Search the 136-page Standard Form 86 for the words “cryptocurrency,” “bitcoin,” or “digital asset” and you will find nothing.
Many applicants take that to mean crypto is irrelevant to the security clearance process. It isn’t.
SF-86 asks about (i) foreign financial interests; (ii) tax compliance; (iii) debt problems; (iv) self-employment; (v) unauthorized computer access, etc. And a crypto portfolio can touch every one of those categories. ([1]).
Defense Office of Hearings and Appeals (“DOHA) judges have already denied clearances in cases where Bitcoin was central to unresolved debt, tax issues, or the purchase of illegal drugs. ([5], [6]).
Below are the actual questions (quoted from the form), and what they mean for federal employees, contractors, and military members who own crypto.
Key takeaways
- The SF-86 never uses the word crypto, but Sections 13A, 20A, 20B, etc. could technically reach it.
- Every answer is certified under 18 US Code § 1001. Your answers are compared against your previous SF-86s responses.
- DOHA denied clearances where crypto losses, crypto-funded debt, or dark-web bitcoin purchases tied to dark-web marketplaces.
- Once clearance is granted, reporting obligations could continue under Security Executive Agent Directive 3 (“SEAD 3).
How Dilendorf Law Firm helps
Max Dilendorf has practiced in the cryptocurrency and digital asset space since 2017. He advises clients on crypto compliance matters involving the Bank Secrecy Act (“BSA”), securities laws, CFTC regulations, and FinCEN requirements.
Dilendorf Law Firm analyzes actual SF-86 questions in light of your cryptocurrency history (exchange records, wallet activity, blockchain data).
We help clients prepare responses that are accurate and consistent with their tax filings, prior security clearance questionnaires, and various financial disclosure reports.
The firm served as counsel of record in more than 130 crypto-related cybercrime arbitration matters before AAA, JAMS, and NAM, involving testimony from retired FBI law enforcement expert witnesses.
Depending on the nature of a client’s case, the firm regularly works with retired law enforcement experts from the FBI, U.S. Department of Justice (“DOJ”), and Department of Homeland Security (“DHS”) to provide expert witness support in crypto and regulatory matters.
The certification you sign before the questions start
SF-86 begins with a clear warning. The form states that falsifying/concealing a material fact is a felony and that agencies “generally fire, do not grant a security clearance, or disqualify individuals who have materially and deliberately falsified these forms” ([1]).
SF-86, Penalties for Inaccurate or False Statements (verbatim)
The U.S. Criminal Code (title 18; section 1001) provides that knowingly falsifying or concealing a material fact is a felony which may result in fines and/or up to five (5) years imprisonment. In addition, Federal agencies generally fire, do not grant a security clearance, or disqualify individuals who have materially and deliberately falsified these forms, and this remains a part of the permanent record for future placements.
The same instructions add a line that crypto holders should read twice: “responses to this form may be compared with your responses to previous SF 86 questionnaires” ([1], [2]).
For example, a crypto wallet omitted from a 2017 SF-86 but disclosed in 2026 is the type of inconsistency the form is designed to identify.
Statute itself carries fines and imprisonment of up to 5 years for materially false statements in any matter within federal jurisdiction ([12]).
Section 20A: your offshore exchange account is a foreign financial interest
Section 20A is the question most crypto holders get wrong, because it never says “exchange” or “token.” It says this:
SF-86, Question 20A.1 (verbatim)
Have you, your spouse or legally recognized civil union/domestic partner, cohabitant, or dependent children EVER had any foreign financial interests (such as stocks, property, investments, bank accounts, ownership of corporate entities, corporate interests or exchange traded funds (ETFs) held in specific geographical or economic sectors) in which you or they have direct control or direct ownership? (Exclude financial interests in companies or diversified mutual funds or diversified ETFs that are publicly traded on a U.S. exchange.)
The word is “EVER,” in capitals, with no seven-year lookback.
That could be a challenging question for cryptocurrency holders.
Consider an applicant who received dozens of airdrops, moved assets across multiple exchanges, interacted with decentralized finance (DeFi) protocols.
In some cases, DeFi transactions could involve liquidity pools, validators or protocols connected to foreign jurisdictions.
Developing a complete history of potentially foreign financial interests could require reviewing years of wallet activity, exchange records, smart-contract interactions, and blockchain data.
The adjudicator may then analyze those facts under Guideline B (Foreign Influence), which identifies as a security concern “substantial business, financial, or property interests in a foreign country, or in any foreign-owned or foreign-operated business that could subject the individual to a heightened risk of foreign influence or exploitation” ([3]).
SF-86, Question 20A.1 follow-ups (verbatim)
Provide the type of financial interest.
Provide the date acquired.
Provide how the financial interest was acquired (such as purchase, gift, etc.).
Provide the cost (in U.S. dollars) at time of acquisition.
Provide the current value (in U.S. dollars) or the value at the time control or ownership was sold, lost or otherwise disposed of.
Are there any co-owners of this foreign financial interest?
Now try answering those questions for a crypto portfolio built over multiple years.
Digital assets may have been acquired through purchases, airdrops, forks, staking rewards, liquidity mining, DAO participation, exchange migrations, or DeFi transactions.
Section 26: the crypto tax years
Section 26 asks about bankruptcy, gambling, taxes, liens, and delinquent debt.
For crypto holders, one question stands out:
SF-86, Question 26.3 (verbatim)
In the last seven (7) years have you failed to file or pay Federal, state, or other taxes when required by law or ordinance?
The IRS treats digital assets as property, puts a yes-or-no digital asset question on Form 1040.
Any taxes income from staking, mining, airdrops, and sales ([8]).
The guideline addresses unexplained wealth.
“Unexplained affluence, as shown by a lifestyle or standard of living, increase in net worth, or money transfers that are inconsistent with known legal sources of income” is its own disqualifying condition, so a crypto windfall you cannot document is a problem even when you owe nothing ([3]). Section 26.7 then asks whether you “defaulted on any type of loan” or had “bills or debts turned over to a collection agency,” which is how leveraged crypto positions surface ([1]).
What DOHA judges have already said about crypto
In June 2025, DOHA judge denied a clearance to an applicant with more than $97,000 in delinquent federal taxes.
The applicant testified that, “[b]elieving that his cryptocurrency investment returns would cover his owed back taxes,” he withdrew $300,000 from a crypto account to purchase a home.
The judge found that it was not clear if the applicant’s tax payments accounted for his “large amount of profit from crypto currency” sales.
The decision noted that this was “not documented.” The judge further observed that “[e]qually unclear are his mounted losses from his gambling in crypto currency” ([5]).
In July 2024 another applicant lost his clearance over a $38,431 charged-off loan.
He “took the money from this loan and invested it in the bitcoin cyber-currency market, with the hopes that it would increase in value.” The judge found the debt to be unresolved ([6]).
The lesson from these decisions is straightforward: cryptocurrency itself is not disqualifying. However, but failing to document/properly report crypto activity on Form SF-86 could be.
For clearance purposes, owning crypto is rarely the issue. Explaining it and documenting it is.
After the clearance: the disclosures do not stop
Clearance holders have continuing reporting duties under Security Executive Agent Directive 3.
Federal employees who file financial disclosures reports must generally report virtual currency held for investment.
Office of Government Ethics treats cryptocurrency as “property held . . . for investment or the production of income,” subject to applicable reporting thresholds. ([9]).
Crypto is not treated as a “publicly traded security.” That means even a small cryptocurrency holding can create a conflict if the employee is involved in a matter that could affect its value ([10]).
FinCEN has also announced its intent to amend the FBAR rules to cover virtual currency held in foreign accounts ([11]).
Contact Us
Questions about cryptocurrency and security clearances? Contact Max Dilendorf at +1 212 457 9797 or info@dilendorf.com, or use our contact page.
Max Dilendorf also advises individuals outside the government sector on cryptocurrency-related disclosure and compliance issues. His represents investment advisers, hedge fund professionals, and other regulated financial industry employees.
This article is for general informational purposes only and does not constitute legal advice. Reading it does not create an attorney-client relationship with Dilendorf Law Firm. Attorney Advertising.
Frequently asked questions
Does the SF-86 ask about cryptocurrency directly?
No. The current Standard Form 86 doesn’t use words crypto, bitcoin, or digital asset. It asks about foreign financial interests, taxes, debts, employment, unauthorized computer access, etc. Crypto activity is frequently responsive to those questions ([1]).
Is an account at a non-U.S. crypto exchange a “foreign financial interest” under Section 20A?
Question 20A.1 asks if you have “EVER had any foreign financial interests (such as stocks, property, investments, bank accounts . . .)” and excludes only companies and diversified funds “publicly traded on a U.S. exchange.” Holdings on a foreign platform fit the plain language of “investments” and “bank accounts,” and the safer reading is to disclose them ([1], [2]).
What if I did not report crypto gains on a prior tax return?
Question 26.3 asks whether, in the last 7 years, you “failed to file or pay Federal, state, or other taxes when required by law.” IRS treats crypto as property and taxes income from sales, staking, mining, and airdrops. Unreported crypto year is generally a yes answer ([1], [8]).
Can crypto losses alone cost me a clearance?
Losses are not a listed disqualifying condition, but the debts they leave behind are. Guideline F lists “inability to satisfy debts,” “a history of not meeting financial obligations,” and borrowing to fund gambling as disqualifying conditions, and DOHA denied a clearance where a $38,431 charged-off loan had been invested in bitcoin ([3], [6]).
What is “unexplained affluence,” and does a crypto windfall count?
Guideline F treats “unexplained affluence, as shown by a lifestyle or standard of living, increase in net worth, or money transfers that are inconsistent with known legal sources of income” as a disqualifying condition. Large crypto gain is a legal source of income (…but only if you can document it with transaction records and tax filings) ([3]).
I left crypto off my last SF-86. Should I disclose it now?
The form warns that your answers “may be compared with your responses to previous SF 86 questionnaires,” and Guideline E lists “deliberate omission, concealment, or falsification” on a security questionnaire as disqualifying. Omission is generally easier to explain than a second inconsistent form, and this is a question to work through with counsel before you sign ([1], [3]).
Do I have to report crypto after I am cleared?
Under SEAD 3, the DCSA reporting aid lists foreign bank accounts, financial anomalies, and ownership of foreign properties as reportable events for Top Secret and “Q” holders. Federl employees who file financial disclosure reports must also list virtual currency as investment property ([4], [9]).
Does the penalty for a false SF-86 answer really include prison?
The form itself states that knowingly falsifying or concealing a material fact under 18 US Code. § 1001 “is a felony which may result in fines and/or up to 5 years imprisonment.” This is addition to denial or revocation of a clearance and removal from federal service ([1], [12]).
