レポート一覧に戻る
Regulatory Compliance
Crypto Asset Exchange Service Providers
Anti-Money Laundering
Financial Infrastructure
Risk Management
2026年08月06日

The Request That Never Says How Long: Japan's Eleven-Point Withdrawal Restriction Demand on Crypto Exchanges

「一定期間」が書かれていない要請——出庫制限11項目が暗号資産事業者に突きつけたもの

Most of the Eleven Points Are Transplanted Banking Practice

Listing the contents makes their character clear: strengthened fraud prevention and fact-finding at account opening; verification and warnings to prevent fraud losses; withdrawal restrictions for a set period after fiat deposit or crypto purchase; advance registration of withdrawal destinations with a subsequent restriction period; appropriate withdrawal limits; enhanced transaction and access-environment monitoring; faster customer verification, transaction restriction and account freezing after detecting suspicious activity; strengthened authentication where impersonation is suspected; matching of remitter names against account holder names; information sharing among operators; and enhanced information provision to and coordination with police.

Specific measures include building mechanisms to verify the authenticity of identity documents, implementing and mandating phishing-resistant multi-factor authentication, applying detection scenarios keyed to current fraud patterns, detecting transactions from the same device or access environment as accounts confirmed to be misused, and establishing capacity to impose restrictions promptly at night and on holidays.

Most of this is a transplant of practice that banks built over nearly two decades responding to wire fraud. Remitter name matching, limit management, and scenario-based monitoring are close to standard equipment in banking. Crypto exchanges are now being asked to reach the fraud-control standard of deposit-taking institutions without the staffing or institutional history those institutions possess.

The One Genuinely New Element Is the Destination Registry

The item without a direct banking analogue is the fourth: advance registration of withdrawal destinations. The request calls for registering destination information in advance, checking it for connections to fraud, preventing withdrawal where such a connection is found, and imposing a temporary restriction on newly registered destinations.

In substance this asks each exchange to operate a whitelist of blockchain addresses alongside a reference database of fraud-linked addresses. The former can be built in-house; the latter cannot. Determining which addresses are fraud-linked requires cross-industry data and law enforcement data to be accurate. That is precisely why the tenth item on inter-operator information sharing and the eleventh on police coordination sit in the same request. Who holds the authority and the data to adjudicate a withdrawal destination is an open question the request leaves unanswered.

"A Set Period" Is Never Defined

The phrase recurring throughout the request is never given a number of days. Nor is any guidance offered on withdrawal limits. The request states at the outset that the method and depth of measures should be determined according to each operator's business and services and the incidence of misuse, and that where system work makes immediate implementation difficult, a planned approach is important. No reporting deadline is set.

Leaving discretion has a rationale. Imposing a uniform period on operators with different assets and customer bases would produce over-regulation and under-regulation simultaneously. But discretion has a side effect. Tighter restrictions degrade customer experience; looser ones confer competitive advantage. When every operator receives the same request but sets its own parameters, activity gravitates toward whoever chooses the loosest setting—and so, disproportionately, does fraudulent money. The request's explicit statement that operators with inadequate measures are more likely to be targeted by criminals reflects awareness of exactly this dynamic. In practice, the months before an informal industry norm settles will be the hardest period in which to make decisions.

Partial precedent exists domestically. bitFlyer already restricts transfer of assets equivalent to deposits made via Pay-easy or convenience stores for 168 hours. That measure, however, is confined to specific deposit channels and is far narrower in scope than the comprehensive restriction now requested.

The Same Week, Brazil Chose the Opposite Drafting

A contrasting case appeared in the same week. On August 7, 2026, the Central Bank of Brazil published Resolution 584, extending fraud prevention rules for payment services to virtual asset services. Transfers exceeding $10,000 in a single transaction or in a customer's same-day aggregate, when directed to overseas virtual asset providers or self-custody wallets, must be held for up to 24 hours while a risk assessment is performed. The rule takes effect January 1, 2027, delayed by a year from the original October 2026 proposal. The central bank retains authority to set periods beyond 24 hours and to extend coverage below the $10,000 threshold.

