About the author:
Outset Legal Lens is led by Alice Frei, Outset PR’s head of security & compliance. In this series, she draws on years of experience in legal, compliance, and due diligence work across Web3 projects to show where teams most often get it wrong, and how to build communication that supports growth without quietly creating liabilities.
The plaintiffs are pursuing two main claims against Circle: negligence and aiding and abetting conversion. The first rests on the argument that the company knew or should have known about the ongoing theft, could foresee further harm and had the ability to intervene, yet failed to do so.
The second claim goes further. CCTP allows USDC to move between blockchains through a burn-and-mint process: tokens are burned on the source chain and an equivalent amount is minted on the destination chain after an attestation process. According to the plaintiffs, this infrastructure provided substantial assistance in moving the stolen value into a form that became significantly harder to recover.
That purported inaction raises a much more difficult legal question: Can an infrastructure provider’s failure to intervene amount to assistance in the underlying wrongdoing?
What matters is what gives Circle the authority – or obligation – to intervene in a particular case. That can come from the company’s own terms, a binding legal requirement or, as the Drift plaintiffs now argue, a duty arising from the circumstances of the hack itself.
There are essentially three levels of intervention:
The company’s CEO Jeremy Allaire has defended a more formal approach, saying that funds can be frozen at the direction of law enforcement or the courts. The logic is straightforward: a private company shouldn’t have to decide for itself who legally owns disputed on-chain assets. Yet the USDC Terms also give the issuer discretion to block addresses associated with illegal activity, making the distinction less clear-cut.
The problem with waiting for formal action is speed. Crypto can move long before a matter enters the judicial process, which is why the law provides emergency measures such as temporary restraining orders and preliminary injunctions.
In Hurlock v. Kelsier Ventures, a judge initially ordered Circle to freeze roughly $57.7 million in USDC over concerns that the funds could otherwise be moved. The order was later lifted, showing how the process can preserve them quickly while still allowing the restriction to be challenged.
One detail makes the Drift case more complicated than a typical transfer of stolen USDC: much of the money allegedly moved through Circle’s own cross-chain infrastructure.
The difference is in how the funds move:
The plaintiffs point to this architecture to argue that the issuer wasn’t simply watching stolen USDC move between wallets. According to the complaint, the attackers relied on CCTP to bridge the funds from Solana to Ethereum.
Circle draws the line differently. It describes CCTP as permissionless and non-custodial, and states that its technology services do not hold, control, manage or transfer users’ assets. From that perspective, providing the infrastructure doesn’t make the company a participant in the underlying movement of funds.
That leaves the factual question at the heart of this part of the case: does operating the infrastructure that enables a cross-chain transfer create a closer legal connection to the resulting loss than simply issuing the asset being transferred?
Whatever the outcome, the case could influence how centralized stablecoin issuers prepare for future hacks. The consequences, however, would look very different depending on which position the court takes.
If the court recognizes a duty to act, issuers will need to treat emergency freezes as part of their incident-response infrastructure. That means clearer escalation criteria, round-the-clock monitoring, faster legal triage and procedures for tracing disputed assets before they move beyond reach. It would also create pressure to intervene earlier, increasing the risk of legitimate funds being blocked on incomplete information.
Much would therefore depend on how narrowly such a duty is defined. A standard limited to cases involving strong evidence of knowledge of a theft, clearly traceable assets and an immediate opportunity to prevent further losses would have very different implications from one triggered simply by receiving notice of suspicious activity.
If the court rejects such a duty, technical control won’t give victims an automatic right to demand intervention. Their ability to preserve stolen stablecoins will continue to depend largely on rapid contact with law enforcement and emergency procedures, while issuers could remain reluctant to resolve contested ownership on their own.
The market impact will therefore depend less on a simple yes-or-no answer than on where the ruling draws the threshold for intervention – and what it expects an issuer to do once that threshold is crossed.
The plaintiffs in McCollum v. Circle, brought in the aftermath of the Drift hack, are testing how far an issuer’s responsibility can extend once a theft is already underway. Circle didn’t cause the original theft. The legal issue instead concerns what responsibility, if any, arises once the company knows that stolen value is moving through infrastructure it operates and has the technical ability to intervene.
But if notice alone is enough to trigger responsibility, issuers will be pushed toward freezing first and resolving ownership later.
The significance of the case therefore goes beyond one hack or one set of wallets. It could help define when centralized control over a stablecoin stops being merely a technical feature and begins to carry legal responsibility for how that control is used – or left unused.
This article is part of Outset Legal Lens. In this series, we’ll keep unpacking the legal side of Web3 communication, with a focus on helping teams speak clearly, responsibly, and in a way that supports the long-term growth of the industry.