Custodial wallet / SaaS in South Korea
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in South Korea with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- VASP registration with KoFIU under the Act on Reporting and Using Specified Financial Transaction Information (amended 2021) is mandatory for the custodial wallet provider (kr.licensing.vasp, kr.aml.act-on-reporting-and-use)
- ISMS certification from KISA required (kr.licensing.vasp, kr.aml.korea-internet-security-agency-kisa)
- Mandatory real-name verified bank account partnership (critical bottleneck — only 5 exchanges achieved this) (kr.licensing.vasp)
- Suspicious transaction reporting (STR) to KoFIU for AML/CTF compliance (kr.aml.korea-financial-intelligence-unit-kofiu)
- KYC/AML obligations under the Act on the Protection of Virtual Asset Users (2024) for customer onboarding (kr.aml.act-on-the-protection-of)
- The SaaS provider, as the VASP, bears primary AML obligations — white-label clients may not be separately registered, shifting compliance burden to the custody provider (kr.licensing.custody)
Key Restrictions
- Only 5 exchanges have achieved the real-name bank account partnership bottleneck (Upbit, Bithumb, Coinone, Korbit, Gopax); a custodial wallet SaaS operator would need such a partnership (kr.licensing.vasp)
- KRW 3B (~$2.2M USD) minimum equity capital required for exchanges under VAUPA; unclear whether a pure custodial wallet SaaS qualifies as an 'exchange' for this threshold — legal interpretation needed (kr.licensing.vasp, kr.licensing.legislation-virtual-asset-user-protection-act-vaupa)
- 100% cold storage for reserves required for custody operations (kr.licensing.custody)
- Compensation reserves (insurance/indemnity) mandatory under VAUPA for custodial functions (kr.licensing.custody, kr.licensing.legislation-virtual-asset-user-protection-act-vaupa)
- ICO effectively banned since 2017 via administrative guidance — affects any token-related custody or issuance (kr.licensing.exchange)
- Token listing requires exchange self-assessment, which could affect which assets the custodial wallet supports (kr.licensing.exchange)
Key Risks
- Real-name account bottleneck is the single greatest operational risk — without a partnership, the model cannot legally operate (kr.licensing.vasp)
- Regulatory ambiguity on whether a pure custodial wallet SaaS (non-exchange, non-trading) fits under the exchange classification with the KRW 3B capital threshold (kr.licensing.vasp)
- Upcoming Digital Asset Basic Act (proposed early 2026) may introduce additional custody-specific licensing or supervision, creating regulatory transition risk (kr.aml.upcoming-digital-asset-basic-act)
- VAUPA imposes severe penalties (including life imprisonment for gains over 5B KRW) for market manipulation/insider trading — custodial wallets handling user assets must have strong internal controls (kr.aml.act-on-the-protection-of)
- White-label model creates AML attribution risk — unclear whether SaaS provider or client bears STR/KYC duties; KoFIU registration likely falls on the entity with key control (the custody provider) (kr.licensing.custody, kr.aml.korea-financial-intelligence-unit-kofiu)
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Act on Reporting and Using Specified Financial Transaction Information (amended) (2021) — VASP registration, AML/CFT
Virtual Asset User Protection Act (VAUPA) (2024) — Investor protection, unfair trading/insider trading prohibition, mandatory insurance/reserves, KRW 3B minimum equity capital for exchanges
VASP: VASP registration with KoFIU + ISMS certification mandatory. KRW 3B (~$2.2M USD) minimum equity capital for exchanges under VAUPA. Real-name verified bank account partnership required (critical bottleneck — only 5 exchanges achieved this: Upbit, Bithumb, Coinone, Korbit, Gopax).
CUSTODY: Included under VASP registration; 100% cold storage for reserves required. Compensation reserves mandatory under VAUPA.
EXCHANGE: VASP registration + real-name bank account partnership. Upbit dominates ~80% market share. ICOs effectively banned since 2017 (administrative guidance). Token listing requires exchange self-assessment.
Act on Reporting and Use of Specific Financial Transaction Information: Requires VASPs to register with KoFIU and comply with AML/CTF standards.
Act on the Protection of Virtual Asset Users (2024): Focuses on user protection, prohibits unfair practices like market manipulation, and enforces AML protocols.
Korea Financial Intelligence Unit (KoFIU): Handles VASP registration, AML reporting, and guidelines. (Official site: kofiu.go.kr)
Korea Internet & Security Agency (KISA): Issues mandatory Information Security Management System (ISMS) certifications for exchanges.
Upcoming Digital Asset Basic Act: Proposed for early 2026 by National Assembly to consolidate regulations on exchanges, token issuance, custody, stablecoins, and ETFs.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a custodial wallet SaaS can operate in Korea only if it obtains VASP registration with KoFIU, ISMS certification, a real-name bank account partnership (severe bottleneck), meets segregation/insurance/cold-storage requirements under VAUPA, and complies with AML/CTF obligations; the provider bears primary AML responsibility, and the KRW 3B minimum capital requirement for exchanges creates interpretive risk for custodial-only operators.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?