- Bank of Korea’s CBDC pilot relied mainly on internal security assessments before launch.
- No independent audit reviewed Project Hangang during or after real-world testing.
- Oversight concerns grow as South Korea expands CBDC and deposit token initiatives.
South Korea’s central bank is facing criticism after reports revealed its first central bank digital currency (CBDC) pilot lacked an independent security audit. Documents submitted by the Financial Supervisory Service (FSS) show the project relied mainly on pre-launch security reviews conducted by participating banks instead of external oversight, raising questions about transparency and public trust.
Bank of Korea Defends Security Review Process
According to a report from Maeil Business Newspaper, a South Korean business daily, the Bank of Korea’s first CBDC pilot, known as Project Hangang, ran between April and June 2025 to test real-world digital currency transactions.Â
The trial involved commercial banks issuing blockchain-based deposit tokens backed by the central bank’s wholesale CBDC infrastructure.
However, documents submitted by the Financial Supervisory Service to lawmaker Lee Heon-seung showed no independent government security inspection occurred during or after testing. Instead, participating banks completed preliminary security assessments before the pilot launched.
The pre-launch review included IT vulnerability testing conducted with the Financial Security Institute and cybersecurity company SK Shields. Nevertheless, Woori Bank and NongHyup Bank also carried out internal inspections despite participating directly in the pilot.
Critics argue this structure reduced independent oversight because institutions testing the system also evaluated their own security measures. Consequently, concerns emerged regarding the objectivity of the overall assessment process.
The Bank of Korea later addressed security concerns in its pilot results report. It stated that deposit tokens were not vulnerable to cybersecurity risks because comprehensive security reviews had been completed before Project Hangang began.
However, observers noted those conclusions reflected the central bank’s internal assessment rather than findings verified through an independent third-party audit. No evidence indicated financial authorities conducted follow-up security inspections after the pilot concluded.
Oversight Questions Grow as Digital Currency Plans Expand

The report also highlighted limited coordination between financial regulators and commercial banks throughout South Korea’s broader CBDC development program. According to submitted documents, only one formal consultation involving deposit tokens occurred during the past three years.
That consultation involved Shinhan Bank and a deposit token-linked insurance product. Meanwhile, banks have not established dedicated supervisory teams focused specifically on CBDCs or deposit token oversight.
The Bank of Korea defended its approach, stating additional inspections were unnecessary because comprehensive security reviews had already been completed before the pilot started.Â
Officials added the process complied with supervisory procedures established by the Financial Supervisory Service.
Industry participants maintain that independent verification remains essential for strengthening confidence in future digital payment infrastructure. They argue external audits following real-world testing would improve transparency and reinforce market credibility.
The scrutiny comes as South Korea continues advancing digital asset policies, including plans for won-backed stablecoins and expanded CBDC initiatives. Authorities are also preparing additional pilot programs involving tokenized government bonds, programmable deposit tokens, and cross-border payment projects under the Bank for International Settlements’ Project Agora.






Leave a Reply
You must be logged in to post a comment.