Who Owes a Fiduciary Duty in Crypto?

Article

Who actually owes a duty when a protocol fails its users

Earlier this year the Delaware Court of Chancery ruled on Hash Asset Management Ltd. v. DMA Labs, Inc., a case meant to test fiduciary responsibilities in the crypto world which asked whether the creators of a token and protocol owe users a fiduciary duty. We’ve been thinking about a version of this since last month's piece on the Drift attack, where $285 million was stolen through a coordinated governance attack without any failure in the code. So, this month we wanted to look at where the law on that question actually sits, and how recent events like the Drift Protocol exploit will influence the future of crypto fiduciary law.

The concept of fiduciary duty has been carefully crafted over centuries of judgements and across multiple legal systems. In fact, his year marks the 300th anniversary of the case usually cited as its origin, Keech v. Sandford (1726). In it, the courts held that a person in a position of trust cannot take for themselves a benefit that comes to them through that position, even where there is no fraud. The same worry, about someone trusted with property turning their control of it to personal advantage, is what now hangs over the people who hold a crypto protocol's keys or are in charge of its governance. A DAO, which are common in crypto, often has no legal personality at all, so it is not obvious who the fiduciary is supposed to be, or who they would owe the duty to, if any. Similar to differing interpretations of the US constitution, a 300-year-old doctrine that has been re-defined time and again does not easily fit over new technology, and the more recent precedents that have stemmed from this case have resulted in judgements that point in different directions.

Hash v. DMA Labs is a useful place to start, because the court declined to find any duty at all. Hash Asset Management had lost a $16 million investment tied to the ICHI token and sued the foundation that issued it, the company that wrote the code, and several people connected to them, alleging breach of fiduciary duty. The Court of Chancery dismissed the claim on the basis that controlling a token, knowing more about it than the buyer, and shaping how it worked were not, on their own, enough to establish fiduciary duty.

American law interprets a fiduciary duty only when there is a specific person whose interests you are bound to put first. A foundation that creates or supports a token, for example the way the Dogecoin Foundation is associated with Dogecoin, is not in the same position as a manager or custodian who holds that token for clients. The issuer makes and controls something and then sells it, while the custodian has been entrusted with assets that belong to identifiable other people. The law has always treated those roles differently, and Hash is a recent reminder that being close to a crypto asset does not, by itself, make you anyone's fiduciary.

However, on the other hand, cases like Samuels v. Lido DAO have shown that ownership can be a contributing factor when control is also in play. In the case, a federal court in California refused to let a large DeFi protocol use its decentralized structure as a shield, and held that token holders who actively governed it, including venture firms such as Paradigm and Andreessen Horowitz, could be treated as general partners and exposed to personal liability. An earlier decision in California, Sarcuni v. bZx DAO, had already allowed governance-token holders to be treated as a general partnership, after noting that some of them held the keys to the protocol's treasury. And in other jurisdictions, the Supreme Court of South Australia similarly rejected the argument that cryptocurrency in wallets under a company director’s control belonged to him because he held the private keys and account credentials and found the assets had been bought with company funds and remained company property no matter who held the keys. These cases are liability rulings rather than fiduciary ones, but they still have an impact on how we interpret fiduciary cases, as the law holds that responsibility follows whoever actually controls the money and the decisions.

The most significant crypto fiduciary duty case to date would have to be FTX’s criminal proceedings. FTX held assets that belonged to its customers and invested them alongside the same capital as its founder's trading firm, spending customer money on the firm's own bets. Because it held what belonged to those customers, it owed them a fiduciary duty, and treating their money as its own was about as plain a violation as the law sees. But most on-chain losses will not look like FTX, as crypto is usually lost through a failure to safeguard the assets rather than fraud, and typically exists inside a structure that calls itself decentralized and has no obvious custodian holding anything. Thus, we’re left with two questions, whether anyone owes users a fiduciary duty in the first place, which is far from settled given that the relationship between a handful of people running a protocol, and a crowd of anonymous users looks nothing like the trustee-to-beneficiary or custodian-to-client relationships the law was built around. The second question is the one Drift recently brought forward, that even where a duty exists, does a fiduciary breach that duty if deceived or by making a possibly negligent decision that causes a loss?

The Drift attackers, who appear to have been linked to North Korea, spent months building relationships with members of the Drift team before persuading members of the protocol's Security Council to pre-sign transactions that handed over administrative control. Not long before the attack, Drift had moved to a two-of-five Security Council with no timelock, meaning that when the hack occurred it only took a matter of hours before around $285 million left the protocol. The people on the Security Council held the keys to other people's money. Clearly, if a duty exists anywhere, it exists with respect to them. Drift, however, called itself decentralized, and no court has yet held that the people governing a protocol owe its users a fiduciary duty at all, which leaves even the threshold question open.

The breach question is the one that existing law on traditional finance has answered, saying that a fiduciary is not an insurer. Being defrauded is not in itself a breach, because the fraudster is the one who answers for the theft, and the fiduciary is liable only where their own carelessness made it possible. That does of course raise the question of if Drift’s directors were acting negligently, and these are the facts that will be debated in any future suit over the incident as the lack of timelock is a serious oversight. Typically, corporate directors and officers have the protection of the business judgment rule when acting in good faith.

None of the law on the subject has been settled, nor has the outcome of the Drift incident.  Traditional finance usually litigates only the breach, because the relationship is fixed in advance, i.e. a director owes the company a duty, and so the question of duty is rarely up for debate. However, as more capital moves on-chain, courts and regulators will need to decide who is responsible, and to what degree, when a protocol's governance is the thing that fails its users.

As our reader you may wonder why we at HODL, which exists to bring institutional strategies on-chain, are speculating on these questions. The reason being that institutions we build for are themselves fiduciaries and its critical to us that we provide the most compliant technology for all users and fiduciaries. When this answer to this question remains unclear, potential fiduciaries who could owe a duty on-chain will decline to engage serious capital which is in turn left on the sidelines.

This year the U.S. Department of Labor proposed a rule on how retirement-plan fiduciaries should apply their duty of prudence when they put alternative assets like crypto in front of savers. With the largest pots of investable funds now considering investing further into crypto, the importance of defining where fiduciary duty lies has never been more prescient. Major capital will continue to stand on the sidelines until these rules are defined as carefully as they are in today’s traditional markets.

Daniel Lis is HODL's Chief Economist and Research Director. He has spent his career performing economic research that has been cited by the New York Times, Bloomberg, and the Wall Street Journal.