
South Korea's Digital Asset Exchange Alliance (DAXA) has introduced new API key standards for local crypto exchanges following a warning from the Financial Supervisory Service (FSS). According to reports from TechFlow, the new policy targets improper API key sharing and possible market abuse, with DAXA now forcing suspicious API keys to expire after warnings, monitoring, and user checks. The rule specifically addresses cases where users lend or share API keys with others, which can give outside tools access to price checks, balances, orders, deposits, and withdrawals. As per TechFlow, the policy was launched on May 29 and applies across all DAXA member companies, including Upbit, Bithumb, Coinone, Korbit, and Gopax.
The FSS warning revealed that API-based trading accounts for around 30% of South Korea's domestic crypto market turnover, as reported by TechFlow. The regulator has cautioned that automated trading can create false volume and distort token prices through repeated small trades, spoofed orders, and coordinated activity across many accounts. These actions can make tokens appear more active than they actually are, with the FSS also warning users about high-frequency trading code shared online and urging investors to avoid chasing sudden price spikes without clear reasons. According to TechFlow, the move signals a sharper regulatory focus on market fairness as South Korean regulators pay closer attention to automated trading with nearly a third of crypto volume tied to automated systems.
Under the new standard, exchanges can increase monitoring after suspicious activity, send warnings, require identity checks again, and force API keys to expire. According to TechFlow, the response level depends on the assessed risk of the activity, with platforms able to issue warnings, force re-authentication, or permanently expire keys. Member exchanges will also require users to re-verify their identity following warning notifications, creating a layered defense system. The most significant security enhancement is the introduction of IP whitelisting, which restricts API key access to pre-registered IP addresses only. This means that even if someone obtains another user's API key, they cannot use it from an unregistered device or location, adding practical barriers against unauthorized access.
Kim Jae-jin, DAXA's executive vice chairman, stated that the group will "respond swiftly to new and emerging threats" with user protection remaining the main value behind the new measures. As reported by TechFlow, the rule does not ban API trading but instead targets cases where users hand over keys or allow others to trade through their exchange accounts. According to TechFlow, Kim added that the alliance and its member companies will respond quickly to new threats and that strong measures will follow wherever user protection demands it. The new standards add to South Korea's broader push toward tighter crypto exchange oversight, following previous measures including five-minute balance checks, automatic trading halts, and monthly audits after a major Bithumb error.