VERSE PRESS

Crypto News, Global First.

Who Pays When Blockchain Fails? A $3.4 Billion Problem With No Clear Answer

Hackers stole $3.4 billion in crypto during 2025. Across three continents, courts and regulators are still figuring out who is legally responsible when blockchain systems break down.

|

Thieves drained $3.4 billion from the broader crypto ecosystem in 2025, according to Chainalysis data, including approximately $1.4 billion from the Bybit exchange in February of that year, the largest single crypto theft on record. The losses mounted relentlessly throughout the year: Immunefi recorded $1.64 billion stolen in Q1 2025 alone, the worst quarter on record, and Chainalysis reported that $2.17 billion had already been taken by mid-July 2025, a figure that had already surpassed the total for all of 2024. Yet despite the scale of losses, a fundamental question remains unanswered in most of the world: when a blockchain system fails or is exploited, who is legally on the hook? Experts and legal analysts flagged in late June 2026 that the absence of clear accountability frameworks is no longer a theoretical concern. It is an active risk for developers, users, and governments deploying blockchain infrastructure at scale.

No Single Throat to Choke

The core problem is structural. In conventional digital systems, a single company typically owns and operates the full technology stack, giving regulators and courts a clear target when things go wrong. Blockchain systems split responsibility across multiple parties at once: the developers who wrote the original code, the auditors who reviewed it, the validators who process transactions, the front-end operators who built the interface, and in many cases a decentralised autonomous organisation (DAO, a community-governed entity with no traditional corporate structure) that controls the protocol. Legal scholars refer to this as the "many hands" problem. Each actor contributes to the system but none bears obvious sole responsibility for its failure.

A November 2024 federal court ruling in California, in the case Samuels v. Lido DAO, sharpened the stakes considerably, and proceedings in the case continued into 2026. Judge Vince Chhabria found that Lido DAO token holders could face unlimited personal liability as general partners of an unincorporated association. "Lido's alleged actions are not those of an autonomous software program," Chhabria wrote. "They are the actions of an entity run by people." At the time of the ruling, Lido DAO held roughly $25 billion in total value locked. Miles Jennings, general counsel at venture firm Andreessen Horowitz, warned that any DAO participation, including something as minor as posting in a governance forum, could be sufficient to hold members liable for the actions of other members under general partnership laws. More than 12,000 DAOs currently operate globally, controlling over $150 billion in assets. The vast majority have no formal legal entity structure, though precise figures are not publicly available.

The Audit Paper Trail Goes Nowhere

One widely misunderstood protection is the smart contract security audit. Projects routinely publish completed audits as a signal of credibility, and users often treat them as a safety guarantee. They are not. Audit firms explicitly disclaim legal liability in their reports. Passing a technical review satisfies no regulatory obligation and does not shield developers from negligence claims. The mismatch between how audits are marketed and what they legally guarantee creates a liability vacuum that no party is currently positioned to fill.

US prosecutors have simultaneously closed off another common line of defence. In a March 2026 indictment of a Maryland man accused of draining over $50 million from a crypto exchange, federal prosecutors stated plainly: "Stealing from a crypto exchange is stealing. The claim that 'crypto is different' does not change that." Federal courts have likewise rejected the related assertion that crypto assets are simply outside the reach of ordinary theft and fraud law. The "code is law" argument, a once-popular claim that on-chain outcomes are self-legitimising because they follow the rules of the protocol, has found no traction in federal court.

India Deploys Blockchain. The Law Has Not Caught Up.

India presents a sharp contradiction. More than 1,200 government departments operate on the National Blockchain Framework. The Reserve Bank of India's digital rupee has moved beyond its pilot phase. A separate count shows over 1,200 Web3 startups active in the country. Yet India has no statute specifically addressing smart contract liability, DAO governance, or accountability for blockchain system failures. The Indian Contract Act of 1872 does not mention smart contracts. Digital signatures generated on-chain are not compliant with the Information Technology Act, meaning smart contract evidence could be ruled inadmissible in court.

A Madras High Court ruling in November 2025 recognised cryptocurrency as property under Indian law, a meaningful step. But property classification does not resolve who owes a duty of care when a protocol malfunctions. Indian legal practitioners currently recommend hybrid contracts, documents that pair a natural-language agreement with on-chain execution, as the most defensible approach. Users relying purely on on-chain DeFi protocols have no regulatory recourse for losses under Indian law today. India's regulatory posture is nonetheless tightening: mandatory transaction reporting requirements took effect in April 2026, and cross-border data-sharing obligations linked to the OECD's Crypto-Asset Reporting Framework are planned for April 2027. Indian fintech firms running validator nodes on networks such as Polygon and Arbitrum face particular exposure, as their intermediary status under these evolving frameworks remains unresolved.

Africa's Stablecoin Gap

Africa's accountability problem is arguably more urgent. Stablecoins (tokens pegged to currencies like the US dollar) have become genuine financial infrastructure across the continent, used for remittances and cross-border trade rather than speculation. No African jurisdiction has implemented comprehensive oversight of stablecoin issuance, reserves, or redemption rights. If a widely used stablecoin loses its peg or an issuer collapses, there is no regional legal mechanism for user recourse. Roughly eight African countries have crypto-specific regulation at all, and existing frameworks focus on licensed intermediaries such as exchanges, not on the decentralised protocols where most accountability gaps sit.

Several jurisdictions have made significant legislative moves. South Africa now has 240-plus licensed crypto service providers under its Financial Sector Conduct Authority, and a June 2026 Johannesburg High Court ruling classified Bitcoin as both money and capital under exchange control rules. Nigeria's Investments and Securities Act 2025 formally brought digital assets under Securities and Exchange Commission Nigeria oversight, a milestone for the continent's largest economy. Kenya enacted its Virtual Asset Service Providers Bill in October 2025, placing oversight under the Central Bank of Kenya and the Capital Markets Authority. The licensing infrastructure across all three jurisdictions, however, does not reach DeFi.

A Partial Fix, US-Only

The US House passed the CLARITY Act in July 2025, which explicitly states that open-source software developers, node operators, and validators who do not hold customer funds are not money transmitters under federal law. The protection is real but narrow. It applies only within US jurisdiction and offers nothing to developers in South Asia, Africa, or anywhere else building on the same global protocols.

The Tornado Cash precedent, in which the US Treasury sanctioned a non-custodial smart contract protocol, further complicated the picture. Regulators in multiple jurisdictions now treat infrastructure-layer protocols as potential financial intermediaries regardless of whether they hold any user funds. For developers who hold upgrade or admin keys over a protocol, a BlockSec Blog analysis of developer liability in blockchain protocol governance framed the dilemma plainly: "If you have the power to freeze a thief's money, the law says you are now a 'financial intermediary.'" Surrendering that key removes the liability exposure but also removes the ability to protect users from future bugs or exploits. Holding it invites regulatory classification as a financial institution.

The legal frameworks governing these systems are still forming, and the gap between operational reality and legal clarity remains wide. Jurisdictions such as India and Kenya are among those where state-level blockchain deployment and grassroots DeFi adoption are both accelerating, outpacing the legal structures designed to govern them and making them plausible sources of the next significant test cases.