Sign In
SEC News

SEC issues shared responsibility standards for digital asset business operators and continues collaboration with relevant agencies to combat mule digital asset accounts



Friday 8 August 2025 | No. 202 / 2025


Bangkok, 8 August 2025 – The Securities and Exchange Commission (SEC) has issued standards and measures to prevent cybercrimes, requiring digital asset business operators to share responsibility for damages if they fail to comply with the prescribed standards and such failure results in harm to clients, in accordance with the Emergency Decree on Measures for the Prevention and Suppression of Cybercrimes. The regulations come into force on 13 August 2025. The SEC is also collaborating with relevant agencies on an ongoing basis to combat mule (nominee) accounts in digital asset transactions. The public is advised to remain vigilant against becoming victims, and individuals hired to open mule digital asset accounts are subject to legal penalties.

Online investment scams have become a growing threat, causing significant financial losses to the Thai public. Criminals increasingly exploit technology for illegal purposes, using mule bank accounts to conceal their identities and evade detection. More recently, they have shifted to using mule digital asset accounts, which is a more complex method that makes it harder for authorities to enforce and suppress such activities.

As the regulator of digital asset business operators, the SEC has issued regulations prescribing standards and measures for the prevention of cybercrimes applicable to such operators, pursuant to the Emergency Decree on Measures for the Prevention and Suppression of Cybercrimes (No. 2) B.E. 2568 (2025).* These regulations, effective 13 August 2025,** aim to enhance investor protection and form part of broader efforts to address the problem of mule digital asset accounts in Thailand.
With regard to efforts to prevent and suppress nominee (mule) digital asset accounts, the SEC has continuously collaborated with the Thai Digital Asset Operators Trade Association (TDO) and digital asset business operators. These efforts have been further strengthened through proactive and ongoing measures. On 12 March 2025, the SEC, together with TDO and industry participants, established an industry standard for the prevention and detection of mule digital asset accounts. The SEC has since monitored compliance and required digital asset business operators to implement the standard rigorously.  

In addition, the SEC has strengthened cooperation with the Ministry of Digital Economy and Society, the Bank of Thailand (BOT), the Anti-Money Laundering Office (AMLO), the Thai Bankers’ Association, TDO, and other relevant agencies to facilitate information sharing and enhance the effectiveness of measures to prevent and suppress mule accounts. Currently, digital asset business operators receive lists of suspected mule accounts from relevant authorities for client screening purposes. As of 30 June 2025, more than 29,000 mule digital asset accounts had been blocked, and digital assets worth approximately 186 million baht had been frozen.  

Mr. Anek Yooyuen, SEC Deputy Secretary-General and Spokesperson, said: "The SEC urges the public to exercise caution in conducting financial transactions to protect themselves from cybercrimes. It is important to note that opening a mule digital asset account on behalf of another person, or allowing someone else to use your digital asset account in connection with such crimes, constitutes a criminal offence. Those found guilty may face up to three years’ imprisonment, a fine of up to 300,000 baht, or both, under the Emergency Decree on Measures for the Prevention and Suppression of Cybercrimes."




Notes:
* The Emergency Decree on Measures for the Prevention and Suppression of Cybercrimes (No. 2) B.E. 2568 (2025) requires financial institutions, payment service providers, telecommunications service providers, social media platform providers, and digital asset business operators to share responsibility for client losses if they fail to comply with the standards and measures for the prevention of cybercrimes prescribed by their respective regulators, resulting in damage to clients.
** Notification of the Office of the Securities and Exchange Commission No. Sor Thor. 22/2568 Re: Standards and Measures for the Prevention of Cybercrimes for Digital Asset Business Operators: https://publish.sec.or.th/nrs/10790s.pdf







Related News

Three financial regulators co-launch Second Class of the Responsible Voices for Finfluencer Project, promoting responsible financial, investment, and insurance communication
SEC seeks public comments on liquidity risk management tools for mutual funds to enhance management flexibility and unitholder protection
SEC seeks public comments on proposed amendment to institutional investor definition to promote fundraising through PE Trusts
SEC and SET co-host Investor Meetup @SEC to provide a forum for dialogue and exchange of views with investors
SEC seeks public comments on draft amendments to the Securities and Exchange Act to further strengthen capital market supervision