Crypto World
South Korea Lowers Crypto Travel Rule Threshold for Transfers
South Korea is preparing to expand its crypto “Travel Rule” so that it applies to virtually all on-chain transfers between registered virtual asset service providers (VASPs), rather than only transactions above a set value. The change removes the current 1 million won threshold (about $700), a step aimed at closing an obvious loophole: users splitting transfers into smaller chunks to stay under reporting and information-sharing requirements.
According to a cabinet decision approving amendments to the Enforcement Decree of South Korea’s Act on Reporting and Using Specified Financial Transaction Information, the updated rules will also add tighter anti-money laundering (AML) obligations around transfers that involve foreign exchanges and personal wallets, where authorities have said existing controls have been exploited.
Key takeaways
- South Korea’s Travel Rule will apply to all transfers between registered crypto VASPs, removing the 1 million won transaction cutoff.
- Receiving platforms must obtain sender and recipient information and can request missing data or reject transfers if required information is unavailable.
- New AML requirements extend to transfers involving overseas crypto exchanges and personal wallets, including risk-based acceptance rules.
- Platforms will need suspicious transaction monitoring for transfers of at least 10 million won involving foreign exchanges or personal wallets.
- The expanded framework starts at staggered timelines: some VASP registration updates take effect Aug. 20, while other transfer-related requirements begin six months after promulgation.
Travel Rule expanded with threshold removed
South Korea’s Financial Intelligence Unit (FIU) said the main driver behind the amendment is the risk that users can circumvent the Travel Rule by breaking up activity into smaller transfers that fall below the prior reporting threshold. The cabinet-approved changes remove the value limit entirely, making information-sharing obligations standard across the board for covered transfers.
The FIU cited an example intended to illustrate how the threshold can be gamed. It described a case where a user purchased Tether USDt (USDT) after depositing roughly 200 million won into a crypto exchange, then executed 216 withdrawals, each valued below 1 million won. By keeping each withdrawal under the cutoff, the user aimed to reduce exposure to the Travel Rule’s information-sharing requirements.
Under the revised framework, the Travel Rule will cover all transfers between registered crypto service providers, regardless of amount. This matters for compliance teams and operational workflows: firms can no longer assume that smaller transfers are “out of scope,” and they will need to ensure their transaction processing can consistently handle sender/recipient information requirements at higher volumes and smaller denominations.
What receiving platforms must do
The amendments specify operational responsibilities for counterparties receiving transfers. Receiving VASPs will be required to obtain sender and recipient information. If required data is incomplete or missing, receiving platforms may request the missing information—or reject the transaction when necessary details cannot be obtained.
For users, this raises the prospect of more frequent transfer friction, particularly around transactions where counterparties fail to provide the expected information. For exchanges and wallet providers, it emphasizes the importance of internal controls and technical readiness—especially where transfers cross different service providers that may vary in how they capture and transmit required details.
The rule change is also designed to standardize accountability across the ecosystem. Instead of relying on a threshold that can be optimized around, the updated approach pushes toward comprehensive compliance for covered counterparties.
Overseas exchanges and personal wallets face new AML controls
Beyond expanding the Travel Rule, the decree introduces new AML requirements for transfers that involve overseas crypto exchanges and personal wallets. Registered local VASPs will need to apply a risk-based approach to decide which transfers they allow based on the risk posed by the counterparty.
In practice, the amendments indicate that transfers to low-risk overseas exchanges will be permitted. However, transfers involving other foreign exchanges and personal wallets are generally allowed only when the sender and recipient are the same person—an effort to reduce anonymity and inter-personal laundering risks.
Where counterparties are assessed as high risk, transactions will be prohibited. This creates a compliance obligation that goes beyond simple eligibility checks: firms will have to maintain and update risk assessments tied to specific counterparties, and ensure those assessments are reflected in transaction controls.
The decree also requires crypto platforms to establish their own suspicious transaction monitoring systems for transfers worth at least 10 million won that involve foreign exchanges or personal wallets. Authorities said suspected money laundering involving overseas exchanges and personal wallets has risen because gaps in existing AML rules for such transfers have been exploited.
Even though the new Travel Rule applies to transfers between registered local providers, the AML changes broaden the compliance perimeter. They are aimed at the points where value can flow into or out of Korea’s regulated rails through foreign venues or self-custody arrangements.
Stronger registration standards and phased implementation
In addition to transaction-specific requirements, the decree strengthens the registration framework for crypto service providers. The amendments include requirements related to financial health, internal controls, staffing, and infrastructure standards, while also expanding scrutiny of major shareholders. This signals an intent to raise baseline operational quality and governance across the sector, not only to improve transaction monitoring.
The VASP registration provisions will take effect Aug. 20. However, existing providers will receive an additional year to comply with some of the financial, staffing, infrastructure, and internal control requirements—suggesting a transition period intended to reduce abrupt compliance shocks for incumbents.
Meanwhile, the expanded Travel Rule and the other transfer-related AML requirements will take effect six months after the decree is promulgated. That timing means exchanges and wallet providers will need to prepare their systems ahead of the compliance start date, including data capture and transfer handling logic required for sender/recipient information, as well as monitoring and risk assessment processes for cross-border and self-custody related activity.
For market participants, the key watch items are how risk assessments for overseas counterparties are implemented and how receiving platforms handle missing information in practice—because those operational details will determine whether the new rules mainly improve traceability or also introduce more frequent transaction rejections for edge cases.
You must be logged in to post a comment Login