South Korea's central bank digital currency pilot operated live blockchain payments for thousands of users without undergoing an independent security audit, relying solely on internal assessments by banks involved in the project.

The first phase of Project Hangang, led by the Bank of Korea (BOK), ran from April to June 2025 and tested deposit-token blockchain payments. Documents submitted by the Financial Supervisory Service (FSS) to Representative Lee Hun-seung's office on July 20 revealed no external security inspections were performed after launch.

Internal Evaluations and Security Assessments

Before the pilot’s initiation, participating banks conducted security checks on the technology. In February 2025, Woori Bank and NH Nonghyup Bank's internal audit teams, supported by the Financial Security Institute and SK Shields, carried out vulnerability assessments. However, no outside auditors reviewed the system during or after the pilot period.

Despite these omissions, the BOK noted in the pilot report's tenth note that thorough pre-launch evaluations were considered sufficient, and further security reviews were deemed unnecessary. Nonetheless, concerns about potential risks in the deposit-token system emerged following its market introduction.

The planned second phase of the program aims to expand participation to 500,000 users, incorporate additional banks, and introduce advanced features like programmable payments and biometric authentication. This expansion heightens the importance of full security oversight.