{"url_path":"/sec/suig/10-q/2026/item-1a","section_key":"item-1a","section_title":"Item 1A RISK FACTORS**","topic":"sec","document":{"doc_type":"10-Q","doc_date":"2026-05-08","source_url":"https://www.sec.gov/Archives/edgar/data/1425355/0001654954-26-004627-index.html","accession_number":"0001654954-26-004627","cik":"0001425355","ticker":"SUIG","issuer_name":"SUI Group Holdings Ltd.","edgar_url":"https://www.sec.gov/Archives/edgar/data/1425355/0001654954-26-004627-index.html","primary_entity_key":"0001425355","primary_entity_name":"SUI Group Holdings Ltd."},"word_count":2694,"has_tables":true,"body_markdown":"**ITEM 1A. RISK FACTORS**\n\n \n\nIn addition to the risk factors set forth below, you should carefully consider the factors discussed in “Item 1A. Risk Factors” in our Annual Report. The risks described below and in those documents are not the only risks facing us. Additional risks and uncertainties not currently known to us or that we currently deem to be immaterial may also materially adversely affect our business, financial condition and/or operating results.\n\n \n\n**Risks Related to Our SUI Treasury Strategy**\n\n \n\n**If we or our third‑party service providers or partners experience a security breach or cyberattack and unauthorised parties obtain access to our SUI, or if our private keys are lost, compromised or destroyed, we may lose some or all of our SUI and our financial condition and results of operations could be materially adversely affected.**\n\n \n\nSubstantially all of the SUI we own is held in custody accounts at BitGo, a well‑known custodian. Security breaches and cyberattacks are of particular concern with respect to our SUI. SUI and other blockchain‑based cryptocurrencies, and the entities that provide services to participants in the SUI ecosystem, have been, and may in the future be, subject to security breaches, cyberattacks or other malicious or unauthorised activities. In recent years, several digital asset platforms and custodial service providers have experienced significant cybersecurity incidents, including large‑scale thefts resulting from the compromise of private keys and other custody‑related controls. These incidents have included compromises of processes and systems that were designed to enhance security, such as offline or “cold storage” arrangements and multi-signature authorisation workflows.\n\n \n\nFor example, in February 2025, a major cryptocurrency exchange reported that unauthorised actors had compromised a cold‑wallet custody system and stolen approximately $1.5 billion in digital assets, illustrating that custody solutions designed to operate offline may be vulnerable to increasingly sophisticated attacks.\n\n \n\nFurther, it has been reported publicly that cyber attacks targeting decentralized finance (“DeFi”) systems focus increasingly on off-chain infrastructure, governance processes, cross-chain messaging and verification mechanisms, and human factors, which increases the attacks’ sophistication and the likelihood of success. For example, in April 2026, it was reported that a liquid restaking protocol suffered an exploit involving a forged cross-chain message that resulted in the unauthorised release of approximately $292 million in rsETH, with subsequent impacts across interconnected DeFi lending markets. Published incident analysis described the event as an attack on off-chain verification and infrastructure, rather than a flaw in the core smart contracts. Similarly, reporting regarding a separate April 2026 exploit of a Solana-based DeFi protocol described how an attacker used “durable nonces,” a legitimate Solana transaction feature, to pre-sign administrative transfers weeks before executing them and illegally obtain substantial assets, without requiring exploitation of a coding vulnerability in the protocol’s programs.\n\n \n\nSimilar incidents affecting other market participants could occur in the future. A successful security breach or cyberattack, whether affecting us or a third-party service provider or partner on which we rely, could result in a partial or total loss of our SUI in a manner that may not be covered by insurance or the liability provisions of the custody agreements with the custodians who hold our SUI; harm to our reputation and brand; improper disclosure of data and violations of applicable data privacy and other laws; or significant regulatory scrutiny, investigations, fines, penalties and other legal, regulatory, contractual and financial exposure and increased costs to strengthen our information security and operational controls, including costs associated with incident response, business continuity measures, enhanced monitoring, third-party assessments, and remediation.\n\n \n\nAlthough we believe that holding SUI in cold storage reduces certain theft risks, cold storage does not eliminate cybersecurity risk. Publicly reported incidents have involved the compromise of transaction approval workflows, signing interfaces, multi-signature processes, or other operational controls that are adjacent to cold storage rather than direct online theft of private keys, and there is a risk therefore that such incidents may take place. In addition, we have engaged in protocol-level and yield-generating activities that may require transferring SUI out of custody accounts or otherwise exposing our SUI holdings to additional technological, operational, smart contract, and counterparty risks. These activities have included native staking, liquid staking and restaking, and during the reporting period, participation in decentralized finance protocols through third-party asset management arrangements. Following the end of the reporting period, the Company unwound all decentralized finance (“DeFi”) positions and recovered all amounts involved therein in response to security incidents affecting certain DeFi ecosystems. \n\n \n\nFurther, any actual or perceived data security breach or cybersecurity attack directed at other companies with digital assets or companies that operate digital asset networks, regardless of whether we are directly impacted, could lead to a general loss of confidence in the broader SUI ecosystem or in the use of the SUI network to conduct financial transactions, which could negatively impact us. This may be true even where the attacks do not directly involve our custodian, our third-party service providers or partners, or our SUI holdings, because our stock price may be influenced by broader perceptions of the security of digital assets, DeFi protocols, and the SUI ecosystem. Such events may lead to reduced user activity, reduced liquidity, higher risk premiums demanded by investors, heightened regulatory scrutiny, and increased volatility in the trading price of digital assets and digital asset related securities, including our common stock, as well as other legal, regulatory, contractual and financial exposure and increased costs.