Sources
[1] U.S. Office of Personnel Management, Standard Form 86, Questionnaire for National Security Positions (rev. Nov. 2016). https://www.opm.gov/forms/pdf_fill/sf86.pdf
[2] Defense Counterintelligence and Security Agency, Guide for the Standard Form (SF) 86. https://www.dcsa.mil/Portals/128/Documents/pv/mbi/standard-form-sf-86-guide-for-applicants.pdf
[3] Office of the Director of National Intelligence, Security Executive Agent Directive 4, National Security Adjudicative Guidelines (effective June 8, 2017), hosted by the U.S. Department of Energy. https://www.energy.gov/sites/prod/files/2018/02/f48/SEAD4_20170608.pdf
[4] Defense Counterintelligence and Security Agency, SEAD 3 Industry Reporting Desktop Aid (rev. May 2024). https://www.dcsa.mil/Portals/128/Documents/CTP/tools/SEAD-3_Reporting_Desktop_Aid_for_Cleared_Industry-revisedMay2024.pdf
[5] Defense Office of Hearings and Appeals, ISCR Case No. 24-01107 (June 5, 2025). https://doha.ogc.osd.mil/Industrial-Security-Program/Industrial-Security-Clearance-Decisions/ISCR-Hearing-Decisions/2025-ISCR-Hearing-Decisions/FileId/237257/
[6] Defense Office of Hearings and Appeals, ISCR Case No. 23-00320 (July 23, 2024). https://doha.ogc.osd.mil/Industrial-Security-Program/Industrial-Security-Clearance-Decisions/ISCR-Hearing-Decisions/2024-ISCR-Hearing/FileId/223318/
[7] Defense Office of Hearings and Appeals, ISCR Case No. 24-01844 (July 29, 2025). https://doha.ogc.osd.mil/Industrial-Security-Program/Industrial-Security-Clearance-Decisions/ISCR-Hearing-Decisions/2025-ISCR-Hearing-Decisions/FileId/239976/
[8] Internal Revenue Service, Digital Assets. https://www.irs.gov/filing/digital-assets
[9] U.S. Office of Government Ethics, Legal Advisory LA-18-06, Guidance for Reporting Virtual Currency on Financial Disclosure Reports (June 18, 2018). https://www.oge.gov/web/oge.nsf/News+Releases/D9038B8D8DE24D88852585BA005BEC34/$FILE/LA-18-06.pdf
[10] U.S. Office of Government Ethics, Legal Advisory LA-22-04, Application of the Securities and Mutual Fund Exemptions to Cryptocurrency, Stablecoins, and Related Investments (July 5, 2022). https://www.oge.gov/web/oge.nsf/News+Releases/E116F1FD24F94BB3852588770058A0FA/$FILE/LA-22-04.pdf
[11] Financial Crimes Enforcement Network, Notice 2020-2, Report of Foreign Bank and Financial Accounts (FBAR) Filing Requirement for Virtual Currency (Dec. 2020). https://www.fincen.gov/system/files/shared/Notice-Virtual%20Currency%20Reporting%20on%20the%20FBAR%20123020.pdf
[12] 18 U.S.C. § 1001, Statements or entries generally (Legal Information Institute, Cornell Law School). https://www.law.cornell.edu/uscode/text/18/1001
Around July 29, 2026, unknown group of attackers gained unauthorized access to Liechtenstein’s Register of Beneficial Owners.
They copied records of approx. 31K+ legal entities, including companies, foundations, and trusts ([1]).
For U.S. families and family offices that hold assets through those structures (including crypto), this is not a tale about how European compliance works.
It is a personal security event, and the next wave of attacks could happen by email, phone, and video call.
This article explains what information was exposed and who may be affected.
It also explores how ordinary data can could become more sensitive when combined with information available through US public databases (e.g., ADV filings submitted by investment advisers to the SEC).
With today’s advanced AI-powered search and pattern-recognition tools, bad actors can uncover insights that would have been difficult to identify just a few years ago.
Finally, it talks about the steps that families with asset protection trusts in Liechtenstein,Cook Islands, Nevis, and other trust-register jurisdictions should consider reviewing now.
This article also touches upon a question that offshore asset protection trust attorneys are increasingly asked after incidents like this: if trust assets are compromised as part of a cyberattack (e.g., account takeover involving a trust bank account or cryptocurrency wallet,), who bears the loss?
Many readers would be surprised to learn that many trust agreements are either silent on this issue or have provisions, placing the risk of loss on someone other than the trustee.
For a more detailed discussion of that issue, see our article, “AI Cyberattacks and Asset Protection Trusts: Who Bears the Loss?“
Key takeaways
- Liechtenstein’s government confirms that data on more than 30K+ legal entities was copied without authorization.
- The Five Eyes cyber agencies, including the NSA, said on June 22, 2026 that frontier AI is changing offensive cyber capabilities – “The timeline is not years, it is months.”
- U.S.families and invididuals should assess their exposure and upgrade cybersecurity.
What was taken
According to the Liechtenstein government, compromised records included names of legal entities and identifying information about their beneficial owners, including names, DOBs, nationalities, countries of residence, etc. ([1]).
The government’s incident response review determined that intrusion was made possible by a flaw in the system’s authorization controls ([2]). Officials described the incident as highly sophisticated attack. ([3]).
For families that use offshore structures, the significance of the breach is beyond the loss of data.
Whoever got these records may now have verified information of who owns or controls thousands of private wealth structures (together with personal information that could be used in phishing, social engineering and impersonation).
How Cybercriminals Build a Targeted List
Beneficial ownership data becomes far more sensitive when it can be matched with info available from other public sources.
For example, every U.S. investment adviser registered with the US Securities and Exchange Commission has to file Form ADV. Much of the information disclosed in those filings is publicly available through SEC’s portal ([4], p. 12).

The issue is that Form ADV shows not only the identity of an advisory firm and its key personnel, but also the firm’s AUM, approx. number of client accounts, and portion of assets that attributed to non-U.S. clients ([5], pp. 13-14).
When combined with beneficial ownership records, this information can provide a road map for cybercriminals.
Recent cyber warnings (e.g., NSA Five Eyes report) and the fallout from the Liechtenstein breach highlight how investment advisers could become attractive targets for sophisticated cyberattacks.
Aggregated public records can identify HNW, where they operate, and professionals who advise them.They could also trace the entities through which they hold and manage assets.
That, in turn, could increase the risk of targeted phishing, business email compromise, impersonation, and other social engineering attacks.
FinCEN has already warned that criminals combine generative-AI images with “stolen personally identifiable information” to build fake identities that pass customer identification and due diligence controls ([7], pp. 2–3).
The FBI’s Internet Crime Complaint Center received 1,008,597 complaints in 2025 with $20.877 billion in reported losses; personal data breach alone accounted for $1.31 billion; business email compromise was apprx. $3.05 billion ([8], pp. 6–8).
Five Eyes Warning
Liechtenstein breach did not occur in isolation.
Just weeks before news of the incident emerged – on June 22, 2026, the NSA and its counterparts in the United Kingdom, Canada, Australia, and New Zealand issued a joint statement on artificial intelligence and cyber risk ([9]).

“Frontier AI models are anticipated to exceed current industry expectations, fundamentally transforming both offensive and defensive cyber capabilities. The timeline is not years, it is months.” — Five Eyes Cyber Security Agencies Statement, June 22, 2026 ([9])
Five Eyes agencies urged organizations saying “Breaches will occur. Preparedness helps you contain them quickly and prevent escalation into major operational and financial crises.”
The guidance was even more than blunt: “Test response plans, train and prepare teams, and assume breaches will occur” ([9]).
For many families with domestic/offshore asset protection trusts, that advice is no longer theoretical.
If the organization never rehearsed how to verify and respond to such a request, it could be exactly the type of target the Five Eyes warning was describing.
Family offices, trustees, and advisers should consider running tabletop exercises and updating their business continuity and incident response plans. This could help to address AI-enabled fraud and attacks.
Cook Islands, Nevis, Liechtenstein: what to review in an existing offshore trust
Liechtenstein register exists because anti-money-laundering rules now require most jurisdictions to record who stands behind a structure ([1]).
The lesson is not limited to Liechtenstein.
Families with offshore structures in foreign jurisdictions (Cayman Islands, Cook Islands, Nevis, Jersey etc.) should assume that similar information exists in trustee records, banking files, and due diligence databases.
Each database has valuable identity information. Each can become a target. Choose your jurisdiction wisely.
The takeaway is not to abandon offshore planning. It is to choose the jurisdiction, trustee, and structure carefully. You should understand that cyber risks are now as important as legal, creditor and tax risk.
In our experience, many U.S. domestic and offshore trusts were drafted long before today’s cyber threats emerged, i.e., the Five Eyes’s Report.
If the trust agreement is silent or unclear on cyber risk and loss allocation, a fresh review of the trust agreement would not hurt.
Depending on the trust instrument and governing law, cyber-related gaps can often be addressed through amendments, trust protector action, or other mechanisms.
If a structure no longer serves its purpose, orderly wind-down could be appropriate.
U.S. tax and reporting consequences should be reviewed before any assets are moved. U.S. tax and reporting obligations should be reviewed before any assets are moved.
When a trustee loses the money: who bears the loss
If a trustee wires trust assets to a fraudster impersonating a settlor, protector, or adviser, the first document to read is the trust agreement.
Many clients are surprised to learn that, for example, New York Banking Law § 100 authorizes a trust company to act in a fiduciary capacity and to “receive, take, manage, hold and dispose of” trust property according to the terms of the trust.
The statute, however, DOES NOT expressly say that the trustee must protect (or has a duty to safeguard) trust assets from foreseeable account takeovers, deepfakes, or other cyber fraud schemes.
That should raise an obvious question: if New York does not clearly address those duties by default, what exactly do the default rules say in Delaware, South Dakota, the Cook Islands, Nevis, or another offshore jurisdiction?
From our experience, most settlors and beneficiaries have no idea.
To be sure, trust statutes establish guardrails. Delaware, for example, allows a trust instrument to modify a fiduciary’s powers, duties, standard of care, indemnification rights, and liability ([15], § 3303(a)).
New York goes even further. Under New York E.P.T.L. § 11-1.7, a provision that relieves a fiduciary from liability for failing to exercise reasonable care, diligence, and prudence is void as against public policy ([16]).
These statutory frameworks provide useful guidance.
However, they don’t fully address a critical modern question – does a trustee have affirmative duty to protect trust assets from AI-enabled fraud, account takeovers, or other cyber threats? And if those safeguards fail, is the trustee responsible?
That is why families should not rely on default rules.
If the settlor expects the trustee to follow specific cybersecurity procedures or pick-up the risk of loss due a cyber-event like an account-takeover, those expectations should be written directly into the trust agreement.
If your trust agreement does not address cybersecurity risks, Dilendorf Law Firm can help evaluate whether an amendment, decanting, or other trust modifications may be appropriate.
Likewise, if your trust has suffered losses as a result of a cyber incident, account takeover, or related fraud, please contact us to discuss your potential claims and evaluate your legal options.
What to do in the first 30 days
- Confirm your exposure. Liechtenstein instructed legal entities to notify their beneficial owners in writing, with letters going out since August 4, 2026; questions may be directed to the Office of Justice at vwbpfragen@llv.li ([1]). Ask your trustee or foundation council for a copy of the notice and a list of the data fields involved.
- Upgrade Security. CISA advises highly targeted individuals to use phishing-resistant FIDO security keys or passkeys. Review CISA guidance for more personal cybersecurity tips ([10]).
- Account Security. Increase security controls for bank and investment accounts. ,
- Review the trust instrument. Review trust agreements to understand trustee’s cyber responsibilities and who bears the risk of loss from an account takeover.
How Dilendorf Law Firm helps
Dilendorf Law Firm advises HNW individuals and family offices on offshore and domestic asset protection trusts. The firm reviews and updates existing trust structures to address modern cyber risks.
Where appropriate, it also represents settlors and beneficiaries in claims involving trustee misconduct, negligence and breach of fiduciary duties that resulted in cyber-related losses.
The firm helps HNW clients, family offices and investment managers prepare for cyber threats through tabletop exercises and incident-response planning.
Following a cyber incident, the firm works with the FBI’s IC3 and retired law enforcement cyber specialists on evidence preservation, fund recovery efforts, and communications with financial institutions and trustees.
If trust assets were transferred as a result of an account takeover, fraudulent instruction, or other cyberattack, and you believe the loss resulted from a trustee’s negligence, Dilendorf Law Firm can evaluate potential claims against the trustee and other responsible parties.
Contact Us
To discuss an offshore or domestic asset protection trust, a breach notice, or losses involving a trustee or custodian, contact Max Dilendorf at +1 212 457 9797 or info@dilendorf.com. You may also reach us through our contact page.
