TL;DR
- South Korea’s CBDC pilot completed live payments across more than 80,000 wallets with no independent post-launch security audit.
- The only formal evaluation was conducted by the participating banks themselves before launch, with no intervention from external bodies.
- Phase 2 of the program scales to 500,000 users and incorporates programmable payments and biometric authentication.
South Korea’s Bank of Korea CBDC pilot project completed thousands of real transactions without any external body auditing its security after launch, according to documents submitted by the Financial Supervisory Service to the office of representative Lee Hun-seung on July 20.
The only formal evaluation of the CBDC was conducted before the system went live, carried out by the internal teams of Woori Bank and NH Nonghyup Bank, with assistance from the Financial Security Institute and SK Shields.
The pilot, known as Project Hangang, processed 114,880 transactions across approximately 81,000 digital wallets and around 12,000 merchants during its first phase, between April and June 2025. However, only 42% of users managed to complete a payment. Participating banks invested between 30 billion and 35 billion won in building the infrastructure.
Why Nobody Audits the CBDC
The Bank of Korea justified the absence of external inspections by stating, in footnote 10 of its pilot report, that pre-launch evaluations were sufficient. Maeil Business Newspaper noted that, in practice, the operator was left in charge of evaluating the security of its own operation.
An industry official quoted by that outlet warned that “the real-transaction pilot is a process of building public trust, not just technological verification”, and that it is problematic for the same organization to create, test and certify the security of its own CBDC system.
This dynamic is far from a technical flaw: it is the very nature of central bank digital currencies. A CBDC is not a decentralized cryptocurrency or an instrument of financial freedom. It is a programmable state control tool, capable of restricting uses, imposing expiration dates or conditioning subsidies. That the State audits its own financial surveillance instrument should come as no surprise.
Phase 2 Will Strengthen Government Control
The Financial Services Commission approved on July 15 the expansion of the project. Gyeongnam Bank and iM Bank are being added, bringing the total to nine institutions. The wallet limit rises from 100,000 to 500,000 users, and the individual amount increases from 1 million to 10 million won. New features include person-to-person transfers, biometric authentication, automatic top-ups and programmable government subsidy payments.
This last point encapsulates the central risk of CBDCs: a State that can program when, where and on what subsidies are spent is not modernizing its payment system. It is building a financial control architecture that, once normalized at a scale of 500,000 users, will be difficult to reverse.







