Outset PR © 2026 All rights reserved
#
Outset Legal Lens

The $280M question: Should stolen stablecoins be frozen before a court steps in?

Published on:
September 11, 2026
by
Alice Frei
In the aftermath of a $280 million hack of Drift Protocol, attackers converted the proceeds into USDC and moved around $230 million through Circle’s Cross-Chain Transfer Protocol (CCTP) from Solana to Ethereum in roughly eight hours. Now the company is being sued over what it allegedly failed to do while those funds were still moving.
About the author:

Outset Legal Lens is led by Alice Frei, Outset PR’s head of security & compliance. In this series, she draws on years of experience in legal, compliance, and due diligence work across Web3 projects to show where teams most often get it wrong, and how to build communication that supports growth without quietly creating liabilities.

The plaintiffs are pursuing two main claims against Circle: negligence and aiding and abetting conversion. The first rests on the argument that the company knew or should have known about the ongoing theft, could foresee further harm and had the ability to intervene, yet failed to do so.

The second claim goes further. CCTP allows USDC to move between blockchains through a burn-and-mint process: tokens are burned on the source chain and an equivalent amount is minted on the destination chain after an attestation process. According to the plaintiffs, this infrastructure provided substantial assistance in moving the stolen value into a form that became significantly harder to recover.

That purported inaction raises a much more difficult legal question: Can an infrastructure provider’s failure to intervene amount to assistance in the underlying wrongdoing?

The ability to freeze is not the same as a duty to do so

What matters is what gives Circle the authority – or obligation – to intervene in a particular case. That can come from the company’s own terms, a binding legal requirement or, as the Drift plaintiffs now argue, a duty arising from the circumstances of the hack itself.

There are essentially three levels of intervention:

  1. Circle may freeze. Its USDC Terms reserve the right to block certain addresses, giving the company discretion to act when warranted.
  2. Circle must freeze. A binding legal trigger can turn that discretion into an obligation. The GENIUS Act requires permitted stablecoin issuers to be capable of complying with lawful orders to freeze or prevent transfers. OFAC (Office of Foreign Assets Control) rules can similarly require assets linked to blocked persons to be frozen without a separate court order.
  3. Circle could be required to freeze. This is the territory the Drift plaintiffs are trying to establish. Their argument is that even without a prior court order, knowledge of an ongoing theft, foreseeable further harm and the ability to stop further movement can together create an independent duty of care.

The company’s CEO Jeremy Allaire has defended a more formal approach, saying that funds can be frozen at the direction of law enforcement or the courts. The logic is straightforward: a private company shouldn’t have to decide for itself who legally owns disputed on-chain assets. Yet the USDC Terms also give the issuer discretion to block addresses associated with illegal activity, making the distinction less clear-cut.

The problem with waiting for formal action is speed. Crypto can move long before a matter enters the judicial process, which is why the law provides emergency measures such as temporary restraining orders and preliminary injunctions.

In Hurlock v. Kelsier Ventures, a judge initially ordered Circle to freeze roughly $57.7 million in USDC over concerns that the funds could otherwise be moved. The order was later lifted, showing how the process can preserve them quickly while still allowing the restriction to be challenged.

Does CCTP change Circle's role?

One detail makes the Drift case more complicated than a typical transfer of stolen USDC: much of the money allegedly moved through Circle’s own cross-chain infrastructure.

The difference is in how the funds move:

  • Regular on-chain transfer: existing USDC moves from one wallet to another on the same blockchain. No additional attestation or minting is required for that individual transaction.
  • CCTP transfer: USDC is burned on the source chain, an off-chain attestation service verifies the burn message, and an equivalent amount is minted on the destination chain.

The plaintiffs point to this architecture to argue that the issuer wasn’t simply watching stolen USDC move between wallets. According to the complaint, the attackers relied on CCTP to bridge the funds from Solana to Ethereum.

Circle draws the line differently. It describes CCTP as permissionless and non-custodial, and states that its technology services do not hold, control, manage or transfer users’ assets. From that perspective, providing the infrastructure doesn’t make the company a participant in the underlying movement of funds.

That leaves the factual question at the heart of this part of the case: does operating the infrastructure that enables a cross-chain transfer create a closer legal connection to the resulting loss than simply issuing the asset being transferred?

The ruling could reshape stablecoin incident response

Whatever the outcome, the case could influence how centralized stablecoin issuers prepare for future hacks. The consequences, however, would look very different depending on which position the court takes.

If the court recognizes a duty to act, issuers will need to treat emergency freezes as part of their incident-response infrastructure. That means clearer escalation criteria, round-the-clock monitoring, faster legal triage and procedures for tracing disputed assets before they move beyond reach. It would also create pressure to intervene earlier, increasing the risk of legitimate funds being blocked on incomplete information.

Much would therefore depend on how narrowly such a duty is defined. A standard limited to cases involving strong evidence of knowledge of a theft, clearly traceable assets and an immediate opportunity to prevent further losses would have very different implications from one triggered simply by receiving notice of suspicious activity.

If the court rejects such a duty, technical control won’t give victims an automatic right to demand intervention. Their ability to preserve stolen stablecoins will continue to depend largely on rapid contact with law enforcement and emergency procedures, while issuers could remain reluctant to resolve contested ownership on their own.

The market impact will therefore depend less on a simple yes-or-no answer than on where the ruling draws the threshold for intervention – and what it expects an issuer to do once that threshold is crossed.

Where does neutral infrastructure end?

The plaintiffs in McCollum v. Circle, brought in the aftermath of the Drift hack, are testing how far an issuer’s responsibility can extend once a theft is already underway. Circle didn’t cause the original theft. The legal issue instead concerns what responsibility, if any, arises once the company knows that stolen value is moving through infrastructure it operates and has the technical ability to intervene. 

But if notice alone is enough to trigger responsibility, issuers will be pushed toward freezing first and resolving ownership later.

The significance of the case therefore goes beyond one hack or one set of wallets. It could help define when centralized control over a stablecoin stops being merely a technical feature and begins to carry legal responsibility for how that control is used – or left unused.

This article is part of Outset Legal Lens. In this series, we’ll keep unpacking the legal side of Web3 communication, with a focus on helping teams speak clearly, responsibly, and in a way that supports the long-term growth of the industry.
Feel free to share the article via social media