This article is for general informational purposes only and does not constitute legal advice. Reading it does not create an attorney-client relationship with Dilendorf Law Firm. Attorney Advertising.
Frequently asked questions
How do I find out whether my family’s structure was affected by the Liechtenstein breach?
Ask the entity’s trustee, foundation council, or registered agent. The Liechtenstein government has directed legal entities to inform their beneficial owners of the personal data breach, with letters going out since August 4, 2026. It operates a dedicated inquiry address, vwbpfragen@llv.li, staffed by the Office of Justice ([1]). Because deleted entities were also affected, structures wound up years ago may still be included ([1]).
What personal information did the attackers get?
The government states the copied data includes the legal entity’s name and, for each beneficial owner, the role held, surname, first name, date of birth, nationality or nationalities, and country of residence ([1]). There is no indication that records were altered or deleted, and the government has not stated that the data has been publicly released ([1]).
How could criminals use a beneficial owner list against me?
The most likely uses are impersonation and social engineering. FinCEN reports that criminals pair stolen personally identifiable info with AI-generated data to create fake identities that could defeat bank verification controls ([7], pp. 2–3). Knowing the exact entity a family controls also makes a fraudulent trustee, banker, or lawyer email far more convincing. Business email compromise produced $3.05 billion in reported U.S. losses in 2025 ([8], p. 8).
Should I update, move, or terminate my Cook Islands or Nevis trust after the Liechtenstein breach?
Not automatically, and not without reading the deed first. The breach shows that identity data behind offshore structures is a target. Practical question becomes is whether your instrument tells the trustee how to verify instructions and what to do after a breach notice. Depending on the deed and the governing law, trust agreement could be fixed by amendment, protector action, decanting, etc.; a wind-down is a last resort that must be coordinated with U.S. tax and reporting obligations. Offshore asset protection trust attorney should review the instrument before any asset moves. Contact Dilendorf Law Firm for a consultaiton.
Can I sue my offshore trustee if it wired trust funds to a fraudster?
Possibly, depending on the facts. The trust instrument and governing law decide most of these cases. Delaware lets an instrument vary a fiduciary’s “standard of care, rights of indemnification and liability” but not excuse “wilful misconduct” ([15]), and New York voids clauses that exonerate a fiduciary “from liability for failure to exercise reasonable care, diligence and prudence” ([16]). Offshore statutes often allow broader exculpation, and Delaware bars claims one year after an adequate trustee report ([17]), so timing and evidence preservation matter.
Is my U.S. beneficial ownership information also exposed?
Not through FinCEN’s register, based on current rules. FinCEN’s March 2025 interim final rule, finalized on August 11, 2026, exempts all entities created in the United States and their beneficial owners from reporting; only certain foreign-formed companies registered to do business in a U.S. state remain reporting companies ([12]). Your exposure in the United States comes mainly from public adviser filings and from your own advisers’ systems, not from a federal ownership database.
What are the warning signs of an attack that uses this data?
Watch for unexpected contact that references your specific foundation, trust, or company by name; requests to change wire instructions or add a signatory; new devices or logins on email and brokerage accounts; and a mobile phone that suddenly loses service, which can signal a number-porting attack. CISA recommends a carrier PIN precisely because porting a number is “a critical step in countering” account takeover ([10]).
What should I do in the first 48 hours after a suspicious wire or account change?
Contact the bank immediately and request a recall of the funds, then file a complaint at ic3.gov with the full transaction details ([8], p. 17). Complaints that meet IC3’s thresholds are routed to the Recovery Asset Team, and for foreign wires the International Financial Fraud Kill Chain is coordinated through FinCEN’s Rapid Response Team and FBI legal attachés ([13]). Preserve emails, call logs, and instruction records before anything is deleted.
What is a tabletop exercise and why would a family office need one?
A tabletop exercise is a facilitated discussion that walks decision-makers through a realistic incident, tests who does what, and exposes gaps before a real event. The Five Eyes agencies told organizations to “Test response plans, train and prepare teams, and assume breaches will occur” ([9]). CISA’s free packages include template objectives, scenarios, and discussion questions for ransomware, phishing, and insider threats ([11]). Dilendorf Law Firm runs these exercises for family offices and investment managers and tailors the scenarios to the family’s actual structures and counterparties.
When should I involve a lawyer?
Involve counsel as soon as you receive a breach notice, before any funds move. A lawyer can coordinate the response with trustees in multiple jurisdictions, preserve evidence in a form law enforcement can use, manage the IC3 filing and bank recall requests, and evaluate whether a bank, custodian, or trustee that honored a fraudulent instruction may bear responsibility, which depends on the facts and the governing agreements. Dilendorf Law Firm coordinates with IC3 and retired cybersecurity law enforcement specialists in these matters.
Sources
[1] Government of the Principality of Liechtenstein, “Cyberattack on the VwbP: latest information” (updated August 2026). https://regierung.li/text/16188/topics
[2] Government of the Principality of Liechtenstein, press release, “Following the cyberattack: security analyses completed” (August 19, 2026). https://www.regierung.li/medienportal-medium/16444/234754/0/medienmitteilung
[3] Government of the Principality of Liechtenstein, press release, “Krimineller Angriff auf das VwbP: Potenzielles Einfallstor identifiziert” (August 4, 2026). https://www.regierung.li/medienportal-medium/16182/234671/medienmitteilung
[4] U.S. Securities and Exchange Commission, Form ADV General Instructions, SEC 1707 (07-24), p. 12. https://www.sec.gov/files/formadv-instructions.pdf
[5] U.S. Securities and Exchange Commission, Form ADV Part 1A, Item 5.F, pp. 13–14. https://www.sec.gov/files/formadv-part1a_1.pdf
[6] 17 C.F.R. § 275.202(a)(11)(G)-1, Family offices (Legal Information Institute, Cornell Law School). https://www.law.cornell.edu/cfr/text/17/275.202(a)(11)(G)-1
[7] FinCEN, Alert FIN-2024-Alert004, “FinCEN Alert on Fraud Schemes Involving Deepfake Media Targeting Financial Institutions” (November 13, 2024), pp. 2–3. https://www.fincen.gov/system/files/shared/FinCEN-Alert-DeepFakes-Alert508FINAL.pdf
[8] FBI Internet Crime Complaint Center, 2025 Internet Crime Report, pp. 6–8, 17. https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf
[9] National Security Agency, “Five Eyes Cyber Security Agencies Statement” (June 22, 2026). https://www.nsa.gov/Press-Room/News-Highlights/Article/Article/4523810/five-eyes-cyber-security-agencies-statement/
[10] Cybersecurity and Infrastructure Security Agency, “Mobile Communications Best Practice Guidance” (December 18, 2024). https://www.cisa.gov/sites/default/files/2024-12/guidance-mobile-communications-best-practices.pdf
[11] Cybersecurity and Infrastructure Security Agency, “CISA Tabletop Exercise Packages.” https://www.cisa.gov/resources-tools/services/cisa-tabletop-exercise-packages
[12] FinCEN, “Beneficial Ownership Information Reporting” (final rule issued August 11, 2026, effective August 14, 2026). https://www.fincen.gov/boi
[13] FBI Internet Crime Complaint Center, “International Financial Fraud Kill Chain Process.” https://www.ic3.gov/Outreach/Brochures/IC3-FFKC_International.pdf
[14] FinCEN, “FinCEN Issues Final Rule to Postpone Effective Date of Investment Adviser Rule to 2028” (December 31, 2025). https://www.fincen.gov/news/news-releases/fincen-issues-final-rule-postpone-effective-date-investment-adviser-rule-2028
[15] 12 Del. C. ch. 33, Administrative Provisions, §§ 3302(e), 3303(a) (Delaware Code Online). https://delcode.delaware.gov/title12/c033/index.html
[16] N.Y. Estates, Powers and Trusts Law § 11-1.7 (New York State Senate). https://www.nysenate.gov/legislation/laws/EPT/11-1.7
[17] 12 Del. C. §§ 3585–3586, Limitations on actions against trustees (Delaware Code Online). https://delcode.delaware.gov/title12/c035/sc07/index.html
Regulated employers and government agencies increasingly ask about crypto holdings and activities on job applications, renewal forms, and background questionnaires.
The questions could appear straightforward, but for individuals who have been involved with crypto for several years, the answers get more complex.
A disclosure may involve multiple exchanges, offshore trading platforms, self-custody wallets, token investments, staking activities, or participation in crypto projects.
This article examines common situations that can make crypto-related disclosures challenging. It explains how Dilendorf Law Firm helps applicants provide accurate, complete, and defensible responses.
How Dilendorf Law Firm helps
Max Dilendorf has practiced in the cryptocurrency and digital asset space since 2017. He advises clients on crypto compliance matters involving the Bank Secrecy Act (BSA), securities laws, CFTC regulations, and FinCEN requirements.
Dilendorf Law Firm reviews the actual form language, reconstructs your crypto history from exchange records and blockchain data. It will help you draft answers that are truthful, complete, and consistent across employment, licensing and security-clearances. .
Where the underlying problem needs fixing, the firm works with your accountant on prior-year tax reporting, requests records and explanations from exchanges, and evaluates claims against platforms whose freezes or closures caused loss.
The firm has served as counsel of record in more than 130 crypto-related cybercrime arbitration matters before AAA, JAMS, and NAM, involving testimony from retired FBI law enforcement expert witnesses.
Depending on the nature of a client’s case, the firm regularly works with retired law enforcement experts from the FBI, U.S. Department of Justice (DOJ), and Department of Homeland Security (DHS) to provide expert witness support in crypto and regulatory matters, including issues arising from employment applications, background investigations, and professional license renewals discussed in this article.
Who gets asked about crypto, and why
Regulators treat crypto as investment property that can create conflicts of interest.
The U.S. Office of Government Ethics (“OGE”) determined in 2018 that crypto “property held . . . for investment or the production of income” must be reported on federal financial disclosure reports, naming the exchange or platform where it is held ([1]).
The same logic applies to private-sector job application/renewal forms.
Traders and analysts at hedge funds and registered investment advisers file holdings reports within 10 days of becoming an “access person.”
After that, the filing comes in every 12 months, plus quarterly transaction reports listing every account holding securities for them ([8]).
Registered representatives at broker-dealers certify on Form U4 that their answers are “true and complete to the best of my knowledge” and accept “a continuing obligation to amend and update” the form ([9]).
Federal employees, contractors, and clearance holders complete the Standard Form 86 (SF-86). This form asks, among other things, about foreign financial interests, self-employment, tax compliance, debts, and civil court actions ([10]).
Bank and fintech compliance staff face a statutory bar on anyone convicted of an offense involving “dishonesty or a breach of trust or money laundering” ([12]).
Five situations where the truthful answer gets complicated
Clients come to Dilendorf Law Firm with one of these fact patterns, and often with several.
1. An exchange closed or froze your account citing KYC or AML rules. Exchanges are money transmitters subject to anti-money-laundering programs and suspicious activity reports(“SAR”) filings ([3]).
Under SAR regulations, crypto exchanges “are prohibited from disclosing to a person involved in the transaction that a suspicious activity report has been filed” ([4]).
So as an exchange’s customer, you will never find out that the exchange filed SAR form with FinCen (unless you hear from FinCen directly – which hopefully will never be the case).
The CFPB has found that platforms “sometimes cite boilerplate user agreement language to absolve themselves of responsibility” for frozen accounts ([7]).
You are left with a closure notice (sometimes citing alleged violations of KYC/BSA regulations), no explanation, and a form asking whether any account was ever restricted.
2. Your crypto sits on a foreign exchange or in an offshore entity. The SF-86 asks if you have “EVER had any foreign financial interests (such as stocks, property, investments, bank accounts . . .)” under your direct control ([10]).
FinCEN explained that that a foreign account holding only virtual currency “is not reportable on the FBAR” today but that it “intends to propose to amend the regulations” to cover it ([5]).
How to list a non-U.S. exchange account depends on the form’s wording and your prior answers.
3. A past tax year never accounted for your crypto. Every Form 1040 filer must answer the digital asset question, and “taxpayers must report all income related to their digital asset transactions” ([6]).
The SF-86 separately asks whether, in the last seven years, you “failed to file or pay Federal, state, or other taxes when required by law” ([10]).
For example, an unreported staking reward or an unfiled amended return can turn a holdings question into a tax-compliance question.
4. Your holdings conflict with the job. OGE determined that because crypto and stablecoins are not publicly traded securities, “no de minimis exemption applies,” so an employee holding any amount may not work on a matter that could directly and predictably affect its value ([2]).
Fund codes of ethics impose pre-clearance and reporting duties of their own ([8]).
Deciding what to divest, disclose, or recuse from before the start date is a legal judgment.
5. You built, advised, or lost money in a crypto venture. Form U4 asks if you are “engaged in any other business either as a proprietor, partner, officer, director, employee, trustee, agent or otherwise” ([9]).
Moreover, the SF-86 requires all self-employment for ten years ([10]).
A token launch, a DAO role, or a mining operation belongs on those forms. The same could be true for aftermath of a hack or fraud: the SF-86 asks about judgments, liens, debts over 120 days delinquent, and any civil court action in ten years ([10]).
How to answer truthfully
Answer the questions that were actually asked. You should be disclosing information only that it responsive to the question; don’t characterize unexplained account closure as legal misconduct or violation unless the finding of law was actually made.
Gather the closure notice, statements, tax returns, and prior forms first, and check every new answer against every earlier one.
For example, the SF-86 guide warns that “responses to this form may be compared with your responses to previous SF 86 questionnaires” ([11]). Amend when facts change.
The stakes are high. Knowingly and willfully making a materially false statement in a matter within federal jurisdiction can result in criminal penalties, including up to five years’ imprisonment ([13]).
The the SF-86 warns that agencies “generally fire, do not grant a security clearance, or disqualify individuals who have materially and deliberately falsified these forms” ([10]).
Contact Us
To discuss a job application, renewal, clearance, or disclosure question involving crypto, contact Max Dilendorf at +1 212 457 9797 or info@dilendorf.com, or use our contact page.
This article is for general informational purposes only and does not constitute legal advice. Reading it does not create an attorney-client relationship with Dilendorf Law Firm. Attorney Advertising.
Frequently asked questions
Do I have to disclose crypto holdings on a hedge fund job application?
Often yes, if you will be an “access person” of a registered investment adviser. The SEC’s code-of-ethics rule requires access persons to report their securities holdings within 10 days of joining, at least every 12 months afterward, and to file quarterly transaction reports, including the name of every broker, dealer, or bank holding securities for them ([8]). Whether a token is a reportable security depends on the facts, and many funds require reporting of all digital assets regardless.
My exchange closed my account citing KYC or AML rules. Do I have to report that?
It depends on the exact question, and the wording matters. Some forms ask only about holdings; others ask about accounts, investigations, or findings. Exchanges are money transmitters with anti-money-laundering and suspicious-activity-reporting duties, and they may not tell you whether a report was filed ([3], [4]). Answer the question asked, accurately, without guessing at the exchange’s reasons.
Is an exchange account closure the same as a finding of money laundering?
No. A closure is a private company’s decision under its user agreement, not a determination by a regulator or court. The CFPB has noted that platforms “sometimes cite boilerplate user agreement language to absolve themselves of responsibility” when consumers lose access to accounts ([7]). Forms that ask about convictions or pretrial diversion, such as the bank-hiring bar in 12 U.S.C. § 1829, address a different category of event ([12]).
Do federal employees and clearance holders have to report crypto?
Yes, subject to thresholds. OGE treats virtual currency as property held for investment and requires it to be reported when the holding exceeded $1,000 at the end of the reporting period or produced more than $200 of income, naming the exchange or platform ([1]). Because no de minimis exemption applies, any holding can require recusal from a matter that would affect its value ([2]).
Does crypto on a foreign exchange count as a foreign financial interest on the SF-86?
It may. Section 20A.1 asks whether you have “EVER had any foreign financial interests (such as stocks, property, investments, bank accounts . . .)” in which you have direct control or ownership ([10]). The form does not mention crypto by name, and FinCEN has said a foreign account holding only virtual currency is not currently reportable on the FBAR, although it intends to propose a rule change ([5]). How a non-U.S. exchange account fits depends on the facts, so get advice before answering.
I never reported crypto on an old tax return. Does that matter for a job application?
It can. The IRS requires every Form 1040 filer to answer the digital asset question and to report all income from digital asset transactions ([6]). The SF-86 asks whether you failed to file or pay taxes when required in the last seven years ([10]). Correcting prior returns before you sign the questionnaire is often the cleanest path, and counsel can coordinate that with your accountant.
Do I have to list a token project, DAO role, or mining operation on Form U4 or the SF-86?
Usually yes. Form U4 Section 13 asks whether you are “engaged in any other business either as a proprietor, partner, officer, director, employee, trustee, agent or otherwise,” including whether it is investment-related and how many hours you devote to it ([9]). The SF-86 requires all employment and self-employment for the past ten years without gaps ([10]). How to describe an informal or unincorporated crypto venture is a judgment call worth making with counsel.
What happens if I answer a crypto question wrong on a federal form or Form U4?
The consequences can be severe. Knowingly and willfully making a materially false statement to the federal government carries up to five years in prison ([13]), and the SF-86 warns that agencies “generally fire, do not grant a security clearance, or disqualify” applicants who falsify the form ([10]). Form U4 applicants acknowledge exposure to “administrative, civil or criminal penalties” for false or misleading answers ([9]). Honest mistakes should be corrected by amendment as soon as they are discovered.
Why hire an experienced crypto attorney for a job application question?
Because the answer turns on how exchanges, custody, tax reporting, and compliance programs actually work. Max Dilendorf has practiced cryptocurrency and digital-asset law since 2017, and Dilendorf Law Firm has been counsel of record in more than 130 cybercrime-related arbitration matters before AAA, JAMS, and NAM. The firm helps applicants address crypto questions on employment, licensing, clearance, and financial-disclosure forms, and it evaluates claims against exchanges when a freeze or closure causes loss.
Sources
[1] U.S. Office of Government Ethics, Legal Advisory LA-18-06, “Guidance for Reporting Virtual Currency on Financial Disclosure Reports,” June 18, 2018. https://www.oge.gov/web/oge.nsf/News+Releases/D9038B8D8DE24D88852585BA005BEC34/$FILE/LA-18-06.pdf
[2] U.S. Office of Government Ethics, Legal Advisory LA-22-04, “Application of the Securities and Mutual Fund Exemptions to Cryptocurrency, Stablecoins, and Related Investments,” 2022. https://www.oge.gov/web/oge.nsf/News+Releases/E116F1FD24F94BB3852588770058A0FA/$FILE/LA-22-04.pdf
[3] FinCEN, Guidance FIN-2019-G001, “Application of FinCEN’s Regulations to Certain Business Models Involving Convertible Virtual Currencies,” May 9, 2019. https://www.fincen.gov/sites/default/files/2019-05/FinCEN%20Guidance%20CVC%20FINAL%20508.pdf
[4] FinCEN, “Money Services Business (MSB) Suspicious Activity Reporting.” https://www.fincen.gov/money-services-business-msb-suspicious-activity-reporting
[5] FinCEN, Notice 2020-2, “Report of Foreign Bank and Financial Accounts (FBAR) Filing Requirement for Virtual Currency,” Dec. 2020. https://www.fincen.gov/system/files/shared/Notice-Virtual%20Currency%20Reporting%20on%20the%20FBAR%20123020.pdf
[6] Internal Revenue Service, IR-2023-12, “IRS: Updates to question on digital assets; taxpayers should continue to report all digital asset income,” Jan. 24, 2023. https://www.irs.gov/newsroom/irs-updates-to-question-on-digital-assets-taxpayers-should-continue-to-report-all-digital-asset-income
[7] Consumer Financial Protection Bureau, “Complaint Bulletin: An analysis of consumer complaints related to crypto-assets,” Nov. 10, 2022. https://files.consumerfinance.gov/f/documents/cfpb_complaint-bulletin_crypto-assets_2022-11.pdf
[8] 17 C.F.R. § 275.204A-1, Investment adviser codes of ethics (Legal Information Institute). https://www.law.cornell.edu/cfr/text/17/275.204A-1
[9] Form U4, Uniform Application for Securities Industry Registration or Transfer, as filed on SEC.gov. https://www.sec.gov/files/rules/other/nasdaqllcf1a4_5/f_formu4.pdf
[10] U.S. Office of Personnel Management, Standard Form 86, Questionnaire for National Security Positions (rev. Nov. 2016). https://www.opm.gov/forms/pdf_fill/sf86.pdf
[11] Defense Counterintelligence and Security Agency, “Completing your Investigation Request in e-QIP: Guide for the Standard Form (SF) 86,” July 2018. https://www.dcsa.mil/Portals/128/Documents/pv/mbi/standard-form-sf-86-guide-for-applicants.pdf
[12] 12 U.S.C. § 1829, Penalty for unauthorized participation by convicted individual (Legal Information Institute). https://www.law.cornell.edu/uscode/text/12/1829
[13] 18 U.S.C. § 1001, Statements or entries generally (Legal Information Institute). https://www.law.cornell.edu/uscode/text/18/1001
Asset protection trusts (domestic and offshore) were designed to keep assets away from creditors.
In 2026, a different question is becoming just as important: can the trustee protect those assets from cybercriminals?
If a criminal gains control of the trust’s bank, brokerage, or custody account, who bears the loss? Does the trustee absorb that risk, or do the beneficiaries?
These issues are best addressed in the trust agreement from the outset. Waiting for a judge or arbitrator to determine responsibility after trust assets have been compromised is a far less desirable outcome.
Why the Question Matters Now
The threat to trust accounts is no longer theoretical. The federal agencies that track the evolving AI risks are measuring the timeline in months.
On June 22, 2026, the Five Eyes cyber security agencies, led by the National Security Agency (“NSA”), warned that:
“Frontier AI models are anticipated to exceed current industry expectations, fundamentally transforming both offensive and defensive cyber capabilities. The timeline is not years, it is months. In this environment, cyber resilience is integral to advancing business continuity, market confidence, and long-term value” ([1]). [emphasis added]
The same statement calls cyber risk “a core business risk and leadership responsibility,” and a trustee holding a family’s liquid wealth is exactly the kind of leader it is addressing ([1]).
The Federal Bureau of Investigation (“FBI”) Internet Crime Complaint Center (IC3) recorded $20.877 billion in reported losses for 2025, including $3,046,598,558 from business email compromise and roughly 4,700 account-takeover complaints totaling $359.7 million ([2]).
Family offices and investment managers are exposed for a structural reason. Form ADV (including the adviser’s business, ownership, clients ) is published on the Securities and Exchange Commission’s (“SEC”) Investment Adviser Public Disclosure website. This is a public domain of who manages significant wealth ([14]).
What New York and Delaware Law Say
Neither New York nor Delaware imposes a specific statutory duty on trustee to safeguard trust accounts against cyberattack or account takeover. Both rely on general prudence standards that written before frontier AI existed.
