South Korea has intensified its oversight of cryptocurrency platforms, and Bithumb has now become the clearest example of how costly compliance failures can be. According to local reporting, the country’s Financial Intelligence Unit, or FIU, fined Bithumb 36.8 billion won, equal to about $24.6 million, and ordered a six-month partial suspension of services affecting new users. The enforcement action follows the discovery of widespread failures tied to anti-money laundering controls and customer verification obligations.
Regulators said the exchange committed roughly 6.65 million breaches of South Korea’s AML and customer due diligence rules. Of those, around 3.55 million involved failures to properly verify customer identities, while about 3.04 million involved transactions that should have been blocked but were nevertheless allowed to proceed. Authorities also identified 45,772 transactions connected to 18 unregistered overseas exchanges, adding a cross-border compliance dimension to the case.
The sanctions go beyond a monetary penalty. Bithumb’s CEO received a formal reprimand, and the exchange’s reporting officer was handed a six-month suspension. At the same time, regulators stopped short of a full operating ban. Existing customers can continue to trade on the platform, while the restrictions primarily target new user account activity, including deposits and withdrawals. In practical terms, Bithumb remains open to its current customer base, but its ability to onboard and activate new users will be constrained for half a year.
Founded in 2014, Bithumb has long ranked among South Korea’s largest exchanges by trading volume. The fine is also notable because it is now the largest ever imposed on a virtual asset exchange in the country, slightly exceeding the 35.2 billion won penalty that was handed to Upbit in 2025. The violations were reportedly uncovered during on-site inspections of South Korea’s five largest crypto exchanges conducted between 2024 and 2025, suggesting that this is part of a broad supervisory campaign rather than an isolated action aimed at a single firm.
Why Bithumb was fined: millions of AML and verification failures
At the heart of the case is a simple regulatory principle: for centralized exchanges, customer identification and AML monitoring are not optional administrative steps. They are core operating requirements. The FIU’s findings indicate that Bithumb’s weaknesses were not limited to a handful of edge cases. Instead, the scale of the violations suggests deeper problems in internal controls, workflow design, and the practical enforcement of compliance rules across the platform.
The 3.55 million identity verification failures are especially significant because they point to weaknesses at the entry point of exchange services. If a platform cannot properly confirm who is opening an account, regulators have reason to question the reliability of subsequent monitoring, suspicious activity detection, and transaction screening. In a market such as South Korea, where crypto regulation has become steadily more structured, inadequate customer verification is treated as a direct threat to financial transparency and market integrity.
The second major category, the approximately 3.04 million transactions that should have been blocked but were not, raises a different but equally serious concern. It suggests that the exchange either had rules that failed to trigger effectively, or it identified problematic activity without properly stopping it. Whether the issue stemmed from poor system settings, gaps in manual review, or failures in escalation procedures, the result is the same: transactions that should not have gone through were processed anyway. That is exactly the type of weakness regulators focus on when assessing whether an exchange can be used as a channel for illicit funds.
Authorities also highlighted 45,772 transactions involving 18 overseas exchanges that were not registered. This matters because South Korea has increasingly emphasized oversight of foreign virtual asset service providers that interact with domestic users or platforms. When a major exchange continues to transact with unregistered offshore entities, regulators may see it as evidence that the exchange is not adequately managing cross-border compliance risks. In other words, this is not only a local KYC issue. It also reflects how well the platform can control external counterparties and outbound transaction exposure.
South Korean regulators have repeatedly stressed that strict compliance with customer verification and AML obligations is critical for maintaining trust in the market. For retail traders, those requirements may feel distant from day-to-day trading. But for an exchange, they shape access to banking relationships, fiat on-ramps, and long-term regulatory standing. Bithumb’s case sends a broader message to the industry: even top-tier platforms with large market share can face severe penalties if compliance systems do not work in practice.
What the sanctions mean: existing users stay active, new users face restrictions
One of the most important details in the enforcement action is that the suspension is only partial. Bithumb is not being shut down entirely. Existing customers are still allowed to trade, which means the exchange’s core market activity can continue for now. The restrictions mainly affect new user account functions, including deposits and withdrawals. This is a targeted regulatory design. It punishes the platform and limits expansion, while avoiding the kind of abrupt, full-platform disruption that could create broader market instability for existing customers.
Even so, a six-month restriction on new user services can have a meaningful business impact. Crypto exchanges depend heavily on fresh account creation, fiat onboarding, and new-user conversion. If newly opened accounts cannot fully activate important functions, marketing campaigns become less effective and competitive momentum slows. In a crowded domestic market like South Korea, six months is long enough for rivals to capture a significant portion of new demand.
The individual sanctions are equally revealing. In addition to the fine, the FIU formally reprimanded Bithumb’s CEO and suspended the exchange’s reporting officer for six months. That indicates the regulator is not treating the matter solely as an abstract corporate failing. It is also assigning accountability to management and compliance leadership. For other exchanges, this raises the standard internally: AML is no longer something that can be treated as a back-office legal formality. It is now a governance issue with direct consequences for named executives.
The FIU will finalize the fine after giving Bithumb at least 10 days to submit its opinion. So while the direction of the enforcement action is already clear, the process still leaves room for the exchange to respond formally. Even with that procedural step, the broader signal is unmistakable. South Korea is moving from general compliance messaging to hard enforcement, using large fines and business restrictions to force operational correction.
Seen in a wider context, the case reflects a sustained tightening of oversight across the country’s crypto sector. Because the violations were discovered during on-site inspections of the five largest exchanges between 2024 and 2025, market participants should assume that similar reviews may continue. Customer due diligence, suspicious transaction detection, cross-border counterparty checks, and reporting discipline are all likely to remain high-priority areas for regulators.
Bithumb’s Bitcoin mistake during the Random Box promotion
The AML case gained even more attention because it followed another high-profile Bithumb incident just weeks earlier. During a promotional campaign called Random Box, the exchange accidentally sent users Bitcoin worth billions of dollars in aggregate. The event had originally been designed to distribute small cash rewards at around 6 p.m. local time. Winners were supposed to receive between 20,000 and 50,000 Korean won.
Instead, staff reportedly entered the payout unit as Bitcoin rather than won. That single operational error transformed what should have been a modest promotional expense into an enormous crypto distribution. According to social media screenshots and user accounts, some users received at least 2,000 BTC each. Based on Bitcoin prices near 98 million won per BTC at the time, that amounted to roughly 196 billion won per person.
The effect was not limited to internal accounting confusion. The mistake briefly caused Bitcoin prices on Bithumb to fall more than 10% below broader market levels. For traders, such a sudden platform-specific discount signals severe short-term dislocation in pricing, liquidity, and operational stability. Bithumb said the incident did not result in customer losses, but the episode still raised fresh questions about the exchange’s internal controls.
Placed alongside the AML enforcement action, the Random Box incident highlights a broader pattern. The two events are different in nature, but both point to weaknesses in execution and control. One involved a promotional payout entered in the wrong unit. The other involved large-scale failures in verification and transaction screening over an extended period. For both users and regulators, these are not minor errors. They affect confidence in whether the exchange can reliably manage risk in both front-end operations and back-end compliance.
At the time of writing, Bitcoin is trading near $74,000. Market prices will continue to move, but the policy signal coming out of South Korea is already clear. Exchanges are expected to maintain strong customer verification, enforce AML obligations, and build internal systems that reduce the risk of both compliance breaches and operational mistakes. For Bithumb, the combination of a record fine, a six-month restriction on new-user services, and a recent high-profile payout error means the next phase will likely center on rebuilding trust through stronger controls rather than simply defending its market position.

