A bill amending the Virtual Asset User Protection Act moved from committee referral to committee review on 26 August 2026. As drafted, it would require virtual asset service providers (VASPs) to periodically verify that they hold user-entrusted virtual assets in matching type and quantity, and to establish a risk-management system for risks arising from virtual asset transactions (proposed Art. 7(2), new Art. 9-2). The sponsors cite recent large-scale mispayment incidents at virtual asset exchanges as the reason for the change; the bill has not yet been enacted, and no effective date or penalty is currently specified.
What this means for you
- This is a pending bill, not current law. It has advanced to committee review (26 August 2026) but has not passed. Treat it as a signal to prepare, not as an active obligation.
- No quantitative threshold applies. The draft reaches virtual asset service providers generally — it is not gated by revenue, user count, or any other numeric trigger disclosed so far.
- The substantive ask is twofold: (1) periodic verification that assets held on behalf of users match the type and quantity entrusted, and (2) a documented risk-management framework covering risks arising from virtual asset transactions.
- Start now on the operational side. If you operate a VASP serving Korean users, review your current balance-reconciliation cadence and risk-management documentation against these two proposed duties, so you are not starting from zero if the bill passes.
- No effective date or penalty has been set. Both will depend on the final enacted text; do not assume the current absence of a penalty figure means the duty will stay low-stakes.
- Track committee progress. Bills at the committee-review stage can be revised, merged with other proposals, stalled, or advanced with little advance notice — recheck status periodically rather than assuming no further movement.
Source: