South Korea’s CBDC Pilot Skipped Independent Security Audits — And The Red Flags Are Piling Up

(SeaPRwire) –

By: Silas Sterling

Crypto infosec circles lit up last week when Financial Supervisory Service documents came to light. The Bank of Korea spent months hyping Project Han River as a model for responsible CBDC testing. Open source security contributors on Mastodon and GitHub spotted the audit gap within hours of the docs going public. Most mainstream coverage brushed past the detail, but anyone who’s ever audited critical financial code knows self-led reviews are a massive red flag for unaddressed vulnerabilities. The BOK’s marketing for the pilot framed it as a secure, well-governed test of future digital payment infrastructure, and the newly revealed gaps undermine every one of those claims.

The first phase of the retail CBDC pilot ran between April and June last year. Pre-launch security reviews and vulnerability assessments wrapped up in February, months before live transactions went live. Woori Bank and NongHyup Bank used their internal inspection teams for the bulk of the checks. They were joined by the Financial Security Institute and SK Shields, a commercial cybersecurity firm with existing service contracts with both lenders. No fully independent, third-party auditor with no ties to the pilot participants was brought in to sign off on the code before testing began. No logs or public records confirm any external firm reviewed the system for bugs or exploits that emerged during live user testing.

The BOK’s official post-pilot report dismissed claims of security weaknesses in its deposit token infrastructure. The report leaned entirely on findings from those pre-launch reviews, with no data from live transaction testing included to validate its claims. No existing regulatory records show any independent security audit was conducted after the pilot concluded. Regulatory coordination across the broader CBDC initiative is almost non-existent. FSS records show only one formal consultation for CBDC or deposit token products over three years, for a Shinhan Bank insurance product tied to deposit tokens. There was no regular regulatory check-in scheduled during or after the pilot to assess security performance.

The BOK claims no additional audits were needed because pre-launch checks were comprehensive, and followed existing FSS supervisory rules. Industry participants have repeatedly pushed back, noting independent public audits would drastically improve public trust in digital currency projects. Preparations for the second phase of Project Han River are already paused. Participating banks raised concerns about high implementation costs and low commercial viability for expanded features like peer-to-peer transfers and merchant payment support. The South Korean government is still moving full steam ahead on other blockchain payment initiatives, regardless of the criticism. Gyeonggi Province plans to launch a government-backed blockchain stablecoin pilot running from August through February 2027, and authorities recently released a broader roadmap covering won-backed stablecoins, institutional CBDC pilots, tokenized government bonds, deposit tokens, and participation in the Bank for International Settlements’ Project Agora.

Any state-issued digital currency that refuses to publish independent, public security audits of its live infrastructure does not prioritize user safety or financial sovereignty. Users have no way to verify their transactions are secure, their data is not being misused, or the system is not vulnerable to outside exploits. The government’s refusal to mandate these checks for its CBDC pilot, paired with plans to roll out more un-audited blockchain payment tools, sets a dangerous precedent for every person who would be forced to use these systems.

Author bio: Silas Sterling, veteran kernel contributor and editor-in-chief of an open-source security digest focused on decentralized and state digital currency infrastructure risks.