Thai Digital Asset Operators Now Face Joint Cybercrime Liability in 2026

Thailand put digital asset operators on the hook for user fraud losses under its amended cybercrime law. Here's what's required and what it means for Thai crypto traders.
Thai Digital Asset Operators Now Face Joint Cybercrime Liability in 2026

Thailand’s amended cybercrime legislation introduced a significant structural change for digital asset operators: they can now be held jointly liable for fraud damages suffered by their users if they fail to meet new security and compliance standards. This isn’t a hypothetical — the provisions are live, they carry financial liability, and they change the compliance calculus for every licensed and unlicensed digital asset business operating in or targeting Thailand.

What Changed and When

Thailand amended two pieces of legislation: the Emergency Decree on Digital Asset Businesses (2018) and the Emergency Decree on Measures for the Prevention and Suppression of Cybercrime (2023). The amendments established that digital asset operators join a category of regulated entities — alongside banks, telecom companies, and social media platforms — that bear joint liability for cybercrime damages if they fail to comply with mandated security measures.

This is the same framework that already applied to banks when users lost money to scams. Banks that failed to implement fraud-screening systems have faced regulatory action and restitution orders in Thailand. Digital asset operators are now in the same legal position.

What the New Compliance Requirements Look Like

The amended rules require licensed digital asset business operators to implement security measures comparable to those used in the banking sector. Specifically:

  • Transaction screening and suspension: Operators must screen transactions and accounts for suspicious activity and have the ability to suspend them. This means real-time or near-real-time fraud detection systems — not just post-hoc reporting.
  • Blacklisting: Operators must maintain and act on blacklists of individuals or wallet addresses linked to cybercrimes. The SEC and other agencies can compel an operator to block specific addresses.
  • Refund mechanisms: Operators must establish mechanisms to expedite compensation to fraud victims. The timeline and process aren’t fully specified in the amendments, but “expedite” implies faster than the standard civil court route.
  • Information sharing: Operators must share information with relevant government agencies — including the Economic Crime Suppression Division (ECSD), the Anti-Money Laundering Office (AMLO), and the MDES.

What Joint Liability Actually Means

Joint liability means that if a user loses funds to a cybercrime conducted through or facilitated by a digital asset operator’s platform — and the operator failed to implement required security measures — that operator can be sued alongside the criminal for the full amount of the loss.

For a licensed operator like Bitkub or Gulf Binance, this raises the stakes for every security and compliance decision. An operator that has robust screening, maintains compliant blacklists, and can demonstrate security-standard implementation has a strong defense. An operator that can’t show compliance faces liability exposure on every fraud case involving its platform.

What This Means for Thai Crypto Users

For Thai retail users, joint liability rules are broadly positive — they mean licensed exchanges have a strong financial incentive to take fraud prevention seriously, not just regulatory incentive. If an exchange’s systems allow a fraudulent transaction to proceed that a properly configured screening system would have flagged, the exchange faces liability.

In practical terms: if you’re the victim of a crypto fraud on a licensed Thai exchange, you now have legal recourse against the exchange itself, not just the perpetrator. Whether that recourse is effective depends on the specific facts of each case, but the legal pathway exists in a way it didn’t before 2026.

What This Means for Unlicensed Operators

The law’s reach has expanded to cover foreign operators targeting Thai users — not just domestic licensees. The Ministry of Digital Economy and Society (MDES) has the authority to order ISPs to block unlicensed foreign platforms under technology-crime law. An unlicensed operator serving Thai users faces: blocking orders from MDES, potential criminal liability under the cybercrime decree, and joint civil liability for any fraud on its platform.

This is the enforcement architecture that explains why the SEC filed criminal complaints against five major platforms (Bybit, OKX, 1000X, CoinEx, and XT.COM) in mid-2025 and why MDES issued blocking orders against them by June 2025. The joint liability framework makes unlicensed operation progressively riskier, not just regulatorily inconvenient.

The Practical Takeaway

For Thai crypto investors, the message is clear: use licensed platforms. Not primarily because of the tax exemption (though that’s valuable), but because the regulatory architecture now provides genuine legal protection for users of licensed operators that simply doesn’t exist for users of offshore unlicensed platforms. When fraud happens on an offshore platform, your recourse is limited to international legal action against an entity that may have no Thailand presence. On a licensed Thai platform, the operator is jointly liable and resident.

For operators, the compliance bar has materially risen. The cost of meeting banking-sector security standards is significant. The cost of not meeting them — and facing joint liability on fraud cases — is potentially much higher.

BrokerTH