Thailand Sec files criminal case against bitkub over concealed $47m crypto hack

5 минут чтения

Thailand’s SEC launches criminal case against Bitkub over concealed $47 million hack

Thailand’s securities regulator has filed a criminal complaint against local crypto heavyweight Bitkub and two of its former directors, accusing them of hiding the impact of a multimillion‑dollar hack from authorities and submitting misleading financial information in the aftermath.

According to details disclosed in Thai press, the Securities and Exchange Commission has referred the case to the Economic Crime Suppression Division, a specialist police unit that investigates complex financial wrongdoing. The dispute centers on a cyberattack in May 2021, when hackers allegedly siphoned off 16 different cryptocurrencies and tokens from the exchange, with a combined value of around 1.7 billion baht (approximately 47 million dollars at the time).

Following the breach, Bitkub was required under Thailand’s Digital Asset Business Decree to report accurate information about its financial position and capital adequacy. Instead, regulators claim, the exchange’s daily net capital reports from May through October 2021 showed no meaningful deterioration in its asset base, despite the sizable loss. By maintaining apparently stable figures, Bitkub is alleged to have concealed the true impact of the theft and failed to reflect the hack in its regulatory filings.

The SEC argues that these filings violated core provisions of the Digital Asset Business Decree, which obliges licensed platforms to truthfully disclose financial data and to promptly inform authorities of any incidents that could affect their solvency, operations, or customers’ funds. In the regulator’s view, failing to account for a 1.7‑billion‑baht outflow is not a technical oversight but a serious breach of disclosure and reporting rules.

Two former Bitkub directors, Sakolkorn Sakavee and Thaweesap Rawan, are specifically named in the complaint. Regulators allege that the pair authorized or were responsible for entries that did not accurately reflect the damage from the cyberattack. By certifying reports that smoothed over the loss, they are accused of intentionally misleading the SEC into believing that Bitkub’s capital position and custody arrangements remained intact and sufficient.

For Thai authorities, the core issue is not only that the hack occurred, but that the resulting shortfall was allegedly obscured for months. Under most digital‑asset regulatory regimes, cyber incidents must be reported promptly, with clear information about what was stolen, how client funds were affected, and how the platform plans to cover any hole in its balance sheet. The SEC claims Bitkub’s filings did the opposite: they created the impression that nothing material had changed.

A criminal complaint of this kind is a significant escalation. It means the regulator believes there is enough evidence to warrant a police investigation and potentially criminal charges, not just administrative penalties or fines. If prosecutors decide to press charges and a court ultimately finds the exchange or its former directors guilty, potential consequences could include substantial financial penalties, suspension or revocation of licenses, and, for individuals, possible imprisonment under Thai law.

The case also underlines how regulators are sharpening their focus on transparency from crypto businesses. Hacks, exploits, and security lapses are unfortunately common in the industry, but authorities are increasingly intolerant of attempts to quietly absorb losses or delay disclosure. In the eyes of watchdogs, an undisclosed hack is tantamount to concealing a material risk from both regulators and customers.

Bitkub’s situation is particularly sensitive because the platform is one of Thailand’s best‑known digital‑asset exchanges, with a major role in onboarding local retail investors into crypto markets. Allegations that it masked a multimillion‑dollar hole in its books risk damaging public trust not only in the company but in the broader domestic crypto ecosystem, which has been trying to position itself as safer and more regulated than the early days of unregulated trading.

For investors and users, the episode underscores the importance of understanding how exchanges are supervised and what obligations they have toward regulators. In Thailand, the Digital Asset Business Decree requires licensed platforms to maintain adequate net capital, segregate customer assets, implement robust cybersecurity measures, and file accurate, up‑to‑date financial reports. Failure on any of these fronts can trigger regulatory action even if users are eventually made whole.

The complaint against Bitkub also fits into a wider global pattern. Around the world, regulators are moving from a light‑touch approach with crypto to one that more closely resembles oversight of traditional financial institutions. That includes demanding timely incident reporting, stress testing, and proof that an operator can withstand shocks such as hacks or market crashes without endangering client funds. Concealing a major breach runs directly counter to this emerging standard.

From a compliance and governance perspective, the case highlights how critical internal controls and board‑level oversight have become. Directors and executives are increasingly being held personally responsible for the accuracy of information sent to regulators. In practice, that means exchanges need clear incident‑response procedures, internal escalation paths, and audit trails showing how decisions were made and who approved financial disclosures after an incident.

For ordinary users trying to protect themselves, there are a few practical lessons. Relying solely on a single centralized exchange to hold significant amounts of crypto carries counterparty risk, regardless of how credible the platform appears. Diversifying custody-using a mix of self‑custody, hardware wallets, and, where necessary, multiple regulated exchanges-can limit the impact if one platform suffers a hack or governance failure. It is also wise to pay attention to public statements, audits, and regulatory news around any service that holds your assets.

The outcome of the investigation into Bitkub will likely shape how Thailand applies and possibly tightens its digital‑asset framework. A strong response could signal that regulators intend to treat non‑disclosure and misreporting in the crypto sector as seriously as similar offenses in banking and securities markets. Conversely, if the case stalls or results only in modest sanctions, it may raise questions about how effectively the rules are being enforced.

In any case, the message to exchanges operating in Thailand and in other jurisdictions with similar laws is clear: a hack, however damaging, may be survivable if it is handled transparently, reported quickly, and followed by concrete remediation. Attempting to bury or minimize the financial impact in official filings, by contrast, is increasingly likely to be treated not as a public‑relations tactic, but as a potential crime.