South Korea's inaugural central bank digital currency (CBDC) pilot was carried out without an independent government security audit, relying mainly on internal reviews by participating banks before launch, according to documents obtained by Maeil Business.
Security Review Process and Concerns
The Financial Supervisory Service (FSS) submitted data to lawmaker Lee Heon-seung showing no separate security inspection took place during or after the Bank of Korea’s CBDC pilot, which ran from April to June last year. Instead, the only security work performed prior to the pilot was an IT security review and vulnerability assessment conducted in February. These assessments partially depended on self-inspections from Woori Bank and NongHyup Bank, alongside contributions from the Financial Security Institute and cybersecurity firm SK Shields.
The arrangement raised concerns since the same banks involved in the pilot also helped evaluate the systems’ security. No evidence of an external government inspection or audit after the pilot was found in the reviewed documents.
The Bank of Korea responded to security worries in its official report on the pilot, denying claims that deposit tokens tested during the project were vulnerable to IT security risks. It emphasized extensive internal security reviews conducted before initiating Project Han River, South Korea’s CBDC testing program. However, Maeil Business noted that the bank’s statements appeared to defend its own evaluations rather than presenting results from an independent third party.
The absence of an external audit is notable because the pilot tested infrastructure potentially foundational to South Korea’s future payment system. The conclusion that security risks were unfounded was based on evaluations prepared by entities participating in the pilot.
Disclaimer: This material is for informational purposes and does not constitute financial advice.



