South Korea Flag

South Korea

Updated: 24 Aug, 2026

South Korea was one of the first jurisdictions in Asia to introduce Travel Rule requirements for virtual asset transfers, with the rules taking effect in 2022. Since then, the regulatory framework has continued to evolve, with significant changes now being introduced to strengthen transparency and AML controls across the virtual asset market.

A key upcoming change is the removal of South Korea's KRW 1 million Travel Rule threshold. From February 2027, VASPs will be required to apply Travel Rule requirements to virtual asset transfers regardless of value, while transfers involving overseas VASPs and self-hosted wallets remain subject to additional risk-based requirements.


South Korea
Breakdown of South Korea's Travel Rule Regulations


What is the scope of the Travel Rule in South Korea?

The Travel Rule applies to transfers of virtual assets between registered virtual asset business operators (VASPs), as well as transfers involving self-hosted wallets where at least one regulated entity is involved in the transaction.

Under the Act on the Protection of Virtual Asset Users, etc., the following activities fall within the scope of virtual asset business activities relevant to the Travel Rule:

(a) The sale or purchase of virtual assets;

(b) The exchange of virtual assets for other virtual assets;

(c) The transfer of virtual assets prescribed by Presidential Decree;

(d) The storage or management of virtual assets; and

(e) The mediation, arrangement, or acting on behalf of the activities described in subparagraphs (a) and (b).


Who is the supervisory body for VASPs in South Korea?

  • The Financial Services Commission (FSC) is South Korea's financial regulator, 
  • The Korea Financial Intelligence Unit (KoFIU) is responsible for AML supervision and the virtual asset reporting system.


What is the Travel Rule threshold in South Korea?

KRW 0

South Korea is removing its existing KRW 1 million Travel Rule threshold through amendments to the Enforcement Decree of the Act on Reporting and Use of Specific Financial Transaction Information.

Under the amended rules, Travel Rule information will have to be provided for all virtual asset transfers, regardless of value, and transmitted alongside the virtual assets when they are transferred.

The zero-threshold Travel Rule provisions are scheduled to take effect six months after 11 August 2026. VASPs have been granted a six-month grace period to align their systems, with final implementation expected in February 2027.


Obligations of originator virtual asset service providers

Originator VASPs must collect and transmit: 

  • originator’s full name *; 
  • originator's wallet address;
  • beneficiary's name*;
  • beneficiary's wallet address.

*For a corporation or organisation, this includes the name of the corporation or organisation and the name of its representative. 

Upon request from the Director of the FIU or the beneficiary VASP, the following additional information must be provided within three business days:

  • The originator's official identification number or corporate registration number, where the originator is a corporation; or
  • The originator's passport number or foreigner registration number, where applicable.


Obligations of beneficiary virtual asset service providers

The receiving VASP is responsible for obtaining and securing the required Travel Rule information.

If the required information is missing, the beneficiary VASP may request the information from the counterparty and, where necessary, refuse to process the transaction.

The counterparty has three business days to provide the missing information. If the information is not provided within this period, the transaction must be refused.


Does South Korea's Travel Rule apply to self-hosted wallets?

South Korea's Travel Rule also addresses transfers involving individual or self-hosted wallets*.

Transfers involving overseas VASPs or individual wallets (self-hosted wallet) are subject to differentiated treatment based on risk. In general:

  • Transfers to low-risk overseas exchanges are permitted.
  • Transfers to other overseas exchanges and individual wallets are permitted where the sender and recipient are the same person.
  • Transfers involving high-risk counterparties are prohibited.
  • Transfers of KRW 10 million or more involving overseas VASPs or individual wallets trigger an internal suspicious transaction monitoring obligation.

Where a VASP conducts a virtual asset transfer with a counterparty using a virtual asset address over which the counterparty does not have exclusive management rights, the VASP must conduct the transaction in accordance with standards determined and notified by the Director of the FIU, taking into account factors such as customer characteristics and transaction patterns.

*These requirements have been discussed and approved by the regulators but have not yet been enforced. VASPs should therefore monitor further regulatory guidance and developments as implementation progresses.


Transfers involving foreign VASPs

When a domestic VASP engages in virtual asset transfer transactions with a foreign VASP, the scope of permissible transactions is differentiated according to the level of risk presented. 

VASPs must assess, among other factors:

  • The content, methods, and level of measures taken by foreign VASPs to prevent money laundering and terrorist financing, in accordance with the methods prescribed and notified by the Director of the FIU; and
  • Whether virtual asset transfer transactions comply with the standards prescribed and notified by the Director of the FIU.

Where these requirements are satisfied, the following rules apply*:

  • Transfers to low-risk overseas exchanges are permitted.
  • Transfers to other overseas exchanges and individual wallets are permitted where the sender and recipient are the same person.
  • Transfers involving high-risk counterparties are prohibited.
  • For transactions of KRW 10 million or more, or where otherwise instructed by the Director of the FIU, VASPs must establish and operate an internal suspicious transaction monitoring system.

*These requirements have been discussed and approved by the regulators but have not yet been enforced. VASPs should therefore monitor further regulatory guidance and developments as implementation progresses.


When do you need to comply with South Korea's Travel Rule?

Now - the Travel Rule went live on 25 March 2022 with a KRW 1 million threshold.

The threshold is now being removed, with the zero-threshold requirement scheduled to take effect in February 2027.


Become Travel Rule Compliant with 21 Analytics

Request a Demo


Which regulations are applicable to South Korea's Travel Rule?

The Act on Reporting and Use of Specific Financial Transaction Information and its Enforcement Decree.

Act on the Protection of Virtual Asset Users, etc.

Cabinet Meeting Approves Amendment to the Enforcement Decree of the Act on Reporting and Use of Specific Financial Information to Strengthen Transparency in the Virtual Asset Market


What else do you need to know about the Travel Rule in South Korea?

All VASPs must meet the following requirements:

  • register with Korean Financial Regulator before they start operating
  • register an authorised company bank account and provide customers with their real-name accounts with the same bank.
  • establish expanded AML/KYC procedures using a risk-based approach, which includes customer due diligence and suspicious transaction reporting. 
  • acquire an Information Security Management System (ISMS) certificate at the Korea Internet & Security Agency (KISA).

Submit the company's details (company name, the name of its representative, location of the place of business, and contact information) and its bank account details to the Financial Intelligence Unit.

  • report large cash transactions (KRW 10 million) (information to be provided includes the name and location of the reporting entity, date and place of payment or receipt of cash; the name of the beneficiary, details of payment or receipt of cash).
  • VASPs are to secure a contract with local banks to provide withdrawal and deposit accounts for their users, under their real names. VASP owners who do not have an authorised bank account will be liable to pay a fine or face 5-year imprisonment.
Written by:
About Hannah
Hannah Zacharias
Head of Regulatory Affairs
Hannah has extensive international crypto experience. She has worked at a Nordic crypto exchange, is part of the DLT Talents program at Frankfurt School Blockchain Center and, currently leads the marketing and regulatory engagement efforts at 21 Analytics. Her crypto regulation research powers 21 Analytics' growth strategy. She writes digestible explainers based on her deep Travel Rule knowledge and engages with policymakers and industry groups.
X
Trust Graphic

New: TRUST Network

Transact with Coinbase, Kraken, Gemini and others.