New York. The Estates, Powers and Trusts Law (EPTL) § 11-2.3 requires a trustee to “exercise reasonable care, skill and caution” as “a prudent investor would,” judged by “facts and circumstances prevailing at the time of the decision or action” ([3]).
The section appears to apply to investments held on or after January 1, 1995. It does not mention anything about cybersecurity standards. It just says that: “A trustee shall exercise reasonable care, skill and caution to make and implement investment and management decisions as a prudent
investor would for the entire portfolio…” ([3])
Banking Law § 100 lists a trust company’s fiduciary powers without imposing any affirmative safeguarding duty ([4]).
In our arbitration practice, a trustee has taken the position that under the NY Banking Law § 100, a trustee does not have an express duty to safeguard trust assets against a foreseeable account takeover.
New York does, however, void any attempt to exonerate an inter vivos or testamentary trustee “from liability for failure to exercise reasonable care, diligence and prudence” ([5]). But the question becomes – what’s reasonable in the agentic AI era?
Delaware. Title 12, § 3302(a) requires a fiduciary to act “with the care, skill, prudence and diligence under the circumstances then prevailing that a prudent person acting in a like capacity and familiar with such matters would use” ([6]).
The section’s history note runs from the Delaware Code of 1915 through later amendments. None of the amendments added anything relating to cybersecurity, account security, or safeguarding ([6]). A prudent-person standard that was initially drafted in 1915 now has to be applied to AI cyber threats the NSA says is measured in months.
Delaware also lets the governing instrument “expand, restrict, eliminate, or otherwise vary” a fiduciary’s “standard of care, rights of indemnification and liability,” with a floor only at “wilful misconduct” ([7]).
A settlor who signs a trust-company form without reading that clause may have waived the right to recover a negligent cyber loss.
| Jurisdiction | Standard of care | May the instrument reduce it? | Express cyber or safeguarding duty? |
|---|---|---|---|
| New York | “reasonable care, skill and caution” as a “prudent investor” ([3]) | Not below reasonable care; exoneration void ([5]) | None found ([3], [4]) |
| Delaware | “care, skill, prudence and diligence under the circumstances then prevailing” ([6]) | Yes, down to a wilful-misconduct floor ([7]) | None found, including in the Qualified Dispositions in Trust Act ([6], [9]) |
Regulation Is Not Private Risk Allocation
A regulated trustee’s cybersecurity rules protect the institution and its regulator, not the settlor’s trust agreement. New York’s 23 NYCRR Part 500 requires every “covered entity” licensed under the Banking Law to maintain a cybersecurity program and use multi-factor authentication ([11]).
Those duties apply to the NY Department of Financial Services (“NYDFS”), not to a beneficiary, and an individual or family.
As a matter of fact, grantor, beneficiary or family can’t even asset a claim against a trustee based on alleged violation of NYDFS cybersecurity standards. Part 500 does not provide a private right of action.
A separate question is what cybersecurity requirements apply to a foreign trustee. The answer will depend on the laws and regulatory framework of the trustee’s jurisdiction. This is is one of many considerations for those evaluating offshore asset protection trusts.
The bank owes less than clients expect. Under Uniform Commercial Code (UCC) § 4A-202(b), an unauthorized wire is effective as the customer’s order if the bank’s security procedure was “a commercially reasonable method of providing security against unauthorized payment orders” and was followed in good faith ([10]).
The trustee, not the bank, is often the first and last line of defense.
A Public Yardstick for Trustee Cybersecurity
Settlors do not need to be technologists to measure a trustee.
The National Institute of Standards and Technology (“NIST”) Cybersecurity Framework (CSF) 2.0 organizes cybersecurity outcomes into six functions, “GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND, and RECOVER,” and is “designed to be used by organizations of all sizes and sectors” ([12]).
The Cybersecurity and Infrastructure Security Agency (“CISA”) ranks multi-factor authentication types from strongest to weakest, with phishing-resistant MFA a distinct category from text-message codes ([13]).
Before signing, a settlor should ask the prospective trustee, in writing:
- Who bears the loss if an account is taken over despite your controls?
- How much cybersecurity insurance does the trustee have?
- Which NIST CSF 2.0 functions does your program map to ([12])?
- Is phishing-resistant MFA required for everyone who can move trust funds ([13])?
- How is a distribution request verified out of band before a wire is released?
Putting It in the Trust Agreement
If the statute is silent, then the trust agreement should define how risk of risk of loss is allocated.
Depending on the jurisdiction, a trust agreement could impose an express duty on the trustee to safeguard accounts, credentials, and digital assets. It could also place the risk of loss arising from account takeovers to the trustee (which is a reasonable approach given today’s threat environment).
It is no longer unusual for a trust to name a cybersecurity adviser together the investment adviser and administrative trustee (especially true where cryptocurrency is part of the estate).
Delaware’s directed-trust statute allows the instrument to give a person authority to direct or veto a fiduciary’s “investment decisions, distribution decisions or other decision of the fiduciary” ([8]).
The instrument should also say where a dispute will be heard.
Under the Federal Arbitration Act, a written arbitration provision in a contract involving commerce is “valid, irrevocable, and enforceable” ([15]). Settlors commonly designate American Arbitration Association (AAA) or JAMS arbitration in a U.S. venue so that a negligence claim is not litigated first in the trustee’s home forum.
Offshore Trusts Raise the Stakes
An offshore trustee can be excellent at creditor protection, but still be unexamined on AI cyber risks.
A Cook Islands trust is governed by the International Trusts Act 1984 and its amendments through 2013, published by the Cook Islands Financial Supervisory Commission ([18]). Notably, U.S. persons who fund foreign trusts must report those transactions on Internal Revenue Service (IRS) Form 3520 ([17]).
We believe many foreign trustees are still working out what the Five Eyes statement means for their business; that’s provided they’re even ware of the NSA report.
The client’s job is to know (before funding the trust) what legal mechanism operate between settlor and trustee if something goes wrong, because no one wants to litigate a negligence claim in Rarotonga.
Existing Trusts Are Not Frozen
An irrevocable trust can often be updated.
New York’s decanting statute, EPTL § 10-6.6, allows an authorized trustee to appoint principal to a new trust for the same beneficiaries ([16]).
Depending on the circumstances, decanting could be used to update a legacy trust by adding specific cybersecurity provisions and allocating the risk of cyber-related losses.
If your asset protection trust is governed by the laws of Wyoming, Delaware, South Dakota, or another jurisdiction, we can help evaluate if decanting is appropriate. Our team, which includes retired IC3 cybercrime specialists, can help structure and transfer trust assets to a new trust designed to address modern cybersecurity risks (including agentic AI cyber threats).
How Dilendorf Law Firm helps
Dilendorf Law Firm PLLC has been counsel of record in more than 130 cybercrime-related arbitration matters before AAA, JAMS, and NAM, including account-takeover and SIM-swap matters involving telecommunications carriers, cryptocurrency exchanges, and trust companies. That work, carried out alongside retired law enforcement and retired IC3 specialists, informs how the firm drafts domestic and offshore asset protection trusts for the age of AI cyber risk.
The firm drafts trust instruments with express safeguarding duties, cyber-loss risk allocated to the trustee, out-of-band verification for distributions, NIST- and CISA-benchmarked security schedules, cybersecurity adviser roles, and forum clauses. It conducts written cyber due diligence on prospective trustees, decants existing irrevocable trusts, and advises family offices, wealth managers, and investment managers on evolving risks.
Contact Us
To discuss a domestic or offshore asset protection trust, contact Max Dilendorf at +1 212 457 9797 or info@dilendorf.com.
This article is for general informational purposes only and does not constitute legal advice. Reading it does not create an attorney-client relationship with Dilendorf Law Firm. Attorney Advertising.
Frequently asked questions
Can my trustee be held responsible if the trust’s account is hacked?
Possibly, but only if the governing law or the instrument imposes a duty the trustee breached. New York’s EPTL § 11-2.3 and Delaware’s § 3302 impose general prudence standards judged by circumstances then prevailing, and neither mentions account security ([3], [6]). An express safeguarding duty and risk-of-loss clause in the trust agreement removes that ambiguity.
What did the NSA and Five Eyes agencies actually say in June 2026?
They said frontier AI models will transform offensive and defensive cyber capabilities and that “the timeline is not years, it is months” ([1]). The statement frames cyber risk as a leadership responsibility rather than a technical issue, which is the standard a settlor should hold a trustee to ([1]).
Does Delaware law let a trust company limit its liability for a cyber loss?
Yes, within limits. Delaware § 3303 permits the governing instrument to vary a fiduciary’s standard of care and liability, but not to exculpate the fiduciary’s own wilful misconduct ([7]). A settlor should read the exculpation clause before signing.
Will the bank reimburse the trust for an unauthorized wire?
Not necessarily. Under UCC § 4A-202(b), an unauthorized payment order binds the customer if the bank’s security procedure was commercially reasonable and was followed in good faith ([10]). The trustee’s own controls therefore matter more than most clients assume.
What does it mean for a trustee to be NIST-aligned?
It means the trustee’s program maps to the six NIST CSF 2.0 functions: GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND, and RECOVER ([12]). NIST designed the framework for organizations of all sizes, so a small trust company cannot claim it does not apply ([12]).
Is a regulated trust company automatically safe?
No. Rules such as 23 NYCRR Part 500 require covered entities to maintain a cybersecurity program and use multi-factor authentication, but those duties run to the regulator ([11]). They do not allocate a cyber loss between trustee and beneficiary; only the trust agreement does that.
Can an existing irrevocable trust add cybersecurity duties?
Often, yes. New York’s EPTL § 10-6.6 allows an authorized trustee to decant principal into a new trust for the same beneficiaries ([16]), and Delaware gives broad effect to instrument terms that vary fiduciary duties ([7]). Whether a specific trust qualifies depends on its terms and jurisdiction.
How should disputes with an offshore trustee be handled?
Decide before funding. A written arbitration clause is enforceable under the Federal Arbitration Act ([15]), and settlors commonly select AAA or JAMS arbitration in a U.S. venue. Without such a clause, a negligence claim may have to be brought in the trustee’s home jurisdiction.
How does Dilendorf Law Firm approach trustee cybersecurity?
The firm has been counsel of record in more than 130 cybercrime-related arbitration matters before AAA, JAMS, and NAM and drafts domestic and offshore trusts with express safeguarding duties, risk-of-loss allocation, security schedules, and cybersecurity adviser roles. It also conducts written cyber due diligence on prospective trustees before the client signs.
