- Premium Content It takes our newsroom weeks - if not months - to investigate and produce stories for our premium content. You can’t find them anywhere else.
Malaysian court order against Luno causes concern across crypto firms
Crypto platforms were taken by surprise last month when a Malaysian court ordered Luno, a digital exchange, to replace assets that were stolen by hackers out of a client’s wallet.
Luno is one of five digital asset exchanges registered in Malaysia.
On October 31, the sessions court in Petaling Jaya, a city just west of Kuala Lumpur, ordered Luno to pay 597,920 ringgit (about US$128,000) to a client, Yew See Tak, whose account was emptied by unauthorized transactions. The court also awarded Yew 100,000 ringgit (around US$21,000) in “exemplary damages,” which is typically done when a defendant has acted recklessly or maliciously.

Luno was ordered by a Malaysian court to replace assets that were stolen by hackers out of a client’s wallet. / Photo credit: Luno
How did the court come to this ruling? Crypto platforms in Malaysia are scrambling to find that answer. The Petaling Jaya court announced the ruling online without providing a written explanation. Courts in Malaysia usually only provide the “grounds for judgment” when an appeal has been filed.
The court has allowed Luno a 14-day stay on the order from the date of the ruling, pending an appeal to Malaysia’s High Court. The industry is now closely watching this appeal process.
At the core of this case lies the question of security.
“Was there enough security? What is the standard to be applied in the industry? Did Luno fail to meet those standards? The grounds of judgment should give us a better idea of this, if and when it is written,” says Derrick Leong, a Malaysian lawyer who is head of legal at IX Swap, a decentralized exchange, and InvestaX, a platform for tokenized assets.
What has many in the industry concerned is that Luno said at the trial that it was using two-factor authentication (2FA) – the technology that even banks use to verify transactions. Two-factor authentication often uses SMS or messaging apps to verify the client’s identity after that person has initiated a transaction.
“The security measures that Luno is alleged to have failed to comply with, like 2FA, are pretty standard across the globe,” Leong points out.
Luno said in a statement that it “has always upheld the strongest levels of regulatory compliance and customer security.”

(From left) Luno general manager of APAC Aaron Tang, Luno country manager of Malaysia Scarlett Chai, and Hata CEO David Low / Photo credit: Luno
David Low, CEO of Hata, another of Malaysia’s registered digital asset exchanges, says that questioning the use of 2FA could create issues beyond the crypto industry.
How did we get here?
It’s not just the customer’s problem
Time to pack up and leave?
Will others follow suit?
Stay ahead in Asia’s tech landscape
This is premium content. Subscribe to read the full story.
Malaysian crypto firms are trying to come to terms with a recent court ruling saying that companies are liable if their clients get hacked.
We know this is not ideal. ⌛ Sign up in 20 seconds. Cancel anytime.
Our subscriber community includes professionals from these companies:





Stay updated on the go with our mobile app.
Get latest insights with smoother, more personalized experience through TIA mobile app.


