News archive

Security disclosure and enforcement

Thai SEC files criminal complaint over Bitkub reporting after a 1.7 billion baht cyberattack

Thailand’s SEC says a May 2021 cyberattack removed customer assets in 16 cryptocurrencies and alleges that Bitkub and former directors submitted reports that did not reflect the material change.

Bangkok skyline representing Thai regulatory action
Image: CoinDesk / Walkerssk

What the Thai SEC announced

Thailand’s Securities and Exchange Commission announced that it had filed a criminal complaint with the Economic Crime Suppression Division against Bitkub Online Co., Ltd. and former directors. The complaint alleges false statements to the SEC under Thailand’s Emergency Decree on Digital Asset Businesses. It also covers allegations that former directors made false entries in a juristic person’s documents. The regulator said it would monitor the legal proceedings and cooperate with enforcement authorities.

The complaint follows an SEC investigation into a cyberattack in May 2021. According to the regulator, digital assets in 16 cryptocurrencies were stolen and some customer assets were withdrawn from the exchange, with an approximate value of 1.7 billion baht. The SEC said later information showed that Bitkub had procured assets to replace those stolen beginning on October 31, 2021. The current announcement therefore concerns both the underlying security event and how its effect was reported.

The alleged reporting failure

The SEC focused on Bitkub’s daily net-capital report, known as Form DA 1. It said reports covering May 10 through October 30, 2021 did not indicate that the exchange’s asset balance had materially changed because of the theft. The regulator characterized that reporting as false statements. Former directors responsible for submitting the forms during the period were included in the complaint, alongside allegations concerning entries made in corporate documents.

Net-capital and asset reports are not administrative trivia. They help a regulator evaluate whether an exchange has sufficient resources, whether customer obligations are covered and whether a security event changed the company’s financial position. If a material theft is absent, the regulator may see a healthier picture than actually existed. Users do not usually receive these forms, but they depend on the supervisory process that the forms support. Delayed accuracy can therefore weaken protection even when assets are later replaced.

Security loss and customer reimbursement are different questions

The regulator’s statement separates the theft from later replacement of the assets. Replenishing customer assets can prevent or reduce direct customer loss, but it does not erase the compromise, the period of undercoverage or the governance decisions made after discovery. A complete assessment must ask when the platform detected the attack, how access was obtained, which wallets and controls failed, when customers and regulators were told, and what evidence shows that replacement assets were actually available.

Cexvia does not equate a historical wallet loss with present insolvency. The SEC said replacement assets were procured starting at the end of October 2021, and the announcement does not state that current customer balances are missing. At the same time, reimbursement should not turn a security incident into a non-event. An exchange’s response capacity, insurance or shareholder support is positive evidence, while delayed disclosure and allegedly inaccurate reporting are negative evidence in separate rating dimensions.

A complaint is not a conviction

The Thai SEC’s release is a primary official source for the complaint and the regulator’s findings, but the next legal steps matter. Filing with the Economic Crime Suppression Division initiates investigation and enforcement; prosecutors and courts determine later outcomes under the applicable procedure. Bitkub and the former directors may contest facts, legal interpretations or responsibility. Cexvia therefore describes the false-reporting claims as allegations and does not state that a court has convicted the defendants.

That evidentiary distinction does not make the event irrelevant before judgment. A regulator’s completed investigation and criminal referral are material facts affecting governance and transparency risk. The appropriate conclusion is conditional and specific: there is an official allegation that regulatory reports failed to reflect a major theft, and the case remains unresolved. Future charging decisions, defense responses, settlements or judgments should be added to the record without rewriting what was known at each stage.

What the case says about exchange transparency

Security controls determine whether an attack succeeds; disclosure controls determine whether users, directors and regulators can respond accurately. A platform can improve wallets while still have weak escalation, accounting or reporting. Strong governance requires incident classification, immediate preservation of evidence, reconciliation of customer liabilities, independent approval of regulatory reports and a clear threshold for public notice. Those controls are especially important when disclosure might trigger customer withdrawals or reputational damage.

The reported explanation that secrecy could avoid panic illustrates the conflict. Preventing a disorderly run can be a legitimate operational concern, but withholding a material asset loss can deprive users and the regulator of informed choices. The solution is not uncontrolled rumor; it is accurate, staged communication coordinated with containment and liquidity planning. A licensed exchange receives public trust partly because it must report truthfully when bad events occur, not only because it can process trades during normal conditions.

What users and Cexvia will monitor

Users should look for Bitkub’s formal response, current proof of customer-asset coverage, security remediation, audit evidence and any changes required by the Thai SEC. They should verify that their own statements and withdrawal records are complete, use unique credentials and phishing-resistant two-factor authentication, and avoid storing more on an exchange than needed for trading or local fiat access. A successful small withdrawal is useful operational evidence, although it cannot prove full platform solvency.

Cexvia will track the complaint through police, prosecutorial and court stages, and keep the 2021 security event separate from the 2026 regulatory action. A final judgment, settlement, remediation order or independently verified disclosure improvement could change the assessment. The conclusion today is already concrete: replacement of the assets reduces direct loss evidence, but the alleged reporting gap materially weakens confidence in historical transparency and justifies heightened scrutiny of Bitkub’s current incident-reporting controls.

Cexvia conclusion

Bitkub replaced the missing assets, but the alleged six-month reporting gap is a serious transparency failure

The official record establishes that the Thai SEC filed a criminal complaint and states its investigative findings. A complaint begins a law-enforcement process; it is not a final criminal judgment against the company or former directors.

Risk meaning
The event adds both a historical security incident and a current regulatory case to Bitkub’s record. Customer balances were reportedly replaced from October 2021, but users and the regulator may have lacked timely information needed to judge the platform’s capital and security position.
User action
Bitkub users should verify current custody and incident disclosures, retain statements, enable strong account security and avoid keeping balances larger than their operational need. Monitor the criminal process and the exchange’s formal response rather than relying on social-media claims about the old attack.
Securities and Exchange Commission, Thailand