Digital Asset Theft and Exploits Affecting Businesses
A Texas business discovers that someone transferred $600,000 in digital assets from a wallet used for customer settlements. Its engineers identify the transactions, a customer demands reimbursement, and the custody provider says the transfer passed its authentication checks. Each account addresses a different question. The transaction record shows a transfer, the customer agreement governs the business's obligations, and the provider's records may show whether someone followed or bypassed the agreed approval procedure.
You should organize the response around those distinctions while qualified technical personnel contain the incident. Counsel assesses ownership, claims, court relief, and notice obligations using the transaction evidence and the agreements in effect when the loss occurred.
Preserve Evidence While Containing the Incident
Technical containment and evidence preservation should proceed together. The FTC's breach response guidance recommends forensic investigation and warns against destroying evidence during remediation. For a digital asset business, relevant material may include wallet access logs, signing requests, employee approvals, support messages, and the version of the application involved. A screenshot of the balance after the theft leaves unanswered who authorized the transfer and how the recipient obtained control.
You should preserve original records and document who collected them, when, and from which systems. Engineers can record the containment measures they take, including changes to credentials or transaction permissions, while counsel identifies records that employees and providers should retain. A preservation request should identify the affected accounts, relevant period, and records sought; a demand to save evidence does not itself compel a provider to disclose another customer's records.
Establish Whose Assets Were Taken
The company operating a wallet may hold its treasury funds, customer property, or assets subject to contractual repayment obligations. Those arrangements produce different ownership and loss questions. You should compare the custody agreement and customer terms with account records, internal ledgers, and the authority granted to each signer before asserting that every asset in the affected wallet belonged to the company.
The same distinction affects a proposed reimbursement. A business that pays customers may need assignments, releases, or other documents addressing the customers' claims against the recipient or a provider. Reimbursement should be coordinated with insurance and recovery rights so the business understands which claims it can pursue and which customers retain.
Identify Who Can Restrict Transfers
A report should provide enough information for an investigator or provider to identify the transactions. The FBI's guidance for cryptocurrency victims asks for addresses, asset types and amounts, transaction dates and times, and transaction identifiers, commonly called hashes. Communications with the suspected recipient and the names of exchanges involved also belong in the record. The FBI encourages reporting even when transaction information is incomplete.
An exchange may be able to restrict an account through which assets passed, but that possibility depends on whether it controls relevant assets and has a basis to act. The FBI's warning about recovery schemes explains that exchanges freeze accounts through internal processes or in response to legal process, and that private recovery companies cannot issue seizure orders. You should distinguish a request to preserve records, a request to restrict transfers, and a demand for return of property. Each seeks a different action.
A transaction analysis can support those requests by identifying the sequence of transfers and explaining the evidence connecting an address to a provider. Any attribution based on inference should be identified as such. An address labeled with an exchange's name in an investigative report may require confirmation through the exchange's records before it can support a claim about a particular account holder.
Support an Application for Emergency Relief
A court application must identify the legal claim, the threatened conduct, and the people or entities the court can bind. Under Texas Rule of Civil Procedure 680, a temporary restraining order without notice requires specific facts in an affidavit or verified complaint showing immediate and irreparable injury before notice and a hearing can occur. Such an order expires within the period the court sets, no longer than 14 days, subject to the rule's extension provisions. Rule 684 requires security in an amount fixed by the court. You should account for the evidence, bond, and subsequent hearing when assessing the cost and usefulness of emergency relief.
Rule 683 also requires specificity and limits who an order binds. A Texas order does not automatically bind every foreign exchange mentioned in a transaction report. Counsel must assess jurisdiction, service, the proposed recipient's relationship to the defendants, and any proceedings needed where the provider operates. A federal case proceeds under the applicable federal rules, including Rule 65, with its requirements for notice, security, and the scope of an injunction.
In Licht v. Ling, the Northern District of Texas entered a June 2025 default judgment awarding an individual fraud victim $2,755,000 under the Texas Theft Liability Act. The court converted its preliminary injunction into a permanent injunction freezing identified cryptocurrency wallets and directed the defendants and named exchanges to preserve related records. Because the defendants never appeared, the court relied on admitted allegations and supporting evidence. The opinion does not report whether the exchanges complied or the plaintiff recovered funds. Its directions illustrate the relief ordered, while enforceability against a particular nonparty requires separate analysis under Federal Rule 65(d)(2) and applicable jurisdictional principles.
Select Claims That Fit the Conduct
Texas law provides a civil theft claim through the Texas Theft Liability Act. Under § 134.003, a person who commits theft is liable for resulting damages. The incorporated theft provisions in Penal Code §§ 31.01 and 31.03 address unlawful appropriation with intent to deprive the owner, include intangible personal property, and distinguish effective consent from consent induced by deception. Whether software accepted a transaction does not, by itself, resolve the owner's consent or the recipient's intent.
