The post South Korea’s DAXA Cracks Down on Crypto API Abuse appeared on BitcoinEthereumNews.com. DAXA mandates Upbit, Bithumb, Coinone, Korbit, and Gopax to invalidateThe post South Korea’s DAXA Cracks Down on Crypto API Abuse appeared on BitcoinEthereumNews.com. DAXA mandates Upbit, Bithumb, Coinone, Korbit, and Gopax to invalidate

South Korea’s DAXA Cracks Down on Crypto API Abuse

2026/05/29 21:39
3분 읽기
이 콘텐츠에 대한 의견이나 우려 사항이 있으시면 [email protected]으로 연락주시기 바랍니다
  • DAXA mandates Upbit, Bithumb, Coinone, Korbit, and Gopax to invalidate suspicious shared API keys.
  • Automated trading accounts for 30% of Korean crypto volume, making API governance a systemic issue.
  • Exchanges must now monitor, warn, re-verify, and force-expire API keys based on risk level detected.

South Korea’s Digital Asset Exchange Alliance (DAXA) has established mandatory compliance standards requiring the country’s major cryptocurrency exchanges to detect and invalidate API keys suspected of being improperly shared or lent between users.

The policy, announced May 28, targets a specific exploitation method that has been used to facilitate price manipulation and unfair trading practices across Korean crypto markets. DAXA member exchanges, including Upbit, Bithumb, Coinone, Korbit, and Gopax, are all subject to the new standards.

Why This Matters

API keys are access credentials that allow users and external programmes to interact with exchange accounts, placing orders, checking balances, and executing withdrawals without manual login. When lent or shared with third parties, they become a tool for coordinated trading activity that can manipulate prices while obscuring who is actually behind the trades.

The Financial Supervisory Service of Korea said that automated trading currently accounts for approximately 30% of cryptocurrency trading volume in the country, making API key governance a systemic market integrity issue rather than an edge case.

What Exchanges Must Now Do

Under the new standards, exchanges are required to implement a layered response framework based on risk level:

  • Enhanced monitoring of API key activity patterns flagged as suspicious
  • Warning notifications are issued to users when abnormal sharing behaviour is detected
  • Identity re-verification requirements triggered by suspicious activity
  • Forced API key expiration for confirmed cases of improper lending
  • IP address whitelisting allowing API access only from pre-registered addresses

The IP whitelist requirement is particularly significant. It means even if an API key is shared, it cannot be used from an unauthorised device or location, adding a hardware-level barrier to credential abuse.

The Context

API credential abuse has been a persistent but underreported vulnerability across crypto trading infrastructure. Security researchers have noted that many API-related incidents are categorised broadly as generic hacks rather than specifically as credential compromise, masking the true scale of the problem.

The 2022 3Commas incident exposed approximately 100,000 API keys linked to Binance and KuCoin accounts, demonstrating the scale of damage possible when credential management fails. Major exchanges, including Binance, Coinbase, OKX, and Kraken, already support IP whitelisting and permission management as optional features. DAXA’s new standards move toward mandatory enforcement rather than voluntary adoption.

DAXA Executive Vice Chairman Jaejin Kim framed the policy in direct terms. “DAXA and its member companies will respond swiftly to new and emerging threats and will take strong measures as needed to uphold the paramount value of user protection.”

What It Signals

Korea remains one of the most active retail crypto markets in the world. Regulatory actions from DAXA and the Financial Supervisory Service consistently set precedents that other jurisdictions observe closely. Mandatory API key governance standards, if adopted more broadly, would close one of the most practically exploitable gaps in crypto exchange security infrastructure.

Related: Samsung Units Invest $408M for 4% Stake in Dunamu

Disclaimer: The information presented in this article is for informational and educational purposes only. The article does not constitute financial advice or advice of any kind. Coin Edition is not responsible for any losses incurred as a result of the utilization of content, products, or services mentioned. Readers are advised to exercise caution before taking any action related to the company.

Source: https://coinedition.com/south-koreas-daxa-forces-crypto-exchanges-to-invalidate-suspicious-api-keys/

SPACEX(PRE) Launchpad

SPACEX(PRE) LaunchpadSPACEX(PRE) Launchpad

Register for a chance to win a free lucky draw

면책 조항: 본 사이트에 재게시된 글들은 공개 플랫폼에서 가져온 것으로 정보 제공 목적으로만 제공됩니다. 이는 반드시 MEXC의 견해를 반영하는 것은 아닙니다. 모든 권리는 원저자에게 있습니다. 제3자의 권리를 침해하는 콘텐츠가 있다고 판단될 경우, [email protected]으로 연락하여 삭제 요청을 해주시기 바랍니다. MEXC는 콘텐츠의 정확성, 완전성 또는 시의적절성에 대해 어떠한 보증도 하지 않으며, 제공된 정보에 기반하여 취해진 어떠한 조치에 대해서도 책임을 지지 않습니다. 본 콘텐츠는 금융, 법률 또는 기타 전문적인 조언을 구성하지 않으며, MEXC의 추천이나 보증으로 간주되어서는 안 됩니다.

RealStocks Now Live

RealStocks Now LiveRealStocks Now Live

Trade real U.S. stock via regulated brokerage