authentication designed to resist phishing. Another proposed check would compare the name of a bank remitter with the name of the holder of the crypto account receiving funds across the customer journey itself. The broader package shows regulators focusing not on one vulnerability, but on multiple points where fraud can exploit ordinary user behavior. The measures combine identity verification, transaction controls and account-security checks, suggesting that preventing scams may require overlapping defenses rather than relying on a single safeguard.
Crucially, the proposals are requests rather than binding rules. The FSA said each exchange should decide how to implement the measures according to its operations, services and exposure to misuse, without imposing a uniform formula. That flexibility creates an unusual balance between regulatory pressure and platform discretion, leaving exchanges responsible for translating broad anti-fraud goals into practical controls. The result could vary from one platform to another, but the message from Japanese authorities is clear: faster withdrawals are not always safer, and delaying transactions may sometimes provide the window needed to stop fraudulent transfers.