\n\n \n\n \n\n24\n\n*Table of Contents*\n\n \n\nAttacks upon systems across a variety of industries, including industries related to digital assets, are increasing in frequency, persistence and sophistication and, in many cases, are being conducted by sophisticated, well‑funded and highly organised groups and individuals, including state‑sponsored actors. The techniques used to obtain unauthorised access to systems or information (including personal data and digital assets), disable or degrade services, or sabotage systems are constantly evolving, may be difficult to detect quickly, and often are not recognised or detected until after they have been launched against a target. These attacks may occur on our systems or those of our third‑party service providers or partners.\n\n \n\nWe may experience breaches of our security measures due to human error, malfeasance, insider threats, system errors or vulnerabilities or other irregularities. In particular, we expect that unauthorised parties may attempt to gain access to our systems or those of our partners and third‑party service providers, through methods such as hacking, social engineering, phishing and fraud. Threats can come from a variety of sources, including criminal hackers, hacktivists, state‑sponsored intrusions, industrial espionage and insiders. Certain threats may target individuals involved in transaction approvals, custody arrangements, and other high privilege activities, including through impersonation, fraudulent communications, and other deception tactics.\n\n \n\nRecent publicly reported  incidents in the digital asset industry have demonstrated that attackers may target individuals with authority to approve transactions or changes to system configurations, including through impersonation, relationship building, and other forms of social engineering designed to obtain misrepresented approvals rather than exploit code vulnerabilities. Attacks of this nature may be difficult to prevent, may not be detected until after assets have been transferred, and may be more likely where functions are performed by a small number of authorised personnel at us or at our third-party service providers or partners.\n\n \n\nIn addition, certain types of attacks could harm us even if our systems are not directly compromised. Some threats are designed to remain dormant or undetectable, sometimes for extended periods of time, or until launched against a target, and we may not be able to implement adequate preventative measures in all cases. Cybersecurity risk may also be heightened by cyberwarfare in connection with ongoing geopolitical conflicts or other future conflicts. Any future breach of our operations, or of the operations of third parties relied upon by participants in the SUI ecosystem, could materially adversely affect our financial condition and results of operations.\n\n \n\n**Cyber incidents or attacks directed at us could result in information theft, data corruption, operational disruption and/or financial loss.**\n\n \n\nWe rely on digital technologies, including information systems, infrastructure and cloud applications and services, including those belonging to third parties with whom we deal. Sophisticated and deliberate attacks on, or security breaches in, our systems or infrastructure, or the systems or infrastructure of third parties or the cloud, could lead to corruption or misappropriation of our assets, proprietary information and sensitive or confidential data, including personal data.\n\n \n\nWe rely in part on the data‑security measures implemented by third‑party service providers or partners with whom we deal, and we may not be sufficiently protected against such occurrences. We may not have sufficient resources to adequately protect against, or to investigate and remediate, any vulnerability to cyber incidents. It is possible that any of these occurrences, or a combination of them, could have adverse consequences on our business and lead to financial loss. In addition, our participation in activities that involve deploying digital assets outside of cold storage, including staking, liquid staking, and transactions involving tokens or instruments representing staked positions, may increase the attack surface and introduce additional risks related to smart contracts, protocol design, cross-chain infrastructure, and counterparty operational controls.\n\n \n\n**The use of, or inability to use, artificial intelligence by us, our employees, consultants, directors, vendors, investors or contract counterparties presents risks and challenges that may adversely impact our business and operating results or the business and operating results of our vendors, investors or contract counterparties.**\n\n \n\nWe may use generative artificial intelligence and/or machine‑learning technologies (collectively, “AI”) in our operations. While AI tools may facilitate optimisation and operational efficiencies, they also present risks, including inaccurate or biased outputs, intellectual property or data‑privacy concerns, and cybersecurity vulnerabilities. In addition, cybersecurity threat actors may use AI‑enabled tools to enhance the scale, speed or effectiveness of attacks against us or our third‑party service providers or partners. AI-enabled tools may assist threat actors to create more convincing social engineering lures, automate reconnaissance, accelerate the development of malicious code, and tailor attacks to specific individuals, including those involved in custody, transaction approvals, and other high privilege functions. These developments could increase the likelihood of successful attacks and reduce the time available to detect and respond to incidents, as well as the likelihood of other legal, regulatory, contractual and financial exposure and increased costs.\n\n \n\n**Business disruptions, including interruptions, delays or failures of our systems or other third‑party services, could materially adversely affect our operating results.