Japan's request and Brazil's resolution are opposite solutions to the same problem. Japan issued a non-binding request with no threshold, no period, and no deadline, delegating judgment to operators. Brazil issued a binding resolution specifying the monetary threshold, the maximum hold, the effective date, and its reserved future discretion. The former is flexible but lacks predictability; the latter is rigid but supports investment decisions. For Japanese operators, the practical difficulty is that the numbers required for a system investment decision have not been provided.

Business Development Insights

  1. The premise of instant settlement in onchain finance is being deliberately dismantled from the regulatory side. Withdrawal restrictions and destination pre-registration both amount to designing latency into payment. Around-the-clock instant finality has been a central value proposition of crypto infrastructure; if multi-day waiting becomes standard at the exchange gateway, practical scenarios for onchain finance including DeFi connectivity and RWA trading require reconsideration from first principles. Firms whose product design assumes exchange connectivity should treat "lead time from deposit to withdrawal availability" as an explicit design variable. This matters particularly for corporate payment and treasury flows built on stablecoins, where an exchange-mediated funding path can become the binding constraint.
  2. No one has yet been designated to operate the data infrastructure that adjudicates withdrawal destinations. That inter-operator information sharing and police coordination appear in the same request is the flip side of requirements individual firms cannot meet alone. A shared database of fraud-linked addresses, its update and false-positive handling, and the legal basis for sharing under personal information protection law are naturally built as common industry infrastructure. Whether a blockchain analytics provider, the industry association, or a newly formed joint body takes that role is undetermined, making this one of the few clearly vacant layers in Japan. For firms considering entry, connectivity to law enforcement and cross-industry consensus-building are the barriers—and equally the source of first-mover advantage.
  3. A request with undefined parameters risks delaying compliance investment decisions. With no restriction period, monetary threshold, or reporting deadline specified, each firm must define for itself what constitutes sufficiency. Where numbers are explicit, as in Brazil, system investment and implementation schedules can be derived mechanically. Japan's design does not permit that, and a wait-and-see posture becomes likely. The effective approach here is to complete a gap analysis mapping the eleven items against current controls first, and for items with undefined parameters, secure only the implementation feasibility across multiple scenarios in advance. Firms that wait for an industry norm to settle before starting will be reliably behind.

Sources

Supervisor

Akihisa Ishida

Cabinet Inc. Founder CEO

Since 2017, He has been consistently engaged in token and NFT utilization, blockchain game planning and development, and NFT-based business development. Having contributed to over 80 blockchain products—including projects for major entertainment companies listed in Tokyo Stock Exchange —He has served in various key roles such as Business Lead, Designer, PM, and Advisor. In 2021, founded Cabinet Inc.

Disclaimer

This report has been prepared solely for informational purposes regarding crypto assets and related markets, and is not intended to recommend, solicit, or offer the purchase, sale, holding, or any other transaction of any specific crypto asset. It does not constitute investment advice, investment solicitation, or the sale or intermediation of financial products as defined under the Financial Instruments and Exchange Act or any other applicable laws and regulations, nor does it constitute tax, legal, or accounting advice.

The information contained in this report is based on sources believed to be reliable at the time of preparation; however, we make no representation or warranty, express or implied, as to its accuracy, completeness, timeliness, or usefulness. Crypto assets are subject to significant price volatility and may result in the loss of principal or other financial losses. Any investment decision shall be made solely at the user's own discretion and responsibility, and we accept no liability whatsoever for any damages arising out of or in connection with the use of this report.

Blockchain Business Consultation

From idea-stage brainstorming and technical validation (PoC) to implementation and operations, Cabinet provides end-to-end business development consulting. Start with a free consultation today.

Sign Up for Newsletter

Beyond the content of this report, we will deliver the latest industry information and exclusive reports by email.