Thailand’s Securities Regulator Charges Bitkub and Former Directors Over Undisclosed $47M 2021 Hack
Table of Contents
You might want to know
Could failing to disclose a security breach constitute criminal wrongdoing for a licensed digital-asset platform?
How did the exchange claim to protect customers after the alleged theft, and what are the potential consequences for those involved?
Main Topic
Thailand’s Securities and Exchange Commission (SEC) has filed a criminal complaint against the cryptocurrency exchange Bitkub and two former directors, accusing them of submitting misleading reports following a cyberattack in May 2021. The regulator’s complaint, reportedly submitted to the Economic Crime Suppression Division, centers on the alleged theft of multiple digital assets from Bitkub valued at roughly 1.7 billion baht (about $47 million) and on subsequent daily filings that, the SEC says, failed to reflect the loss.
According to the SEC’s account, Bitkub submitted daily net-capital reports from May through October 2021 that showed no material change in the exchange’s asset figures, thereby concealing the drain of digital assets caused by the hack. If proven, these omissions would contravene Thailand’s Digital Asset Business Decree, which obliges licensed firms to report accurate capital and asset positions to the regulator. The SEC’s filing alleges that the daily reports were false or misleading and that company officers intentionally omitted the theft from their disclosures.
The two former directors named in the complaint — identified in local reporting as Sakolkorn Sakavee and Thaweesap Rawan — are accused of making entries intended to mislead regulators into believing customer assets remained intact. The matter has now been transferred to police and prosecutors, who will determine whether to move the case to court. Criminal liability in such circumstances would typically depend on proving intent to deceive and a statutory breach of reporting obligations under the applicable digital-asset regulatory framework.
Bitkub’s public response framed the issue as a retrospective reporting decision tied to an incident five years earlier. Company statements stressed that customer funds were never left unrecovered: the exchange said its co-founders covered the stolen amounts at the time by purchasing replacement assets so that customers did not suffer losses. The firm also stated that the rationale for not disclosing the theft immediately was to avoid triggering a panic withdrawal or a “bank run” that could have imperiled the platform and its users. In support of that position, Bitkub announced that the SEC had confirmed its holdings were intact as of September 2025.
In a recorded statement later shared publicly, one former director reportedly accepted personal responsibility, saying he altered filings without informing colleagues and withheld news of the breach out of fear that disclosure would cause mass withdrawals and destroy the exchange. He said the founders injected personal funds to replace stolen assets until every affected customer was made whole, apologized, resigned from the boards, and pledged cooperation with regulators. These admissions, if accurately translated and verified, may factor significantly into prosecutorial decisions.
The case arrives while Bitkub — once the leading exchange in Thailand — pursues strategic growth and a potential public listing. Market shifts and competition, including the expansion of Binance’s local operations, have reshaped market share since 2021. Bitkub previously postponed a proposed initial public offering on the Stock Exchange of Thailand amid market weakness and later considered a sizable Hong Kong offering. Ongoing regulatory inquiries and criminal proceedings may affect capital-raising plans and public-market readiness.
This key insight significantly impacts the understanding of regulatory compliance in digital-asset markets: transparency obligations and timely disclosure of security incidents are central to the legal and reputational standing of licensed crypto firms. Even if customer balances are ultimately restored by private means, failing to disclose material events to regulators can give rise to criminal investigations and civil enforcement actions.
From an industry perspective, the situation highlights the tension between short-term crisis management and long-term regulatory compliance. Firms may face hard choices during a breach: immediate public disclosure could destabilize confidence and cause mass withdrawals, while withholding information risks regulatory enforcement and criminal exposure. Regulators generally favor prompt reporting to preserve market integrity and enable coordinated responses that protect customers and financial stability.
For stakeholders — customers, investors, and potential public-market investors — the case underscores the importance of robust internal controls, transparent governance, and clear incident-response protocols. Independent audits, well-documented decision-making during crises, and clear communication with regulators can mitigate both operational and legal risks. The ultimate legal outcome will depend on investigative findings about what was known by company officers, when it was known, and whether actions taken were lawful under Thailand’s digital-asset regulations.
Key Insights Table
| Aspect | Description |
|---|---|
| Incident | A May 2021 hack reportedly drained ~1.7 billion baht (~$47M) in 16 digital assets from Bitkub. |
| Regulatory allegation | Thailand’s SEC alleges false or misleading daily net-capital filings from May–October 2021 that hid the loss. |
| Individuals named | Two former directors are accused of making entries that misled regulators about customer asset safety. |
| Exchange response | Bitkub says founders covered the stolen assets immediately to ensure customers were not out of pocket and cites concerns over a potential bank run for nondisclosure. |
| Legal path | Case referred to police and prosecutors; they will decide whether to press charges and take the matter to court. |
| Market impact | Ongoing investigations may complicate Bitkub’s plans for public listings and affect investor confidence. |
Afterwards...
Looking ahead, this episode reinforces the need for improved incident reporting standards, stronger governance, and better crisis communication in the digital-asset sector. Regulators and exchanges should continue developing frameworks that balance the need for timely disclosure with practical mechanisms to protect customers during active incidents.
Key areas for further work include enhancing real-time monitoring of exchange reserve reporting, standardized breach notification timelines, clearer legal guidance on acceptable mitigation measures taken by founders or operators, and independent verification of reserve restorations. Encouragingly, initiatives that promote transparency — such as cryptographic proof-of-reserves, third-party attestations, and standardized regulatory reporting APIs — can reduce information asymmetry between platforms and regulators while preserving market stability.
Exploring these areas can help align operator incentives with customer protection and regulatory expectations, reducing the likelihood that well-intentioned but opaque decisions lead to legal exposure and diminished public trust.