CryptaCount
EN
EnglishENDeutschDEEspañolESFrançaisFRItalianoIT日本語JA한국어KONederlandsNLPolskiPLPortuguêsPT
Log in Start Free

Thailand SEC Files Criminal Complaint Against Bitkub Over Alleged False Disclosures

CryptaCount Editorial · · 10 min read
ENFORCEMENT Thailand SEC Files Criminal ComplaintAgainst Bitkub Over Alleged FalseDisclosures

Thailand's Securities and Exchange Commission has filed a criminal complaint against Bitkub Online and two of its former directors, alleging that the exchange submitted false regulatory reports following a cyberattack in May 2021 that resulted in the theft of digital assets worth approximately 1.7 billion baht (around USD 50 million). For accounting firms advising digital asset businesses in Southeast Asia, and for CFOs responsible for regulatory filings at licensed exchanges, this case is a direct signal: net liquid capital reporting for crypto platforms carries the same legal weight as equivalent obligations in traditional financial services, and gaps in disclosure invite criminal, not just administrative, consequences.

Thailand SEC Files Criminal Complaint Against Bitkub Over Alleged False Disclosures

What the Thailand SEC Has Alleged

The SEC's complaint, announced on 24 July 2026, names Bitkub Online as the corporate respondent and identifies two former directors, Sakolkorn Sakavee and Thaweesap Rawan, as the individuals responsible for submitting company reports during the period under investigation. Both held leadership roles at the time the disputed filings were made.

The core disclosure allegation

According to the SEC, a cyberattack in May 2021 led to the theft of 16 categories of digital assets from Bitkub's wallets. The regulator says the stolen assets were eventually replaced by 31 October 2021, but that the daily net liquid capital reports filed between 10 May and 30 October 2021 did not reflect the reduction in the exchange's asset position caused by the theft. The SEC's position is that those reports created a misleading picture: one in which customer assets appeared unchanged and the exchange appeared not to have suffered any losses from the incident. The alleged violations span multiple provisions of Thailand's digital asset regulations.

Bitkub's public response

Bitkub disputed the SEC's framing in a post on X. The exchange said the case arises from a disclosure timing decision, not from fraudulent intent. Its stated rationale was that disclosing the wallet compromise immediately could have triggered a bank-run dynamic while the company was actively working to replace the stolen assets. Bitkub said its co-founders personally acquired equivalent digital assets to cover the shortfall, and that neither the company nor its customers ultimately incurred financial losses. The company added that it has since overhauled its governance, compliance, and security infrastructure. The criminal process will now proceed through formal investigation, potential prosecution, and court proceedings.

Why the Timing Matters: IPO Scrutiny and Governance Risk

The complaint lands at a sensitive moment. Bitkub's parent company has been exploring a potential public listing, including a possible offering in Hong Kong, a fact the company confirmed publicly in December 2025. A pending IPO places every historical disclosure under a microscope. Prospective investors, underwriters, and auditors will need to assess whether the alleged reporting failures create contingent liabilities, affect the integrity of historical financial statements, or trigger representations and warranties obligations in any listing documentation. Founded in 2018, Bitkub has grown into one of Thailand's largest digital asset exchanges by trading volume. That scale amplifies the systemic governance questions the SEC complaint raises.

The net liquid capital reporting obligation

Thailand's digital asset framework, administered by the SEC, requires licensed exchanges to maintain and report net liquid capital on a daily basis. This obligation exists precisely so the regulator can monitor whether a platform holds sufficient liquid assets to meet its obligations to customers at any given time. The SEC's allegation is not that Bitkub lacked capital at the end of the period, but that the reports filed during the five-and-a-half-month window between the attack and the replacement of the stolen assets did not accurately capture the real-time position. That distinction matters for accounting and legal analysis: even if the eventual outcome was that no customer suffered a loss, the regulatory duty to report an accurate daily position appears to have been treated by the SEC as a continuous, non-deferrable obligation.

Accounting and Reporting Implications for Crypto Exchanges

The Bitkub case exposes several layers of accounting complexity that will be directly relevant to any firm that advises or audits a licensed digital asset exchange, or any CFO overseeing one.

Asset theft as an impairment event, not a timing decision

Under most accounting frameworks, the theft or loss of an asset triggers recognition of that loss at the point the event occurs, or when the entity first has reliable information about it, whichever is earlier. The decision to defer disclosure to regulators while arranging replacement assets does not reset the accounting clock. A crypto exchange holding digital assets on behalf of customers has specific custodial obligations. If those assets are stolen, the exchange's own balance sheet may need to reflect either a liability to customers or a reduction in custodied assets from the moment of theft, depending on the structure of the custody arrangement and how the local accounting standard treats digital assets in that context.

Regulatory capital reports versus financial statements

Net liquid capital reports submitted to the Thailand SEC are regulatory filings, distinct from audited financial statements. However, the underlying data feeds both. If the regulatory reports for the May to October 2021 period showed no significant asset reduction, auditors reviewing the company's financial statements for the same period would need to determine whether the financial statements themselves were consistent with that position, or whether a different and accurate picture was presented to the auditors while a different one went to the regulator. That divergence, if it existed, would be a serious audit concern. Accounting firms with clients in the digital asset exchange sector should treat this case as a prompt to review how their clients handle the interaction between real-time regulatory reporting and the broader financial statement preparation process.

