On August 6, 2026, Japan’s Financial Services Agency asked the Japan Virtual and Crypto Assets Exchange Association to ensure that every crypto-asset exchange strengthens its measures against fraud.
The request responds to rapidly increasing social-media investment and romance scams, the growing use of crypto to transfer victims’ funds, and the targeting of non-face-to-face services and firms with weaker controls. Its significance lies in timing: the FSA is emphasizing intervention before a suspicious withdrawal is completed, not only reporting and investigation after the event.
What the FSA Asked Every Crypto Exchange to Do
The FSA request lists eleven measures. Their application should reflect each firm’s business, services, and history of misuse, and the agency recognizes that system changes may require a planned implementation period.
The measures cover the full customer and transaction lifecycle:
- Strengthen identity-document verification, examine the actual purpose of account opening, warn that account trading is a crime, and apply enhanced checks to higher-risk customers.
- Warn customers that opening an account, purchasing crypto, or withdrawing crypto at another person’s direction carries a high fraud risk.
- Consider delaying or restricting crypto withdrawals for a period after a fiat deposit or crypto purchase, and inspect rapid, high-value, or repeated withdrawals.
- Pre-register destination wallet addresses, check them for fraud links, block associated addresses, and delay transfers to newly registered addresses.
- Apply risk-based withdrawal limits and review them dynamically.
- Strengthen monitoring of transactions and access environments using current scam scenarios, customer profiles, device data, common attributes, and unusual access patterns.
- Rapidly contact customers, hold or restrict transactions, freeze accounts where appropriate, maintain night and holiday response, and file suspicious transaction reports when required.
- Use stronger, phishing-resistant authentication where impersonation is suspected.
- Match the name of the person sending fiat with the crypto account holder.
- Share scam patterns, methods of account misuse, and response cases among exchanges.
- Provide information quickly to police and strengthen cooperation.
The request is not a statute, and it does not prescribe one identical control for every firm. Nevertheless, it gives exchanges a clear supervisory signal: customer friction—including withdrawal delays—may be expected where it is justified by fraud risk.
What Japan’s 2025 AML Data Reveals
This episode uses both JAFIC’s annual report and the separate National Risk Assessment. They serve different purposes.
The JAFIC Annual Report 2025 reports 1,019,405 suspicious transaction notifications across all covered sectors in 2025. Crypto exchanges accounted for 44,335, up from 22,667 in 2024—an increase of approximately 95.6%. An STR is a risk signal supplied for analysis; it is not proof that a crime occurred.
STR information led to 1,110 detected cases and supported another 3,026 cases after investigations had already begun. Fraud-related offenses accounted for 960, or 86.5%, of the cases initiated through STR information. Those offenses included fraudulent acquisition or transfer of bank and crypto accounts, social-media investment and romance scams, fake-police scams, and refund scams.
Separately, Japan recorded 1,777 money-laundering cases under the Organized Crime Punishment Act in 2025, up 515 cases or 40.8% from the previous year. Fraud was the most common predicate offense, with 795 cases, followed by theft and computer fraud.
The annual report describes a concrete crypto-related case. Members of a special-fraud group used OTC trading to process crypto purchased with criminal proceeds. They routed it through an overseas exchange, swapped it into another crypto asset, sent it to another wallet, and exchanged it for cash. They were arrested for concealment of criminal proceeds.
This helps distinguish two related but separate stages. A victim who is deceived into sending crypto has suffered crypto-enabled fraud. Money laundering involves acts that conceal or disguise the origin, ownership, or destination of the resulting criminal proceeds.
The 2025 National Risk Assessment adds broader typologies, including fraud proceeds converted into crypto through corporate bank accounts and cash moved through multiple wallets before OTC cash-out.
Current AML/CFT Duties for Crypto Exchanges
Crypto exchanges are specified businesses under the Act on Prevention of Transfer of Criminal Proceeds. Their current duties include:
- customer identification and verification, including verification of beneficial owners for legal entities;
- preparation and retention of verification and transaction records;
- ongoing, risk-based customer management and updating of customer information;
- assessment and filing of suspicious transaction reports; and
- transmission of originator and beneficiary information under the Travel Rule for covered transfers to other regulated providers.
The STR obligation requires judgment. The FSA’s reference cases are indicators, not automatic filing rules. A firm must consider the customer’s attributes, the circumstances and purpose of the transaction, other information it holds, and whether that information is current. A pattern can justify enhanced review or a temporary restriction without proving that the customer committed money laundering.
This is where the August request deepens the operational model. The same customer and transaction data used for ongoing due diligence and STR analysis must now support fast fraud intervention: contacting the customer, holding the transfer, changing authentication requirements, or freezing the account where appropriate. Those actions need escalation criteria, delegated authority, evidence retention, and coverage outside ordinary business hours.
What the July Legal Reform Changes—and What It Does Not
Japan enacted an amendment in July 2026 that will move the main regulation of crypto-asset trading from the Payment Services Act to the Financial Instruments and Exchange Act. The law was enacted on July 15 and promulgated on July 23. Its main crypto provisions are not yet in force and will take effect on a date specified by Cabinet Order within one year.
The reform builds a financial-market framework around crypto. It introduces information disclosure, suitability and business-control requirements, market surveillance, and rules against unfair trading.
It should not be described as a new AML law. Crypto exchanges are already specified businesses under the Act on Prevention of Transfer of Criminal Proceeds. Their duties include customer due diligence, recordkeeping, suspicious transaction reporting, and transmitting originator and beneficiary information under the Travel Rule.
The August anti-fraud request, the existing AML/CFT regime, and the coming FIEA framework therefore need to be mapped separately—even when the same workflow or system supports all three.
Crypto and Money-Laundering Risk in Real-Estate Transactions
The exchange is not the only place where crypto-related money-laundering risk appears. On April 28, the FSA, Ministry of Finance, Ministry of Land, Infrastructure, Transport and Tourism, and National Police Agency jointly requested action from real-estate and crypto industry groups.
The request highlighted several distinct legal and compliance risks.
First, a business that receives crypto from a real-estate agent or buyer and pays fiat to a seller may be providing crypto-exchange services without registration, depending on the structure. Calling the service “settlement support” does not determine its legal character.
Second, crypto exchanges were asked to apply stricter transaction verification where suspicious circumstances exist—for example, when a customer receives a property purchase price in crypto and attempts a high-value transaction inconsistent with the customer’s profile. Firms should file an STR with the competent authority where required and notify police when criminal activity is suspected.
Third, the request addressed reporting under the Foreign Exchange and Foreign Trade Act. A person receiving more than ¥30 million equivalent in crypto or other value from overseas may need to file a payment-receipt report. A non-resident acquiring Japanese real estate also has a reporting obligation; for acquisitions from April 1, 2026, the stated acquisition purpose does not remove that requirement.
For transaction monitoring, this creates an important source-of-funds and source-of-wealth question. A large incoming crypto transfer may be genuine property-sale proceeds, fraud proceeds presented as a sale, or part of a structure involving an unregistered intermediary. Wallet screening alone cannot distinguish them. Exchanges may need the sale agreement, property details, counterparty information, payment path, economic rationale, and cross-border status.
What International Firms Should Review Before Entering Japan
International exchanges, stablecoin companies, and compliance providers should test whether their Japan operating model can:
- verify the real purpose of an account and apply enhanced controls to high-risk customers;
- explain and document why a transaction or address was flagged;
- delay or restrict a withdrawal without losing the audit trail;
- contact customers and make escalation decisions outside normal business hours;
- combine customer, transaction, wallet, device, and access information;
- validate source of funds and economic purpose where crypto is linked to a property transaction;
- determine whether a settlement structure may involve unregistered exchange activity; and
- distinguish obligations under the FSA request, the existing AML/CFT statute, the foreign-exchange reporting regime, and the coming FIEA framework.
Japan’s direction is not simply “more monitoring.” It is an earlier intervention, backed by clearer operating responsibility.
If Japan is part of your expansion plan, Wakyodo can help identify the regulatory, operational, and partnership gaps before implementation.
