South Korea’s Financial Supervisory Service (FSS) disclosed on July 20, 2026, that the Bank of Korea ran its first central bank digital currency pilot without any separate security inspection by financial authorities. The banks being tested checked their own systems instead.
Key Takeaways
- Bank of Korea ran Project Hangang’s first-phase pilot over three months from April to June 2025, with up to 100,000 users across seven banks, according to Bank of Korea’s own pilot report.
- Woori Bank and NongHyup Bank inspected their own systems as participating banks, not as neutral outside auditors, per FSS disclosure.
- The Financial Supervisory Service held just one substantive consultation with banks on deposit tokens and CBDCs in three years.
- The first-phase pilot moved about 81,000 participants through 114,880 transactions using bank-issued deposit tokens.
- Bank of Korea now plans a second phase expanding the pilot from seven participating banks to nine, starting in September, per Yonhap News reporting cited in the disclosure.
What Happened?
Documents the FSS submitted to the office of Representative Lee Heon-seung of the People Power Party show a gap between how the pilot was tested and how it was billed. The three month pilot ran from April to June 2025 and moved real transactions between banks and consumers using deposit tokens, distinct from the wholesale currency settling behind the scenes.
No outside financial regulator reviewed the system while it was live. The entire security process consisted of a preliminary review and an inhouse IT vulnerability assessment in February, two months before launch. The Financial Security Institute and the security firm SK Shieldus took part, but the actual inspection work fell to the in-house teams of Woori Bank and NongHyup Bank, two of the banks being tested.
No evidence surfaced in the FSS documents of an independent audit conducted after the pilot concluded. An industry insider quoted in the disclosure argued a live transaction pilot needs outside verification “to secure objectivity” and market confidence, not just a technical sign off from the institutions running it.
@bok_hub‘s Phase 1 CBDC Pilot Criticized for Lacking Independent Security Oversight
— BLOCKMEDIA(블록미디어) (@with_blockmedia) July 21, 2026
The Bank of Korea (BOK) is facing mounting scrutiny over revelations that its Phase 1 Central Bank Digital Currency (CBDC) pilot was conducted without independent security audits or formal… pic.twitter.com/rt1Ub9Brpu
The Bank Graded Its Own Homework
Bank of Korea’s own pilot report addresses the same question directly, in a section titled “Reference 10: Misconceptions and Truths About Digital Currency.” Asked whether deposit tokens are vulnerable to IT security risks, the bank answers “that is not the case,” pointing to its own pre-launch review as proof.
The report states, translated: the issuing banks “conducted a thorough IT security review of the entire relevant system before the launch of Project Hangang.”
That answer is the institution that ran the pilot vouching for itself. The bank’s own report describes the check as an IT security risk review carried out between December 2024 and February 2025 by the Financial Security Institute and an outside IT vendor, not a post launch or ongoing regulatory audit. A Bank of Korea official said:
That defense conflates “we checked carefully once” with “someone independent checked us.” Those are different claims, and only the second one answers the objectivity question the industry insider raised.
A Supervisory Framework That Hasn’t Caught Up
The disclosure’s most telling figure isn’t about the pilot itself. Substantive consultations between the FSS and the banking sector on deposit tokens and CBDCs totaled just one case in three years, a discussion tied to a Shinhan Bank deposit-token-linked insurance product. Banks have not yet built dedicated units for this asset class.
Bank of Korea now plans phase two, expanding the pilot to nine participating banks, adding Kyongnam Bank and iM Bank (formerly Daegu Bank). The new phase adds peer-to-peer transfers, biometric authentication, and automatic transfers, and will attempt, for the first time, disbursing government subsidies as tokenized deposits.
Implications for CBDC Trust
A wholesale CBDC is only as credible as the rails consumers trust it to run on. Project Hangang layers a Bank of Korea-issued wholesale CBDC as the settlement asset underneath commercial deposit tokens consumers actually spend, so any security question about deposit tokens is also a question about the central bank’s own settlement layer.
South Korea has moved fast on CBDC infrastructure while its bank supervisor has moved slowly on oversight capacity for it. The mismatch gets sharper once government money enters the pipes. A subsidy program running on self audited rails carries different political and operational risk than a limited user pilot did, because a payment failure would touch public funds, not volunteer testers.
CoinLaw’s Takeaway
This reads as a sequencing problem, not a proven security failure. Project Hangang’s deposit tokens may well be secure. The issue is that the only entity saying so is the one that built the system, while the regulator meant to check that claim has held one substantive consultation on this asset class in three years.
That gap gets harder to defend once real subsidy payments move through the same rails when phase two starts in September 2026.
CBDC pilots elsewhere have leaned on outside red team testing specifically to avoid this appearance problem. Bank of Korea’s own report shows it chose a faster, cheaper path: a pre-launch self-review, then a public defense of that review once critics raised the same concern an industry insider raised on the record. Whether that holds up depends on what, if anything, the FSS builds before phase two goes live with public money attached.