Lack of Independent Security Verification: Korea's Central Bank CBDC First Phase Pilot Relied Solely on Participating Banks' Self-Inspection
2026-07-21 03:50
Odaily reported that according to data from the Financial Supervisory Service, the Financial Supervisory Service of South Korea, the central bank of Korea did not conduct any independent security verification during the first phase of its CBDC pilot project. Security assessments were only carried out internally by the participating banks themselves before the project commenced. Prior to the project launch, only IT vulnerability self-assessments were conducted by the participating banks. These assessments were jointly executed by the Financial Security Institute, SK Shields, and the self-inspection teams of Woori Bank and Nonghyup Bank, forming an evaluation model characterized by "self-inspection by the regulated entity." In its pilot results report, the Bank of Korea acknowledged external concerns over the security of deposit tokens and responded that the preliminary reviews were sufficient. However, critics pointed out that this explanation is a self-assessment, not an independent third-party verification.