Sources
[1] National Security Agency, Five Eyes Cyber Security Agencies Statement (June 22, 2026). https://www.nsa.gov/Press-Room/News-Highlights/Article/Article/4523810/five-eyes-cyber-security-agencies-statement/
[2] Federal Bureau of Investigation, Internet Crime Complaint Center, 2025 IC3 Annual Report, pp. 4, 6, 8, 12, 44. https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf
[3] N.Y. Estates, Powers and Trusts Law § 11-2.3 (Prudent investor act). https://www.nysenate.gov/legislation/laws/EPT/11-2.3
[4] N.Y. Banking Law § 100 (Fiduciary powers). https://www.nysenate.gov/legislation/laws/BNK/100
[5] N.Y. Estates, Powers and Trusts Law § 11-1.7 (Limitations on powers and immunities). https://www.nysenate.gov/legislation/laws/EPT/11-1.7
[6] 12 Del. C. § 3302 (Degree of care; authorized investments). https://delcode.delaware.gov/title12/c033/index.html#3302
[7] 12 Del. C. § 3303 (Effect of provisions of instrument). https://delcode.delaware.gov/title12/c033/index.html#3303
[8] 12 Del. C. § 3313 (Advisers). https://delcode.delaware.gov/title12/c033/index.html#3313
[9] 12 Del. C. §§ 3570–3576 (Qualified Dispositions in Trust). https://delcode.delaware.gov/title12/c035/sc06/index.html
[10] Uniform Commercial Code § 4A-202 (Legal Information Institute, Cornell Law School). https://www.law.cornell.edu/ucc/4A/4A-202
[11] N.Y. Department of Financial Services, 23 NYCRR Part 500 (Second Amendment, Nov. 1, 2023). https://www.dfs.ny.gov/system/files/documents/2023/12/rf23_nycrr_part_500_amend02_20231101.pdf
[12] National Institute of Standards and Technology, The NIST Cybersecurity Framework (CSF) 2.0 (Feb. 26, 2024). https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf
[13] Cybersecurity and Infrastructure Security Agency, More than a Password (MFA). https://www.cisa.gov/MFA
[14] U.S. Securities and Exchange Commission, Investor.gov, Form ADV. https://www.investor.gov/introduction-investing/investing-basics/glossary/form-adv
[15] 9 U.S.C. § 2 (Federal Arbitration Act). https://uscode.house.gov/view.xhtml?req=granuleid:USC-prelim-title9-section2&num=0&edition=prelim
[16] N.Y. Estates, Powers and Trusts Law § 10-6.6 (Decanting). https://www.nysenate.gov/legislation/laws/EPT/10-6.6
[17] Internal Revenue Service, About Form 3520. https://www.irs.gov/forms-pubs/about-form-3520
[18] Cook Islands Financial Supervisory Commission, Legislation (International Trusts Act 1984 and amendments). https://www.fsc.gov.ck/public/content.aspx?cn=legislation
Common wire fraud fact pattern: U.S. company receives an email from a vendor that appears to be ordinary, requesting that it update its bank details before the next payment.
The controller then wires $500,000. Two days later, the vendor calls to ask where the money is.
The company contacts its bank. Bank issues a request to recall the funds.
Within a few hours, it receives a reply that the receiving bank has credited the money and that the account holder has already transferred it out in amounts ranging from $60,000 to $80,000.
There is now nothing left to return.
Business email compromise (“BEC”) is a type of fraud. The FBI’s Internet Crime Complaint Center (IC3) recorded 24,768 BEC complaints and reported losses of $3.05 billion in 2025. This makes it the second-most costly type of cybercrime ([1]).
By the 48-hour mark, when the first account has been emptied, the chances have decreased (although they have not disappeared completely).
Once the bank says that it can’t reverse the transfer, victim company should consider the following protective steps described in this post.
Why the bank can’t simply take the money back
According to Article 4A of the Uniform Commercial Code, once a payment order has been accepted, cancellation is not valid unless the receiving bank agrees to it. There is, however, a narrow exception in the case of unauthorized or mistaken orders ([11]).
Even if deceived, the company agreed to the wire. When the account number and the name do not match, the beneficiary’s bank as a general rule “may rely on the number as the proper identification of the beneficiary” ([12]). And that’s the big problem for the victim company.
A recall is a request (not a default right), and it applies only as long as the money remains in the first account.
However, by the time the victim realizes the fraud, the money is often long gone from that account.
The FBI continues to tell victims to make this request right away, together with “any necessary indemnification documents” ([1]). A request must be made; it is not the final step.
The money is not gone; it has moved
Criminals send the money stolen from victims via “money mules.” These mules get the money from the victims and send the funds to conspirators, many of whom are based overseas ([7]).
According to FBI data, the funds involved in BEC are being sent to over 140 different receiving countries, via intermediary banks in the United Kingdom, Hong Kong, China, Mexico, and the United Arab Emirates.
More and more are going into custodial accounts held by payment processors, peer-to-peer platforms, and crypto exchanges ([2]).
Batches ranging from $60,000 to $80,000 are intended to bypass banks’ AML filters.
Each of those transfers ends up in a different account at another bank, where it can be identified and, depending on the circumstances, frozen.
Step one: complete IC3 complaint
The FBI’s Recovery Asset Team (RAT) operates the Financial Fraud Kill Chain (“FFKC”). The FFKC works with banks, asking them to freeze fraudulent transfers. Dilendorf Law Firm works with retired FBI IC3 agents to facilitate processing of complaints with the IC3 unit.
In 2025, the RAT froze $679 million out of the $1.16 billion that criminals had attempted to steal, achieving a success rate of 58 percent ([1]).
For a company at hour 48, the FBI states that it “will expand the FFKC process beyond the initial recipient bank if information is provided during the FFKC initiation on ‘second hop’ transactions to other domestic or international accounts” ([1]).
FinCEN’s Rapid Response Program handles cases involving wires sent to foreign accounts and has assisted in the recovery of over $1 billion since 2015.
FinCEN says that it is most likely to interdict funds reported to law enforcement within 72 hours; however, it does not claim that recovery is impossible after that time ([3]).
Victims do not contact FinCEN themselves. Instead, they file a complaint with IC3 or the nearest Secret Service field office, providing all account and bank details for both parties along with a summary of the fraud ([3]).
A bare complaint only goes as far as the first account. One that includes all that the bank knows about the onward transfers allows the FBI to pursue the second hop.
Step two: push the banks to use their own tools
FinCEN’s advisory on BEC informs financial institutions that they have a duty to file a suspicious activity report “regardless of whether the scheme or involved transactions were successful.”
Furthermore, the fact that a recovery request has been made does not release them from that obligation ([4]).
Section 314(b) of the USA PATRIOT Act enables banks to share information with one another, benefiting from a liability safe harbor, regarding transactions which may involve fraud proceeds, such as those connected with wire fraud and “money mule” schemes ([5]).
You should ask the company’s bank in writing to activate both of these channels with the receiving bank and with each subsequent bank as it is identified.
Step three: the forfeiture route
Even after the first account has been emptied, the Department of Justice can trace and seize the stolen money and return it.
In a case in Massachusetts, a workers’ union sent $6.4 million via an email that had been spoofed by only one letter.
The government’s complaint states that the money passed “through a series of intermediary bank accounts,” some of it being routed to a cryptocurrency exchange and to banks in Hong Kong, China, Singapore, and Nigeria.
The investigators were still able to trace the funds to seven domestic accounts, seized them, and brought a civil forfeiture action worth about $5.3 million ([8]).
In a case in Florida, $2,462,000 that had been stolen through an email impersonating a vendor was seized, forfeited, and sent “back to the victim” ([9]).
The process involves remission and restoration as set out in 28 C.F.R. Part 9. A person qualifies as a victim if they have suffered a specific pecuniary loss as a direct result of the crime, and the petition must contain “documentary evidence of a specific pecuniary (i.e., monetary) loss and the date the loss occurred” ([6]).
A petitioner could be disqualified if they have recourse to other reasonably available assets or compensation, so the insurance and counterparty issues discussed below should be dealt with carefully ([6]).
Step four: identify every other pocket
Depending on the facts, a victim may have claims or leverage beyond the thief’s accounts:
- The other party involved. FinCEN recommends that banks record which “compromised or impersonated parties” were involved, note whether auto-forwarding or inbox rules had been set, and indicate whether the authentication compromised was single-factor or multi-factor ([4]). When the vendor’s mailbox has been breached, the question of how to allocate the loss between the two companies is still an open one and will be decided by forensic evidence.
- The holders of the receiving accounts. The attachment statute in New York allows a court, on an appropriate showing, to attach the property of a defendant who is a nondomiciliary or foreign corporation, or one who “has assigned, disposed of, encumbered or secreted property” with the intent to defraud creditors ([14]). Civil proceedings directed at the identified holders of mule accounts can reach funds that have not been seized criminally.
- The company’s own bank. Under Article 4A, the risk of an unauthorized payment order is allocated in accordance with the bank’s security procedure ([13]). Where the customer has authorized the wire, the claim is less extensive, but it still needs to be examined.
- Insurers. Make sure that every policy which could possibly respond to the loss is notified promptly.
- Taxes. The IRS regards money taken “through fraud or misrepresentation” as stolen, and the loss can be deducted in the year the theft is discovered, but not so long as there is “a claim for reimbursement with a reasonable prospect of recovery” ([15]).
Preserve the evidence
The Secret Service states that “any delays will decrease the likelihood of financial recovery” and advises victims to “maintain records of all potential evidence” ([10]).
Victims should not wipe the devices in question. They must export the full email headers and obtain the mailbox audit logs before the retention periods expire.
How Dilendorf Law Firm helps
Dilendorf Law Firm has arbitrated over 130 cases involving cybercrime and represents victims of business email compromise both in the United States and overseas.
If a bank recall fails, we will work with you on filing the IC3 complaint with the details that the Recovery Asset Team requires.
Through our team of retired IC3 expert witnesses, we contact the FBI and the Secret Service on your behalf, both for U.S. and for non-U.S. companies.
Dilendorf Law Firm also works with retired IC3 law enforcement investigators who can help trace funds and determine which network (the company’s internal systems or the counterparty’s network) was breached.
We apply pressure on the banks through the 314(b) and SAR channels and submit remission and restoration petitions whenever funds are seized.
Contact US
At Dilendorf Law Firm, we represent U.S. and non-U.S. companies whose wires have been diverted through business email compromise, from the first IC3 complaint through tracing, bank negotiations, and forfeiture petitions.
Where appropriate, we may pursue claims against counterparties, account holders, and financial institutions.
You can reach us at +1 212 457 9797 or by email at info@dilendorf.com.
This article is for general informational purposes only and does not constitute legal advice. Reading it does not create an attorney-client relationship with Dilendorf Law Firm. Attorney Advertising.
Frequently asked questions
Frequently asked questions
Should the money be considered lost if the receiving bank says the account is empty?
It does not have to be. When a complaint points out “second hop” transactions to other accounts, the FBI’s Recovery Asset Team will carry forward its freeze requests “beyond the initial recipient bank” ([1]).
For example, in a case from 2024, a BEC wire for $6.4 million was traced via intermediary accounts to seven domestic accounts, and the government asked for the forfeiture of about $5.3 million ([8]). The results depend on how quickly action is taken and on how complete the information provided is.
What prevents my bank from simply cancelling the wire?
The law regards an accepted wire as final. After the beneficiary’s bank has accepted the payment order, cancellation will not take effect unless the receiving bank agrees or a rule of the funds-transfer system permits it, with a limited exception in the case of unauthorized or mistaken orders ([11]).
A bank which pays into the account number stated on a wire can generally rely on that number even if the name does not match ([12]). A recall is a request which the receiving bank may choose to carry out if the funds still exist.
Can you still file with IC3 after 48 hours?
Yes. FinCEN is most likely to recover funds reported within 72 hours, meaning that hour 48 falls within that time frame, and neither FinCEN nor the FBI says that reporting later is pointless ([3]).
The FBI urges victims to file a report “regardless of the amount lost” and to include all details about the transactions ([1]). You should file the report immediately and then add further information as the banks provide details about subsequent transfers.
What information should the complaint include?
When a wire is sent overseas, FinCEN requires the name and account number of the victim, the name and home country of the victim’s bank, a summary of the fraud, the name and account number of the beneficiary, the beneficiary’s bank and country, and the amount, date, and currency of the transfer ([3]).
You should also include any details concerning second-hop accounts that your bank has obtained, so that the FBI can ask for downstream freezes ([1]).
What action can banks take that I myself cannot?
Banks are allowed by law to exchange information with one another regarding proceeds suspected to be the result of fraud, thanks to a legal safe harbor. FinCEN’s Section 314(b) guidance covers wire fraud and “money mule” schemes, and it does not require the bank to have previously identified the specific funds that have been laundered ([5]).
Furthermore, banks are required to file suspicious activity reports in the case of BEC whether or not the wire transaction was successful ([4]). Therefore, you should request in writing that your bank make use of both methods.
How can a victim recover their money after the government has seized it?
By means of remission or restoration as provided in 28 C.F.R. Part 9. The U.S. Attorney’s Office informs known victims, who then submit a petition together with “documentary evidence of a specific pecuniary (i.e., monetary) loss and the date the loss occurred” ([6]).
A victim who has “recourse to other reasonably available assets or compensation” may be deemed ineligible ([6]). In the 2023 Florida BEC case, $2,462,000 was forfeited and paid over to the victim ([9]).
Should I take the people whose accounts were credited with the money to court?
It depends on the specific circumstances. People who act as money mules receive the funds obtained through fraud and pass them on to the offenders, and in some cases they know precisely what they are doing ([7]).
Under New York law, it is possible to attach a defendant’s property if the defendant is not a resident of the state or has disposed of or hidden the property with the intention of defrauding creditors ([14]). Whether it is worthwhile to proceed with a civil action depends on who the account holders are and what is left.
May the company write off the loss?
Yes in general, but the timing is important. The IRS considers money obtained “through fraud or misrepresentation” to be stolen and allows the deduction of theft losses in the year that the theft is discovered ([15]).
If there is “a claim for reimbursement with a reasonable prospect of recovery,” the loss is not recognized until there is reasonable certainty that the reimbursement will not be received ([15]). It is necessary to coordinate the recovery effort with the company’s tax advisers.
At what stage should a lawyer become involved?
As soon as the bank reports that the recall has failed. The company then begins to manage a number of parallel initiatives: the IC3 complaint and second-hop tracing, bank-to-bank information sharing, evidence preservation, possible forfeiture petitions, and any potential claims against a counterparty or account holders.
Dilendorf Law Firm takes charge of all of these actions, including coordination with the FBI and the Secret Service whether the company is based in the U.S. or not, retired law enforcement forensics, and assessment of claims against banks and other parties.
Sources
[1] FBI Internet Crime Complaint Center, 2025 Internet Crime Report, pp. 7–9, 17. https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf
[2] FBI IC3, PSA I-091124, “Business Email Compromise: The $55 Billion Scam,” Sept. 11, 2024. https://www.ic3.gov/PSA/2024/PSA240911
[3] FinCEN, Rapid Response Program Fact Sheet, Apr. 15, 2026, pp. 1–2. https://www.fincen.gov/system/files/2026-04/RRPFactSheet.pdf
[4] FinCEN, Advisory FIN-2019-A005, “Updated Advisory on Email Compromise Fraud Schemes,” July 16, 2019, pp. 9–10. https://www.fincen.gov/system/files/advisory/2019-07-16/Updated%20BEC%20Advisory%20FINAL%20508.pdf
[5] FinCEN, Section 314(b) Fact Sheet. https://www.fincen.gov/system/files/shared/314bfactsheet.pdf
[6] U.S. Department of Justice, “Returning Forfeited Assets to Crime Victims,” pp. 2–3, 6. https://www.justice.gov/file/440746/dl
[7] U.S. Department of Justice, Office of Public Affairs, “U.S. Law Enforcement Disrupts Networks Used to Transfer Fraud Proceeds, Taking Over 4,000 Actions,” Feb. 6, 2025. https://www.justice.gov/archives/opa/pr/us-law-enforcement-disrupts-networks-used-transfer-fraud-proceeds-taking-over-4000-actions
[8] U.S. Attorney’s Office, District of Massachusetts, “United States Files Forfeiture Action To Recover Over $5 Million From Business Email Compromise Scheme Targeting Massachusetts Workers Union,” June 5, 2024. https://www.justice.gov/usao-ma/pr/united-states-files-forfeiture-action-recover-over-5-million-business-email-compromise
[9] U.S. Attorney’s Office, Middle District of Florida (published by U.S. Secret Service), “United States Recovers $2.4 Million Obtained In Business Email Compromise,” Oct. 31, 2023. https://www.secretservice.gov/newsroom/releases/2023/10/united-states-recovers-24-million-obtained-business-email-compromise
[10] U.S. Secret Service, “Understanding Business Email Compromise.” https://www.secretservice.gov/investigations/bec
[11] Uniform Commercial Code § 4A-211, Cancellation and Amendment of Payment Order (Cornell LII). https://www.law.cornell.edu/ucc/4A/4A-211
[12] Uniform Commercial Code § 4A-207, Misdescription of Beneficiary (Cornell LII). https://www.law.cornell.edu/ucc/4A/4A-207
[13] Uniform Commercial Code § 4A-202, Authorized and Verified Payment Orders (Cornell LII). https://www.law.cornell.edu/ucc/4A/4A-202
[14] New York Civil Practice Law and Rules § 6201, Grounds for Attachment (New York State Senate). https://www.nysenate.gov/legislation/laws/CVP/6201
[15] Internal Revenue Service, Publication 547 (2025), Casualties, Disasters, and Thefts, pp. 6, 8, 23. https://www.irs.gov/publications/p547
The most authoritative cyber warning of 2026 came on June 22, when the National Security Agency (“NSA”), joined by the cyber security agencies of the United Kingdom, Canada, Australia, and New Zealand, stated:
“Frontier AI models are anticipated to exceed current industry expectations, fundamentally transforming both offensive and defensive cyber capabilities. The timeline is not years, it is months” ([1]). [emphasis added]
The agencies warned that AI is “shrinking the window between vulnerability discovery and exploitation” and state flatly that “Breaches will occur” ([1]).
For wealth managers and family offices holding digital assets, this warning highlights a complex network of risks rather than a single threat.
If you use an exchange, the user agreement typically assigns the risk of loss to you. If you choose self-custody, you are solely responsible for security.
If you use a trust or regulated custodian, their duty to protect your assets depends entirely on the terms of the governing document. Each arrangement should be reviewed carefully.
Exchanges: the loss is contractually yours
The FBI attributed the theft of approximately $1.5 billion from the exchange Bybit in February 2025 to North Korea ([2]).
In 2025 alone, the FBI received 181,565 complaints involving cryptocurrency with $11.366 billion in reported losses, up 22 percent from 2024 ([3]).
When customers report account takeovers, the Consumer Financial Protection Bureau found that companies “often” respond that transfers are irreversible and that “consumers are responsible for the security of their accounts” ([4]).
One platform cited terms stating the customer would not hold it liable for “equipment or software failures or malfunctions … security breaches and unauthorized access” ([4]).
In our experience, platform agreements routinely include clauses that shift losses to the customer if their device is compromised. Review these agreements proactively, before any incident occurs.
Self-custody: you are the security team
Hardware and browser wallets do not eliminate risk; instead, they transfer it to the holder.
A joint FBI, CISA, and Treasury advisory describes North Korean actors targeting “individual holders of large amounts of cryptocurrency” with trojanized applications whose fake “update” function installs malware that steals private keys ([5]).
The Federal Trade Commission is direct: if a wallet “is stolen or compromised,” you are “likely to find that no one can step in to help you recover your funds” ([6]).
AI-generated voice clones and deepfake video calls are already used to walk holders through the steps that drain a wallet ([7]). The NSA expects those tools to improve within months, not years ([1]).
Trusts and custodians: the duty is what the document says
Many families have placed digital assets in U.S. or offshore asset protection trusts with a professional trustee or a regulated custodian. This approach is often sound, but it does not provide automatic protection.
New York Banking Law § 100 gives trust companies fiduciary powers, including the power to “receive, take, manage, hold and dispose of according to the terms of such trust” the property entrusted to them ([8]).
The statute gives these powers; however, it does not contain any express duty to safeguard digital assets against foreseeable account takeovers or cyber attacks.
If that duty is not written into the trust agreement or custody agreement, you should expect the trustee will argue (in case of an account takeover or stolen funds from the trust) that the duty to safeguard does not exist.
The same considerations apply outside New York.
If the asset protection trust is established in South Dakota, Wyoming, or an offshore jurisdiction, do not assume that default rules impose the duties omitted by New York’s statute.
The trust agreement should clearly define the trustee’s responsibilities for safeguarding assets, including cryptocurrency and bank accounts, and specify the consequences of any breach in the age of agentic AI cyberattacks.
Regulators expect more of licensed custodians. DFS guidance issued September 30, 2025, to BitLicensees and limited purpose trust companies requires custodians to hold customer crypto only for custody and safekeeping and to segregate it on-chain and on their ledger.
It also requires trust companies to treat customers’ crypto as belonging solely to customers, and to disclose the customer’s property interest and any material sub-custodian risks ([9]).
These expectations are excellent, but they do not replace the need for enforceable contract terms and insurance.
What to check this month
1. Exchange and platform agreements: locate the loss-allocation, device-compromise, and arbitration clauses ([4]).
2. Trust and custody agreements, in every jurisdiction: confirm an express duty to safeguard digital assets, a defined security standard, and remedies for breach (given NSA’s June 22, 2026 warning concerning agentic AI cybercrime).
3. Trustee and custodian insurance: confirm coverage, limits, and exclusions for cyber theft, and whether your assets are within the covered class.
4. Key control: document who holds keys, who can authorize transfers, and what verification is required ([9]).
5. Incident plan: know that the first report goes to the FBI’s IC3 with wallet addresses, transaction hashes, amounts, and timestamps ([10]).
How Dilendorf Law Firm helps
We have addressed each of the issues described above. Dilendorf Law Firm has arbitrated more than 130 cyber crime cases involving custody disputes and represents clients in all types of crypto compromise cases, including (i) assigning retired law enforcement agents, (ii) tracing stolen assets, (iii) investigating intrusions, and (iv) arbitrating claims against custodians, trust companies, and exchanges. We know the attack vectors used against wallets, exchanges, trustees, and custodians, and the defenses each raises afterward. On the prevention side, working with retired IC3 cybercrime specialists, we design asset protection trusts for cryptocurrency and negotiate custody and trustee agreements that state the duty to safeguard expressly. We also help clients verify a trustee’s insurance limits and plan secure transfers of assets from one wallet or custodian to another, using the services of retired IC3 cybercrime specialists. The NSA has emphasized the urgency of this issue. All trust, bank, and custody agreements should be reviewed promptly.Contact US
At Dilendorf Law Firm, we advise wealth managers, family offices, and individual holders on the custody of digital assets held on exchanges and in self-custody wallets.
We also help clients complete due diligence on onshore and offshore trustees and regulated custodians in New York and other U.S. jurisdictions.
If your crypto has already been compromised, we assign retired law enforcement agents to trace and investigate the theft and arbitrate claims against exchanges, trust companies, and custodians.
Contact us at +1 212 457 9797 or email us at info@dilendorf.com.
This article is for general informational purposes only and does not constitute legal advice. Reading it does not create an attorney-client relationship with Dilendorf Law Firm. Attorney Advertising.
Frequently asked questions
Does my exchange have to reimburse me if my account is hacked?
Usually the exchange will say no. The CFPB found that companies “often” tell consumers that transfers are irreversible and that consumers are responsible for account security, and some cite terms disclaiming liability for “security breaches and unauthorized access” ([4]). Whether that holds depends on the agreement and the platform’s own failures.Is a hardware wallet safer than a regulated custodian?
Neither is safe by default. U.S. agencies report state actors targeting both exchanges and “individual holders of large amounts of cryptocurrency” with malware that steals private keys ([5]). The better question is which model gives you an enforceable duty, insurance, and a recovery path if the attack succeeds.Does a New York trustee automatically owe a duty to protect crypto from hackers?
Not expressly. Banking Law § 100 grants powers to hold and manage property “according to the terms of such trust” and sets no cybersecurity standard ([8]). The duty to safeguard digital assets should be written into the trust or custody agreement, with a defined standard and remedies.What should a settlor check in an existing crypto trust?