Using crypto accounting software to close the gap

One of the structural weaknesses the Bitkub case highlights is the difficulty of maintaining accurate, real-time asset positions across multiple wallet types when a security incident is active. Robust crypto accounting software that integrates directly with an exchange's on-chain activity, wallet infrastructure, and internal ledger can produce a continuous, timestamped record of asset positions. That kind of audit trail is not just operationally useful; it is increasingly what regulators expect to see when they review compliance. The question of whether a platform's reporting systems were capable of generating accurate daily net liquid capital figures, and whether those figures were then accurately reported, is likely to feature prominently in the investigation of this case. Firms evaluating digital asset accounting software for exchange clients should prioritise solutions that produce immutable, timestamped ledger entries and that flag discrepancies between on-chain balances and reported positions automatically.

Broader Enforcement Context in Southeast Asia

This action does not exist in isolation. Regulators across Southeast Asia and beyond have been steadily raising the bar for digital asset disclosures. The FATF's 7th targeted update on crypto compliance, which identified the enforcement gap as the central challenge in virtual asset regulation globally, provides important context: see our coverage of FATF's 7th targeted update on the global crypto enforcement gap. The Bitkub case is a concrete, country-level illustration of what that enforcement gap looks like when it closes. Separately, the ASIC enforcement action against a former finance director in Australia shows that personal liability for individuals who hold signing responsibility over regulatory filings is a real and growing feature of the enforcement landscape, not a theoretical one.

For accounting firms with clients operating licensed exchanges in Thailand or other ASEAN jurisdictions, the Bitkub complaint reinforces the need to document, at the point of any material security incident, exactly what was reported to whom and when. The gap between an internal decision to delay external disclosure and the regulatory obligation to file accurate daily reports is the precise fault line the Thailand SEC has chosen to prosecute.

Practical Steps for Accounting Firms and CFOs

The details of this case point to a set of concrete actions that advisers and in-house finance teams at digital asset exchanges should address now, before any incident occurs.

Review incident disclosure protocols against regulatory filing obligations

Many exchanges have internal incident response procedures that prioritise operational containment before external communication. Those procedures need to be mapped explicitly against each regulatory reporting obligation, including any that have a daily or near-real-time cadence. Where those obligations require the reporting of accurate asset positions, a policy of delaying disclosure while remediation is underway may put the entity in breach regardless of the eventual outcome.

Establish a clear chain of personal responsibility for regulatory filings

The Thailand SEC's decision to name two former directors personally, not just the corporate entity, is a deliberate signal about individual accountability. Finance directors, compliance officers, and any other individual who signs or approves regulatory filings at a licensed digital asset exchange should have a documented understanding of what each filing certifies, what the legal consequences of inaccuracy are, and what the internal process is for verifying the underlying data before submission.

Audit the interaction between incident management and financial reporting systems

When a security incident affects the asset base of an exchange, the incident management workflow and the financial reporting workflow need to be connected, not siloed. CFOs should verify that their crypto bookkeeping software and reporting stack is capable of capturing an asset-loss event at the moment it is identified internally, and that the output feeds directly into regulatory capital calculations rather than being subject to manual adjustment downstream.

Thailand SEC Files Criminal Complaint Against Bitkub Over Alleged False Disclosures

FAQ

What exactly did the Thailand SEC allege against Bitkub?

The SEC alleged that Bitkub Online and two former directors submitted daily net liquid capital reports between May and October 2021 that did not accurately reflect the impact of a cyberattack in which digital assets worth approximately 1.7 billion baht were stolen. The regulator says the filings gave the impression that customer assets and the exchange's financial position were unaffected.

Does Bitkub deny wrongdoing?

Bitkub has disputed the SEC's characterisation of events. The exchange says the decision to delay disclosure was made to avoid a bank-run scenario while it worked to replace the stolen assets, and that co-founders personally covered the shortfall. Bitkub says no customers ultimately suffered financial losses. The matter will now be tested through the Thai criminal justice process.

What is net liquid capital reporting and why does it matter?

Net liquid capital reporting is a regulatory obligation for licensed digital asset exchanges in Thailand. It requires the exchange to file daily reports showing that it holds sufficient liquid assets to meet its obligations to customers. The obligation is designed to give the regulator continuous visibility into the financial resilience of licensed platforms. Accurate reporting is a legal requirement, not a discretionary disclosure.

What are the personal liability risks for finance directors at digital asset exchanges?

The Thailand SEC's decision to name individual former directors in the criminal complaint illustrates that personal liability for regulatory filing failures is a live enforcement risk, not just a corporate one. Finance directors and compliance officers who have signing responsibility for regulatory reports need clear documented processes for verifying the accuracy of those reports before submission, particularly following any material operational or security event.

How should accounting firms advising exchange clients respond to this development?

Firms should review their clients' incident disclosure protocols against each regulatory reporting obligation, verify that the financial reporting infrastructure captures asset-loss events at the point they occur rather than after remediation, and confirm that individual executives understand the personal legal consequences of inaccurate regulatory filings. Engagements should also consider whether historical filings for any past security incidents were consistent across regulatory submissions and audited financial statements.

Source: Cointelegraph

THGeneralEnforcementEnforcement

Related articles

Enforcement
Thailand Issues Arrest Warrant for Chinese Businessman Over Mining Power Theft
Enforcement
ASIC Sentences Former Finance Director Over Crypto Scam Proceeds: What Accounting Firms and CFOs Must Act On Now
Enforcement
US Seizes $25M in Crypto Tied to Investment and Romance Scams: What Accounting Firms and CFOs Must Act On Now
Enforcement
SEC Pays $150K to Settle Coinbase Records Lawsuit Over Deleted Gensler Texts