**\n\n \n\nDisruptions or failures caused by cyberattacks, natural disasters, acts of terrorism, geopolitical conflict, pandemics, climate‑related events, power outages, telecommunications failures, or changes in the pricing or terms of third‑party services could impair our ability to conduct business operations or result in a material weakness in our internal controls over financial reporting, any of which could materially adversely affect our future operating results.\n\n \n\n**Risks Related to Our Investments**\n\n** **\n\n**Our $10 million in principal amount loan to Mustang Funding, LLC is subordinated to Senior Lenders in right of payment, in respect of our exercise of rights and remedies, and in right of collateral, with the result that we could lose a significant portion or all of our investment.**\n\n \n\nOn December 12, 2022, contemporaneously with our entry into a non-binding letter of intent with Mustang Funding, LLC (“Mustang”) contemplating a combination or merger transaction, we entered into a lending agreement with Mustang pursuant to which we loaned Mustang the principal amount of $5 million maturing in September 2023 (as amended, the “Mustang Litigation Funding”). Among other things, our related loan agreement with Mustang requires us to consent to any additional indebtedness Mustang may incur, subject to certain limitations and exceptions.\n\n \n\n \n\n25\n\n*Table of Contents*\n\n \n\nAlthough our loan to Mustang was not secured at the time that it was made, we negotiated for and obtained the right in the governing documents to seek and obtain collateral in the event that there were a default by Mustang or our negotiations for a combination transaction were to break down. At that time, we believed it was important to obtain this right because (i) Mustang was contemporaneously seeking a senior secured lending facility with whom we had no previous working experience, and (ii) a breakdown in combination negotiations, combined with our anticipated subordination (discussed below) could mean that we would need to extend the terms of this loan beyond nine months.  In sum, as a creditor, we believed that we needed to secure our loan on more traditional commercial lending terms in order to better protect our investment.\n\n \n\nOn December 28, 2022, we entered into a subordination agreement with Orion Pip LLC, in its capacity as administrative and collateral agent for itself and other senior lenders (the “Senior Lenders”) under a senior secured lending agreement with Mustang, pursuant to which we subordinated our right to payment (subject to certain exceptions) and our right to exercise rights and remedies, to Mustang’s prior repayment in full of all amounts owing to the Senior Lenders. The subordination agreement prohibited the Senior Lenders or Mustang from extending the stated maturity of amounts owing under the senior secured lending agreement beyond December 2026. The Senior Lenders are owed $15.675 million in principal amount under the senior secured lending agreement as of December 31, 2025.\n\n \n\nIn June, August and September 2023, we advanced additional principal to Mustang as we continued working with them on a potential definitive merger agreement and related deliverables. These additional principal advances resulted in the loan principal growing to an aggregate of $10 million. In connection with these advances, the maturity date of our loan was ultimately extended to June 2024. In April 2024, we agreed to a final extension of the maturity date to the earlier of December 31, 2024, or 90 days after the termination of negotiations for our combination transaction with Mustang.\n\n \n\nOn August 20, 2024, we terminated the non-binding letter of intent with Mustang. As a result, amounts owing under our $10 million loan to Mustang were to mature on November 18, 2024.  Nevertheless, the subordination agreement with the Senior Lenders effectively worked to prohibit Mustang’s payment, and our collection, of our loan.  Accordingly, at that time we invoked our right to obtain collateral security from Mustang for our loan for the purpose of protecting our investment and essentially converting our loan position from a short-term unsecured loan to a longer-term loan involving standard commercial lending terms, including terms relating to collateral security.  Ultimately, in late January 2025 we were able to enter into an amendment to our loan agreement with Mustang that extended the maturity date of our loan to March 2027 and increased the interest rate on our loan principal to 20% per annum (with 15% per annum remaining payable in cash on a monthly basis, and the additional 5% per annum being payable upon maturity), and also enter into an amended and restated subordination agreement with Orion Pip LLC that subordinated our right to collateral on customary and negotiated terms and conditions.\n\n \n\nOn April 2, 2026, we received from a Senior Lender a notice of foreclosure and public sale of all or a material portion of Mustang’s assets, and we understand that the foreclosure has been postponed pending further negotiations between Mustang and its creditors. The timing and outcome of any such foreclosure, restructuring, insolvency or similar proceeding are uncertain and may be protracted, contested and costly. If a foreclosure or other enforcement action occurs, or if there is no improvement in Mustang’s financial or business condition, we may lose a substantial portion or all of our investment in Mustang or be required to accept cash or securities with a value that is significantly less than the carrying value of the loan, any of which could result in significant losses and have a material adverse effect on our business, financial condition and results of operations.\n\n \n\nWe have not received interest payments when due under our loan agreement with Mustang since February 2026, and, based on Mustang’s current financial condition and the foreclosure action described above, by the Senior Lenders, we do not expect to receive the overdue or any future interest payments in the foreseeable future. If Mustang continues to fail to make required payments, we may be required to increase allowances, recognize further impairment or ultimately write off all of this loan, which could adversely affect our revenues, results of operations and financial condition."}