Whether the trust is in New York, South Dakota, Wyoming, or offshore, confirm the trustee has an express duty to safeguard digital assets, review the security standard and key-control provisions, and verify that the trustee’s insurance covers cyber theft with limits adequate for the holdings. DFS expects licensed custodians to disclose segregation, the customer’s property interest, and sub-custody risks ([9]); ask your trustee for the same.Is crypto held with a custodian insured like a bank deposit?
No. The FTC states that crypto in accounts “is not insured by a government like U.S. dollars deposited into an FDIC insured bank account,” and that if the storage provider is hacked, “the government has no obligation to step in” ([6]). Any coverage is private and defined by the policy.What should be done in the first hours after a theft?
Report immediately to the FBI’s Internet Crime Complaint Center at ic3.gov or a local FBI field office, providing cryptocurrency addresses, amounts and asset types, dates and times, and transaction hashes ([10]). Preserve devices and messages. Be wary of anyone offering to recover funds for a fee, which the FBI warns may be another scam ([10]).How does Dilendorf Law Firm approach a custody engagement?
We start from the record of more than 130 arbitrated cyber crime custody disputes: what attacks succeeded, and what defenses exchanges, trustees, and custodians raised. For a compromise that has already happened, we assign retired law enforcement agents, trace and investigate, and arbitrate against the custodian, trust company, or exchange. For prevention, we review agreements and insurance, design or restate an asset protection trust with an express duty to safeguard, and plan secure transfers. Outcomes depend on the facts.Sources
[1] National Security Agency, “Five Eyes Cyber Security Agencies Statement,” June 22, 2026. https://www.nsa.gov/Press-Room/News-Highlights/Article/Article/4523810/five-eyes-cyber-security-agencies-statement/
[2] FBI Internet Crime Complaint Center, PSA “North Korea Responsible for $1.5 Billion Bybit Hack,” Feb. 26, 2025. https://www.ic3.gov/psa/2025/psa250226
[3] FBI Internet Crime Complaint Center, “2025 Internet Crime Report,” pp. 7–8, 52. https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf
[4] Consumer Financial Protection Bureau, “Complaint Bulletin: An analysis of consumer complaints related to crypto-assets,” Nov. 2022, pp. 17–18, 20, 42–43. https://files.consumerfinance.gov/f/documents/cfpb_complaint-bulletin_crypto-assets_2022-11.pdf
[5] CISA, FBI, and U.S. Treasury, Joint Cybersecurity Advisory AA22-108A, “TraderTraitor: North Korean State-Sponsored APT Targets Blockchain Companies,” Apr. 18, 2022 (updated Apr. 20, 2022). https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-108a
[6] Federal Trade Commission, “What To Know About Cryptocurrency and Scams.” https://consumer.ftc.gov/articles/what-know-about-cryptocurrency-scams
[7] FBI Internet Crime Complaint Center, PSA “Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud,” Dec. 3, 2024. https://www.ic3.gov/PSA/2024/PSA241203
[8] New York Banking Law § 100, Fiduciary powers (New York State Senate). https://www.nysenate.gov/legislation/laws/BNK/100
[9] New York State Department of Financial Services, Industry Letter, “Updated Guidance on Custodial Structures for Customer Protection in the Event of Insolvency,” Sept. 30, 2025. https://www.dfs.ny.gov/industry-guidance/industry-letters/il20250930-updated-guidance-custodial-structures
[10] FBI Internet Crime Complaint Center, PSA “FBI Guidance for Cryptocurrency Scam Victims,” Aug. 24, 2023. https://www.ic3.gov/PSA/2023/psa230824
More and more clients prefer to use funds from crypto trading, mining, or DeFI transactions to support EB-5 petitions.
Federal courts and agencies recognize crypto as both funds and property, allowing its use in EB-5 applications.
The main challenge is evidentiary: U.S. Citizenship and Immigration Services (“USCIS”) requires detailed proof for each transaction that the capital was lawfully earned and transferred.
This article explains the legal requirements, examines why crypto-funded petitions often receive Requests for Evidence (RFEs), and offers limited guidance for crypto EB-5 filings.
Crypto is “funds” under federal law
Federal appellate courts have on more than one occasion dismissed the notion that bitcoin does not come within the normal meaning of the term “funds.”
In 2026 the Second Circuit stated that “bitcoin qualifies as ‘funds’” since it “can be and is used as a currency to make sales and purchases,” referencing the First Circuit’s 2025 decision in United States v. Freeman ([1]).
That case itself drew upon earlier judgments, such as United States v. Murgio, 209 F. Supp. 3d 698 (S.D.N.Y. 2016), in which it was concluded that bitcoins are funds ([2]).
Furthermore, FinCEN described convertible virtual currency as a medium of exchange that “either has an equivalent value in real currency, or acts as a substitute for real currency.”
As such, FinCen considers individiduals who exchange virtual currency as money transmitters who have to be registered and who must keep records ([3]).
The Internal Revenue Service (“IRS”) considers digital assets, such as crypto, stablecoins, and NFTs, to be property. The IRS requires taxpayers to report all sales, exchanges, or dispositions even if no taxable gain results ([4]).
What the EB-5 statute requires
The definition of “capital” given in the Immigration and Nationality Act is wide-ranging but excludes “assets directly or indirectly acquired by unlawful means” ([5]).
Under the EB-5 Reform and Integrity Act of 2022, paragraph (L) of section 203(b)(5) of the INA require that the petitioner prove the capital arose from a lawful source and was acquired by lawful means.
This means that the petitioner must provide as evidence business registration records, tax returns filed, and any records of judgments.
The law also requires the identification of each person who transfers funds into the U.S. on the investor’s behalf, and gifts and loans are allowed only if they are made in good faith (not with the intention of avoiding the source-of-funds rules). ([5]).
These regulations state that assets acquired by unlawful means “shall not be considered capital” and provides the documentary evidence to the USCIS([6]).
The USCIS Policy Manual tells officers to verify that the investor is the legal owner of the capital and that it was acquired in a legal manner.
The Policy also includes separate lists of evidence for petitions submitted before and after May 14, 2022 ([7]).
The path-of-funds rule from the precedent decisions
The decisions of the Associate Commissioner from 1998 are still being used by USCIS when assessing the source of funds.
USCIS’s requests for additional information relating to crypto follow these established precedents.
- In Matter of Izummi, the petition was denied since “the record does not reveal from where these funds originated,” and the petitioner had “not documented the path of the funds, such as by wire-transfer records” ([8]).
- In Matter of Ho, the bank statements and letters were not adequate since “the wire-transfer receipt does not reveal from what bank account(s) the funds originated,” and the agency again stated that “simply going on record without supporting documentary evidence is not sufficient” ([9]).
- In Matter of Soffici, the funds held in the joint account could not be assigned to one particular investor, and the corporate funds were not those of the petitioner ([10]).
- The decisions are based upon Matter of Treasure Craft of California and Matter of Brantigan, which require the petitioner to carry the burden of proof in visa petition proceedings ([11], [12]).
For crypto, the “path of funds” requires tracing each coin or token from acquisition, through all wallets and exchanges, to the fiat wire that funded the investment.
Why crypto petitions draw RFEs
Deficiencies USCIS has raised in crypto-funded cases commonly include:
1. Transaction hashes and wallet addresses provided only as links or screenshots and not as printed and certified records.
2. No evidence to show that the petitioner has control over the wallets from which the proceeds were generated.
3. Exchange account statements that show a fiat withdrawal but do not include the crypto sales that caused it.
4. No evidence that income tax was reported and paid on each disposal, even though the IRS requires taxpayers to maintain “records documenting receipts, sales, exchanges, or other dispositions of virtual currency and the fair market value” ([13]).
5. Trades carried out on a decentralized exchange or in a peer-to-peer manner where there are no KYC/AML records.
6. Crypto funds mixed with other money, which may require the petitioner to show the legitimate source of every dollar.
USCIS now uses a machine-learning tool to classify and tag scanned evidence.
This enabled adjudicators to quickly access relevant information ([14]).
The DHS Inspector General confirms that USCIS uses AI to “expedite the processing and review of immigration and naturalization documents” ([15]).
Petitioners should expect every page of their financial history to be reviewed using AI.
The standard of proof
The petitioner must meet the preponderance of the evidence standard.
In Matter of Chawathe, the AAO held that a petitioner satisfies this burden when the claim is “probably true,” and officers must assess each document for relevance, probative value, and credibility ([16]).
USCIS EB-5 guidance confirms that a petitioner “does not need to remove all doubt” ([7]).
However, crypto RFEs often demand more extensive proof, so it is important to anticipate a wide-range of questions.
What is at stake if the petition fails
A response to an RFE must be submitted within the deadline that USCIS establishes, which may not exceed 12 weeks; and the petition can be denied as abandoned or on the basis of the existing record if no response is received ([17]).
Investors who are already in the United States can file Form I-485 at the same time as Form I-526E if a visa is immediately available ([18]).
However, the adjustment application is conditional upon the petition being approvable, and there is usually no appeal against a denial of the adjustment application ([19], [20]).
According to 2025 USCIS policy, the agency will serve a Notice to Appear when, after an adverse decision, the applicant is not lawfully present ([21]).
Consular processing is not always an available option: starting on January 21, 2026, the State Department suspended the issuance of immigrant visas to nationals of 75 listed countries ([22]).
Planning a crypto-funded EB-5 petition
1. Before filing, make sure to reconstruct the entire history, including the dates of the acquisitions, the cost basis, the wallet addresses, the exchange accounts, all the transfers. etc.
2. Print out the blockchain records and the exchange statements in the form of PDF files, label them, and associate each transaction hash with a specific line item in the tracing schedule.
3. Establish ownership of the wallet using the exchange’s KYC records, signed messages, or forensic attestations.
4. Make sure that the tax returns are accurate, fix any omissions before USCIS finds them, using AI.
5. Engage a separate forensic examiner, preferably one who has previously been a law enforcement investigator. Max Dilendorf regularly works with such expert witness to support client’s crypto EB-5 petitions.
6. Place the investment funds in a separate account so that there is no possibility of them being mixed up.
Prevention checklist
- Hold on to your tax returns for seven years and verify that each one shows activity involving digital assets.
- Keep the statements from your exchange account and your KYC confirmations.
- Make sure that gifts and loans are accompanied by evidence from the donor or lender regarding the source of the funds.
- List all the intermediaries who transferred money into the United States.
- Do not submit any links or media files that USCIS will not be able to open.
How Dilendorf Law Firm helps
Max Dilendorf has been at the forefront of digital asset and crypto law since 2017. Max represents clients in EB-5 petitions involving cryptocurrency.
Additionally, Max handled over 130 cybercrime cases related to digital asset theft and complex forensic investigations with retired law enforcement agents, providing the experience needed for complex crypto-funded EB-5 matters.
Contact US
At Dilendorf Law Firm, we assist U.S. and international investors with EB-5 petitions funded through cryptocurrency, digital assets, and other non-traditional sources of wealth.
Our team helps clients establish a lawful source and path of funds, prepare responses to USCIS Requests for Evidence (RFEs), document cryptocurrency transactions, and coordinate forensic tracing of digital asset transfers.
If you are considering an EB-5 investment using proceeds from crypto trading, mining, staking, DeFi, NFTs, or other digital assets, we can help.
Contact us at +1 212 457 9797 or email us at info@dilendorf.com.
This article is for general informational purposes only and does not constitute legal advice. Reading it does not create an attorney-client relationship with Dilendorf Law Firm. Attorney Advertising.
Frequently asked questions
Can cryptocurrency be used as the investment capital for an EB-5 petition?
Yes. The Immigration and Nationality Act defines “capital” broadly and excludes only assets acquired by unlawful means ([5]). