Japan FSA Crypto Cybersecurity Report: What CASPs Must Map Now
The Deloitte Tohmatsu LLC research report is dated 30 June 2026, and the FSA added it to its public research page on 23 July 2026 under the title “Cybersecurity Issues and Countermeasures in Crypto-Asset-Related Businesses.” It sits under the FSA’s Blockchain Governance Initiative Network (BGIN) research track and follows the JFSA’s April 2026 Policy for Strengthening Cybersecurity in Crypto-Asset Exchange Services. For compliance and security teams at Japan-registered crypto-asset exchange service providers, the report is the clearest signal so far of where the FSA intends to take its supervisory guidelines next.
Japan FSA crypto cybersecurity expectations are shifting away from a narrow focus on protecting signing keys and toward the whole chain of systems, people, and outside vendors that surround a transaction. The report analyses recent large-loss incidents, maps the crypto ecosystem as a supply chain, and extracts five priority areas that it says operators should specify and deepen in their own controls. None of it is binding on its own. All of it points at the questions a Japanese supervisor is now equipped to ask.
Related reading: MiCAR reporting obligations
A research report, not a new rulebook
The first thing to fix is status. The document is a contractor research report. Its own front matter states that its contents do not represent the official views of the FSA, and that its case studies were organised for research purposes from publicly available material and not as any attribution of legal responsibility. Reading it as if a new binding standard had dropped would be a mistake, and it would set up the wrong internal conversation with the board.
What the report does carry is direction. It says explicitly that it takes into account the intent of the JFSA’s April 2026 Policy for Strengthening Cybersecurity in Crypto-Asset Exchange Services, examines the areas where crypto-asset exchange service providers should place greater emphasis, and aims to derive insights for the revision of the supervisory guidelines. The research status and contents were discussed, and expert advice was received, at the JFSA Blockchain Roundtable during Japan Fintech Week 2026 and at the BGIN Block #14 meeting. That combination of provenance is why it deserves attention: it is the analytical spadework that tends to precede a guideline update, and it names the control areas that update is likely to touch.
For a compliance function, the practical move is to treat the report as a gap-analysis input rather than a compliance deadline. Map your current control set against its five priority areas, record where you already meet the described practice, and log where you rely on an assumption you cannot yet evidence. If and when the FSA Administrative Guidelines are revised, that mapping becomes the head start.
The dates that anchor this guidance
Several dates matter for how a Japanese CASP should sequence its reading, and they separate binding instruments from research and policy signalling.
- 10 February to 11 March 2026: JFSA public consultation on the draft policy to strengthen cybersecurity among crypto-asset exchange operators, which drew 18 public comments.
- April 2026: the JFSA finalised its Policy for Strengthening Cybersecurity in Crypto-Asset Exchange Services, built around self-help, mutual-help, and public-help measures.
- 30 June 2026: date shown on the Deloitte Tohmatsu research report; 23 July 2026: addition of the report to the FSA’s public research page.
- 1 June 2026: section 16 of the FSA Administrative Guidelines, Third Volume (Financial Companies), was amended and applied. The research report benchmarked the 1 April 2025 edition, but that edition is not the current version. The Administrative Guidelines set supervisory viewpoints rather than constituting legislation.
- June 2025: the version of the JVCEA Crypto Asset Security Management Standard benchmarked in the report. Separately, new JVCEA rules and guidelines on system governance for cryptocurrency exchange operations took effect on 1 July 2026; verify against current JVCEA notices whether further rule areas (such as system-risk management, emergency response, information security, or user-asset management) were also updated and must be included in a current-state mapping.
- 26 January 2026: the JPCrypto-ISAC Guidelines for Management of Contractors in Crypto-Assets-Related Businesses, a supply-chain and contractor-security reference the report leans on.
The report itself sets no reporting deadline, no remittance date, and no first reference date. Anyone who tells the business that “the FSA has set a new June 2026 cybersecurity deadline” has misread it. The operative framework comprises statutory and implementing requirements under the Payment Services Act, FSA supervisory viewpoints in the Administrative Guidelines, and applicable JVCEA self-regulatory rules for association members.
Why signing-adjacent systems now require equal attention
The report broadens the threat model beyond signing-key theft. In sampled cases, attackers tampered with user interfaces, APIs, CI/CD pipelines, unsigned-transaction generation logic or production programs and then abused legitimate signing processes to cause fund outflows. The report’s infrastructure-attack category also includes compromises of private keys and seed phrases, so it does not conclude that signing keys have ceased to be a primary target.
The scale data the report assembles from third-party trackers makes the point. Citing TRM Labs, it records that illicit crypto volume reached an all-time high of about USD 158 billion in 2025, of which roughly USD 2.87 billion was stolen across around 150 hacking and exploitation incidents, with the top ten incidents accounting for 81 percent of the annual total. The single February 2025 Bybit breach, at about USD 1.5 billion, made up roughly half of everything stolen that year. On TRM’s classification, infrastructure attacks that target keys, wallet infrastructure, privileged access, and front-end surfaces drove around USD 2.2 billion of losses, some 76 percent, across only 45 incidents, an average close to USD 48.5 million each.
Drawing on SlowMist data for incidents since 2023, the report highlights that third-party vulnerabilities produced the largest single loss category, roughly USD 1.59 billion, from only 17 recorded events. That asymmetry, low frequency and very high severity, is the operational headline. A control programme tuned to stop many small incidents can still be blind to the rare supplier compromise that empties a cold wallet.
Bybit is the archetype the report walks through in detail. On its account, an attacker compromised the development environment of the external wallet service used by the exchange and tampered with its transaction-generation interface. The compromised computer interface displayed the intended transaction, but the hardware wallet displayed the malicious transaction details. The signers did not sufficiently verify those details before signing. The signed transaction upgraded the cold-wallet contract and drained it; no signing key was stolen.
How Japan’s existing crypto framework already frames the risk
Japan does not regulate crypto exchanges through a general “all firms” cyber rule. The obligations sit in a specific stack, and getting the instrument right matters for any control narrative you present to the FSA. Crypto-asset exchange service providers must register with the FSA under the Payment Services Act, the regime that has governed crypto-asset exchange services since the 2017 amendments. Day-to-day self-regulation, including rules on user-property management, runs through the Japan Virtual and Crypto assets Exchange Association, the certified self-regulatory organisation established under the Act. This two-layer design, a statutory supervisor plus a certified self-regulator whose standards are read into supervision, is a defining feature of the Japanese model and one the report relies on throughout.
On asset custody, user crypto-assets must in principle be managed in cold wallets. Hot-wallet management is permitted only to the minimum extent necessary for operations, and the operator must separately hold crypto-assets of the same type and quantity as those managed online. That cold-storage discipline is exactly the control the report says is necessary but no longer sufficient. Bybit held funds in a cold wallet and still lost them: the attack corrupted the authorisation process for movement out of cold storage, bypassing cold-wallet discipline without touching the keys themselves.
The report’s own mapping of observed attack methods against existing references, including NIST CSF 2.0, the FSA Guidelines on Cybersecurity for the Financial Sector, the FISC Security Measures Standard, the FSA Administrative Guidelines for crypto-asset exchange service providers, the JVCEA Crypto Asset Security Management Standard, and OWASP SCSVS, concludes that the guidelines already cover the risky areas. The gap it identifies is depth and operator understanding, not absent rules. Operators, it says, need to specify and deepen controls according to their own system configuration, outsourcing relationships, wallet and key management methods, and use of DeFi and external services. In supervisory terms, that is a shift from “do you have a policy” to “can you show the control works against this specific attack path.”
The five priority areas in Japan’s FSA crypto cybersecurity report
The report extracts five priority areas from its analysis. Each is a place where a Japanese CASP can expect harder supervisory questions, and each carries a trap that a checklist reading would miss.
Third-party and supply-chain risk management
The report treats supplier compromise as a direct route to the operator’s own asset loss, well beyond a peripheral vendor issue. It recommends periodic assessment of a provider’s security posture across phishing and malware countermeasures, production-environment access control, CI/CD management, cloud IAM and KMS management, program-change management, and log monitoring, plus least-privilege and just-in-time access, short-lived credentials, and immediate revocation of access on project completion, including for subcontractors. The trap is multi-level outsourcing. When a vendor re-contracts to a sub-vendor, the chain becomes a black box, and the report is direct that sub-outsourcing must be confirmed and supervised, never left to trust. A SOC 2 report whose scope excludes a signing-adjacent component leaves that component unassessed, so the exclusions have to be read.
Preventing malicious code injection and program tampering
Because the losses ran through tampered UIs, APIs, and pipelines, the report asks for controls that explicitly target unauthorised change: strict production-credential management, rigorous CI/CD review, software bills of materials, integrity verification of source code and files, validation of API responses, network segmentation, segregation of duties, hardware-backed credentials, elimination of standing administrator access, and multi-party approval for high-risk changes such as KMS policy modifications. It also suggests version pinning and prohibiting automatic execution when pulling in external libraries, so a poisoned dependency cannot run unchecked.
Preventing unauthorised transfers of crypto-assets
The report calls for layered controls over transfer transactions that go beyond multi-signature and hardware wallets: additional approvals keyed to amount, frequency, new destination addresses, unknown contracts, privilege changes, and large withdrawals; delayed execution; offline signing; transaction simulation; technical review of decoded transaction data; and design that limits damage even when a control is bypassed, through per-address holding limits, withdrawal limits, abnormal-withdrawal detection, and automatic suspension or circuit breakers.
Smart contracts and DeFi
Here the report challenges a widely held assumption. A protocol’s risk profile continues to evolve after a smart-contract audit completes, through post-deployment operations, administrator and upgrade privileges, oracle settings, risk parameters, and cross-chain configuration; residual risk often lives in functions outside the audit scope, later upgrades, and external dependencies. Its recommended controls run to segregation of duties, timelocks, allowlists for change targets, caps on the magnitude of changes, multi-source verification for cross-chain flows, and monitoring of invariants such as issuance volume and collateral value.
Leveraging external assessments without over-relying on them
The report endorses using third-party assessments, SOC 2 or ISO/IEC 27001 attestations, penetration tests, code and smart-contract audits, and bug-bounty results, to confirm baseline assurance. It then spends as much space warning that the existence of an assessment is not evidence of security. Teams should confirm the assessment’s scope, timing, methodology, exclusions, and the assessor’s independence and qualifications, understand what was not assessed, and close the gaps against their own outflow scenarios with additional questionnaires, technical-evidence review, on-site checks, and their own compensating controls.
Blind signing, and the push toward Clear Signing
One operational detail runs through almost every case the report studies: the signer could not really see what they were signing. Complex smart-contract transactions, bridge and cross-chain calls, staking, privilege grants, and contract upgrades often reach a hardware wallet as raw calldata or an EIP-712 message that a human cannot interpret, and small hardware screens make it worse. Signers then approve on trust, which is the behaviour the Bybit attackers exploited.
The report points to the industry response. On 12 May 2026, the Ethereum Foundation, together with wallet developers, security firms, and other participants, announced Clear Signing, a framework aimed at achieving “what you see is what you sign” and reducing blind signing. Its core technology, ERC-7730, is a JSON-based descriptor standard for presenting structured data such as smart-contract calls and EIP-712 messages in human-readable form; originally a draft in February 2024, it has since expanded, with a version 2 covering cross-chain interactions and software wallets.
The caution the report attaches is worth carrying into any control design. Clear Signing depends on the accuracy of the displayed information and the authenticity of its descriptors, so a wrong or compromised descriptor can itself mislead. It should be treated as one layer, used alongside double-checked approvals, anti-malware controls, third-party risk management, segregation of duties, and anomaly detection, rather than as a standalone fix.
What cross-border groups touching Japan should read into it
For a group that runs entities in more than one jurisdiction, the temptation is to fold Japan into an existing framework and assume equivalence. The instruments do not line up that way. Japan’s regime sits in the Payment Services Act with the JVCEA as certified self-regulator; the EU regulates the same activity through the Markets in Crypto-Assets Regulation and layers operational resilience obligations on top through the Digital Operational Resilience Act. The obligations, the supervisors, and the reporting artefacts differ, and a control that satisfies a Japanese examiner is not automatically the one an EU authority will ask for. Groups that report ICT incidents under the EU rules should keep the two mappings distinct, as set out in our guide to DORA ICT incident reporting.
The substance, though, travels well, because the report says as much. Its root-cause analysis concludes that the deficiencies behind DeFi outflows, weaknesses in privilege management, credential management, CI/CD, cloud configuration, signing controls, and cross-chain connection management, are common across crypto operations, including centralised exchanges and custodians anywhere. A European CASP working through its resilience testing under the DORA threat-led penetration testing regime, or building the client-asset safeguards that come with the end of the MiCA CASP transitional period, will recognise the same signing-adjacent attack surface the FSA report describes.
The report also frames cross-border coordination as its own recommendation. It argues that anonymity, cross-border reach, and instant settlement make individual-operator controls insufficient for real-time detection, tracing, and asset freezing, and calls for common international data standards for threat and vulnerability information, stronger information-sharing organisations such as JPCrypto-ISAC coordinating with overseas ISACs, and joint supervision. That is the same instinct behind cross-border supervisory cooperation elsewhere, visible in the EBA and NYDFS stablecoin supervision arrangement and in FATF travel-rule work; Japan applies originator and beneficiary information requirements to covered transfers by registered providers, with cross-border scope limited to designated jurisdictions having equivalent requirements, covered in our note on the FATF approach to stablecoins and unhosted wallets.
Reading the report without over-reading it
A few misreadings are easy to fall into, and each has an operational cost. The report is research that names weaknesses and possible controls, with an explicit note that controls must be tailored to each firm’s own circumstances and risk profile, and that addressing only the listed measures is not sufficient. Reading it as an enforcement action, or speculating about penalties from it, would be a misreading.
The report’s structural argument is that real crypto services run as composite architectures, a mix of centralised elements and decentralised infrastructure, and carry the risks of both: the single points of failure of centralised components and the irreversibility of on-chain settlement. The report states that real-world crypto services commonly combine centralised and decentralised components, creating both centralised single points of failure and exposure to irreversible on-chain settlement. Where a firm uses DeFi protocols, the report warns that the full burden of risk can shift to the user, so the risk assessment before using such a protocol has to be its own exercise, separate from a vendor contract review.
Finally, the report’s forward look should not be treated as immediate obligation. Its medium-to-long-term considerations, reducing attack surfaces, restricting inbound internet access to critical systems, treating development and CI/CD environments as security targets as critical as production, isolating production from development and administrative systems, and preparing for post-quantum cryptography through cryptographic agility, are a direction of travel. They are a strong planning input for a multi-year security roadmap, not a control the FSA is measuring you against this quarter.
Frequently Asked Questions
Is the June 2026 report binding on Japanese crypto-asset exchange service providers?
No. It is a contractor research report that states its contents do not represent the FSA’s official views. Binding statutory obligations arise under the Payment Services Act and its implementing measures. The FSA Administrative Guidelines set supervisory viewpoints, while applicable JVCEA self-regulatory rules bind association members. The report’s value is as a preview of the control areas a future guideline revision is likely to address.
What are the five priority areas the report identifies?
Enhancement of third-party and supply-chain risk management; measures to prevent malicious code injection and program tampering; measures to prevent unauthorised transfers of crypto-assets; measures for smart contracts and DeFi; and leveraging external assessments while confirming their scope and limits. Each is framed as an area where operators should specify and deepen controls to fit their own systems and outsourcing.
Why does the report expand the focus beyond signing-key protection?
Because several large-loss cases involved tampering with systems and processes around signing, including interfaces, APIs, CI/CD pipelines and transaction-generation logic, so that a legitimate signer authorised a malicious payload without the signing key itself being stolen. The Bybit case is the clearest example. This does not mean that signing-key theft is no longer a major risk.
Does cold-wallet storage still protect our users’ assets?
Cold storage remains a required and useful control: it stops direct theft from offline keys. The Bybit breach demonstrated its limit: attackers corrupted the authorisation process for moving assets out of cold storage, so the funds left despite cold-wallet discipline. Cold storage must be paired with layered transfer controls, decoded transaction verification, and abnormal-withdrawal detection to defend that authorisation path.
What is Clear Signing and does it solve blind signing?
Clear Signing is a framework announced on 12 May 2026 by the Ethereum Foundation and ecosystem participants to make transaction contents human-readable at the point of signing, using the ERC-7730 descriptor standard. It reduces blind signing but does not eliminate the risk: a wrong or compromised descriptor can mislead a signer, so the report treats it as one of several layers, still short of a complete answer.
How should a Japanese CASP use the report right now?
As a gap-analysis input. Map current controls against the five priority areas, evidence where the described practice is already met, and log where a control rests on an unverified assumption, particularly around external providers, production-environment access, and signing verification. That mapping shortens the response time if the Administrative Guidelines are later revised.
Does the report apply to firms outside Japan?
Its status is Japanese, and its instruments are Japanese, so a non-Japanese entity is not supervised against it. Its root-cause findings, however, describe risks the report calls common across crypto operations everywhere, so EU and other CASPs can use it as threat-model input while keeping their own MiCAR and DORA obligations mapped separately.
What existing standards does the report benchmark against?
It compares observed attacks against, among others, NIST CSF 2.0, the FSA Guidelines on Cybersecurity for the Financial Sector, the FISC Security Measures Standard, the FSA Administrative Guidelines for crypto-asset exchange service providers, the JVCEA Crypto Asset Security Management Standard, JPCrypto-ISAC contractor-management guidelines, OWASP SCSVS, CCSS, and the MITRE ATT&CK, AADAPT, and D3FEND frameworks.
Related Articles
- MiCAR Reporting Obligations: how the EU regime frames reporting duties for crypto-asset service providers, the counterpart to Japan’s Payment Services Act model.
- DORA ICT Incident Reporting: the EU operational-resilience reporting obligations that cross-border groups must keep distinct from Japan’s supervisory expectations.
- DORA TLPT for European Financial Entities: threat-led penetration testing under DORA, which tests the same signing-adjacent attack surface the FSA report describes.
- MiCA CASP Transitional Period End and Client Assets: client-asset safeguarding as the EU transitional window closes, a parallel to Japan’s user-property rules.
- EBA and NYDFS Stablecoin Supervision Arrangement: cross-border supervisory cooperation of the kind the report calls for in crypto.
- FATF Stablecoins and Unhosted Wallets: the travel-rule and AML context relevant to Japan’s registered exchanges, including the jurisdiction-limited scope of certain cross-border transfer requirements.
Key Takeaways
- The Deloitte Tohmatsu report is dated 30 June 2026 and was added to the FSA’s public research page on 23 July 2026; it is research, not binding law, but reads as the groundwork for a revision of the crypto-asset exchange supervisory guidelines.
- Large-loss incidents increasingly include compromises of systems and third parties around the signing process. The Bybit case is the report’s principal example of an outflow without theft of the signing key, but the report does not conclude that signing keys are no longer a primary target.
- Third-party vulnerabilities produced the largest single loss category since 2023 from only 17 recorded events, so the severity risk sits with rare supplier compromises far more than with the frequent small incidents.
- Japan’s existing framework, the Payment Services Act, FSA Administrative Guidelines (section 16 updated in 2026), and JVCEA standards (including rules effective 1 July 2026), already covers the risk areas; the report’s concern is depth of control and operator understanding.
- The five priority areas are third-party risk management, program-tampering prevention, unauthorised-transfer controls, smart-contract and DeFi measures, and disciplined use of external assessments.
- Cold-wallet storage remains necessary but not sufficient; it must be paired with layered transfer controls, decoded transaction verification, and automatic suspension.
- Clear Signing and ERC-7730 reduce blind signing but are one layer only, since a compromised descriptor can itself mislead a signer.
- Cross-border groups should treat the substance as portable threat-model input while keeping Japan’s PSA obligations mapped separately from EU MiCAR and DORA duties.
Sources and References
- Deloitte Tohmatsu LLC, “Cybersecurity Issues and Countermeasures in Crypto-Asset-Related Businesses” (research paper prepared for the FSA, dated 30 June 2026; added to FSA public research page 23 July 2026): https://www.fsa.go.jp/policy/bgin/ResearchPaper_dtc_20260630_en.pdf
- Financial Services Agency, Fintech and Innovation / BGIN research track (report listing page, updated July 23, 2026): https://www.fsa.go.jp/en/policy/bgin/innovationtop.html
- Financial Services Agency, Policy Approaches to Strengthen Cyber Security in the Financial Sector: https://www.fsa.go.jp/en/policy/cybersecurity/index.html
- Financial Services Agency, Press Releases (2026): https://www.fsa.go.jp/en/news/index.html
- Payment Services Act: use the current Japanese law together with the FSA’s implementation materials for amendments effective from 1 June 2026: https://www.fsa.go.jp/news/r7/sonota/20260522/20260522.html. For convenience only, the latest available official English translation is current to Act No. 61 of 2022: https://www.japaneselawtranslation.go.jp/en/laws/view/4477/en.
- Japan Virtual and Crypto assets Exchange Association (JVCEA): https://jvcea.or.jp/en/
- NIST Cybersecurity Framework 2.0: https://www.nist.gov/cyberframework
What a Japanese CASP should do with the report this quarter
The most useful thing a compliance and security team can do with this report is unglamorous: run its five priority areas as a gap analysis, evidence what is already in place, and be honest about the assumptions that are not yet provable, especially where an external provider sits between the firm and its own funds. The Bybit lesson is that a compromised computer interface can conceal a malicious transaction while the hardware wallet still displays the malicious details. The report says the signers did not sufficiently verify those details, so firms should strengthen independent transaction verification and limit what a single bypassed control can move. Do that now, and a later revision of the FSA’s crypto cybersecurity guidelines becomes a confirmation exercise rather than a scramble.
Disclaimer: The information on RegReportingDesk.com is for educational and informational purposes only. It does not constitute legal, regulatory, tax, or compliance advice. Always consult your compliance officer, legal counsel, or the relevant supervisory authority for guidance specific to your institution.
