DarkReading

Thailand SEC Complaint Over 2021 Bitkub Cyberattack Case


Thailand’s cryptocurrency exchange Bitkub has rejected allegations of fraud after the Thailand SEC filed a criminal complaint related to the company’s disclosures following the Bitkub cyberattack in 2021. The case focuses on how the exchange reported the impact of the cyberattack on Bitkub to regulators, rather than on the safety of customer funds. 

In response to the complaint, Bitkub stated that all customer assets currently held on its platform remain safe, fully accounted for, and protected in accordance with applicable regulations. The company argued that the allegations stem from decisions made during the aftermath of the 2021 security breach and do not reflect fraudulent conduct. 

Thailand SEC Files Complaint Over the 2021 Bitkub Cyberattack 

On 23 July 2026, the Thailand SEC filed a criminal complaint against Bitkub Online Co., Ltd. and its former directors, Sakolkorn Sakavee and Thaweesap Rawan. The regulator alleged that the company’s daily net capital reports submitted between 10 May and 30 October 2021 failed to accurately reflect the material reduction in its digital asset holdings caused by the Bitkub cyberattack. 

According to the regulator, the reports did not disclose the impact of the theft on the company’s asset balance. The Thailand SEC also accused the two former directors of making false entries in company documents that gave the impression that customer assets were still being held normally and that the company had not suffered any damage. 

The complaint has been referred to Thailand’s Economic Crime Suppression Division for further investigation. Following that process, the matter may be forwarded to prosecutors and the courts. The Thailand SEC noted that filing a criminal complaint does not represent a final determination of guilt. 

Bitkub Says Disclosure Decision was Intended to Prevent Customer Losses

Following media reports about the complaint, Bitkub published a statement on LinkedIn explaining its position on the cyberattack and the subsequent reporting decisions. 

The company said the allegations relate to an incident in early May 2021, when one of its digital asset wallets was compromised by cybercriminals. Bitkub acknowledged that the breach was not disclosed at the time. 

According to the company, the individual responsible for disclosure obligations deliberately withheld information about the wallet compromise. Bitkub said the decision was made to avoid triggering a “bank run,” or mass withdrawals of digital assets by customers, while the company worked to replace the stolen assets. 

The exchange stated: 

“The decision of such individual not to disclose the incident was made with the intention to prevent a bank run—that is, a mass withdrawal of digital assets by customers upon learning of the theft—which could have rendered the Company unable to procure sufficient replacement digital assets for the customers while the recovery process was still ongoing.” 

Bitkub added that such a scenario could have resulted in significant customer losses and broader damage to Thailand’s digital asset industry. 

The company also stressed that, at the time of the Bitkub cyberattack, all of its digital asset wallet security systems complied with standards prescribed by the relevant authorities and had been audited. 

Co-founders Replaced Stolen Assets After Cyberattack on Bitkub 

Although the digital assets stolen during the cyberattack on Bitkub were never recovered, the company said its co-founders voluntarily absorbed the financial loss. 

According to Bitkub, the co-founders purchased digital assets matching the same types and quantities as those stolen and transferred them to the company. As a result, the exchange said neither its customers nor the business ultimately suffered any financial loss from the incident. 

In its statement, Bitkub said: 

“As no bank run occurred, even though the stolen digital assets could not be recovered, the Co-Founders of the Bitkub Group voluntarily absorbed the loss by purchasing equivalent digital assets (in the same type and quantity as those stolen) and providing them to the Company. Consequently, neither the Company nor its customers suffered any financial loss from the theft.” 

Thailand SEC Previously Confirmed Customer Assets Were Intact 

Bitkub also pointed to the findings of an earlier inspection conducted by the Thailand SEC after reports of the Bitkub cyberattack surfaced online. According to the company, the regulator verified that, as of 8 September 2025, all customer assets held by the exchange were safe and fully accounted for. 

The company reiterated this point in its latest statement, saying: 

“At the outset, for the sake of clarity and mutual understanding, the Company wishes to affirm that all customers’ assets currently held by the Company are safe and fully accounted for. The Company reiterates its strict compliance with all applicable laws and regulations in safeguarding and maintaining customer assets.” 

Bitkub maintained that the criminal complaint relates to historical reporting practices between May and October 2021, more than five years ago, rather than to the current condition of customer assets or any ongoing security concerns. 

As the investigation proceeds, the case will determine whether the company’s reporting following the Bitkub cyberattack complied with regulatory requirements. For now, the complaint remains an allegation, and the legal process involving the Thailand SEC, investigators, prosecutors, and the courts has yet to reach a final conclusion. 



Source link