A civil theft allegation also has a fee consequence. Section 134.005 provides actual damages and permits up to $1,000 in additional damages against the person who committed the theft, while requiring an award of court costs and reasonable and necessary attorney fees to a prevailing person. That fee provision applies to a prevailing defendant as well as a prevailing claimant. You should assess the evidence of theft before using the claim in a dispute that may instead concern contractual performance.
Conversion, a claim concerning unauthorized control over another’s property, presents a separate analysis. In Halo Mining Ltd. v. NorthData Holdings, Inc., the Northern District of Texas granted Halo summary judgment in March 2026 on conversion of 638 mining machines. It rejected conversion claims for mined bitcoin and deposit funds after Halo failed to answer the defendants’ argument that those assets were not specific property recoverable through conversion. The court separately granted Halo summary judgment on civil theft based on deemed admissions concerning the deposit, bitcoin, and equipment. The different results within the same order show why counsel should examine the property claimed and the evidentiary record before selecting a claim.
Examine the Rights of Subsequent Recipients
A business seeking the return of virtual currency must also consider the recipient's rights. Under Texas Business and Commerce Code § 12.003, a qualifying purchaser obtains control for value and without notice of an adverse claim, meaning another person's asserted property interest. Such a purchaser takes free of the adverse claim, and subsection (f) bars actions based on that claim under conversion, constructive trust, and other theories.
Notice includes knowledge of the adverse claim or awareness of a significant probability that it exists coupled with deliberate avoidance of confirming information. That makes the recipient's acquisition, payment, control, and knowledge part of the investigation. Following transfers to a current holder does not establish that the holder participated in the theft or that the business can recover the assets from that holder. You should assess this protection, and which jurisdiction's law applies, before demanding return from a subsequent purchaser.
Review Provider Obligations and Insurance
A custody provider, developer, or other vendor may have obligations relevant to the loss even when someone else initiated the transfer. You should compare its promised services with the incident evidence. If an agreement required two authorized approvals, the questions include what counted as an approval, whether the provider obtained both, and whether a failure contributed to the loss. A provider's description of a transfer as authenticated may answer only part of that inquiry.
The agreement's limits on damages, exclusions, notice provisions, and dispute procedures also affect the claim. An audit engagement tied to a particular version of software calls for comparison with the version involved in the exploit. A reimbursement offer may include a release extending beyond the payment under discussion. Those provisions should be assessed before the business accepts a credit, signs a release, or assumes that a vendor will cover the missing assets.
Insurance presents a separate source of possible payment. The FTC's cyber insurance guidance distinguishes coverage for the business's incident costs from coverage for claims brought against it. You should examine applicable cyber, crime, and other policies for coverage of the particular asset and event, notice deadlines, consent requirements, and conditions on selecting investigators or counsel. Coverage for a forensic investigation does not establish coverage for the stolen tokens.
Determine Whether Customer Notice Is Required
An asset theft and a breach involving personal information raise different statutory questions. Under Texas Business and Commerce Code § 521.053, the notification analysis concerns unauthorized acquisition of computerized data compromising sensitive personal information. You should assess the actual information involved under § 521.002; a loss from a company treasury wallet alone does not establish that customer information was acquired.
For a business that owns or licenses covered data, § 521.053(b) requires notice to affected individuals without unreasonable delay and no later than 60 days after determining that the breach occurred, subject to the statute's investigation, restoration, and law enforcement provisions. Under subsection (c), a business maintaining covered information for another owner or license holder must notify that owner or license holder immediately after discovering a qualifying breach. You should document when the relevant facts became known and which obligations follow from them.
A report to the Texas Attorney General has a separate deadline. For a reportable breach involving at least 250 Texas residents, notification is due as soon as practicable and no later than 30 days after determining that the breach occurred, using the Attorney General's electronic reporting process. Contractual notices and other applicable jurisdictions' laws should be assessed separately. Customer communications should distinguish confirmed losses and protective measures from conclusions the investigation has not established.
Evaluate Recovery Against the Cost of Pursuing It
A recovery assessment should identify defendants against whom relief can be enforced, assets available to satisfy a claim, and the evidence needed for the next decision. You should evaluate the initial investigation and emergency application separately from the cost of contested litigation or proceedings abroad. A documented sequence of transfers may justify contacting a provider while providing too little information to justify a lawsuit against a named person.
Settlement documents should specify the asset and amount to be returned, the receiving address and verification procedure, the treatment of fees, and when a release becomes effective. Where assets belong to customers or an insurer has paid part of the loss, settlement authority and competing recovery rights also require resolution. Counsel can address those legal decisions while investigators establish what happened and technical personnel determine how the business can resume operations safely.
Related practice area: Digital Assets
This article is general information about the law, not legal advice, and reading it does not create an attorney-client relationship. Laws change and how they apply depends on your specific facts. For advice on your situation, consult a qualified attorney.
Need advice tied to your business issue?
Share the issue. Get direct attorney review. Receive a concrete recommendation.
Submit an Inquiry