Crypto-asset consumers depend on regulated intermediaries to execute transactions and, in certain arrangements, to safeguard digital assets. This dependence creates a legal question when unauthorized access or another cyber incident causes an asset outflow or service disruption. This article examines the allocation of preventive and remedial duties under Indonesian law and the conditions under which a Digital Asset Trader may be held liable for hacking-related losses. It uses normative legal research with statutory, conceptual, and limited comparative approaches, supported by an event illustration concerning the September 2024 Indodax incident. The event sources are limited to company statements, news reports, and publicly observable information; no court judgment, regulator finding, internal ledger, or forensic report was available. The study finds that POJK Number 27 of 2024, as amended by POJK Number 23 of 2025, already differentiates the duties of Digital Asset Traders and Custody Managers, requires separate records and custody arrangements, and assigns responsibility for crypto assets stored by each entity. Consumer redress is also available through internal complaints, LAPS SJK, OJK action, contract, consumer-protection law, and tort. Liability nevertheless requires proof of a legal duty, breach of the applicable standard of care, foreseeability, causation, actual recoverable loss, and the absence of a valid defence. The remaining gaps are narrower: Indonesia has no hacking-specific automatic compensation fund, no uniform public assurance model reconciling reserves with customer liabilities, and no detailed common protocol for valuing complex losses. Because the required evidence is unavailable, legal responsibility for the Indodax incident cannot be conclusively determined
Copyrights © 2026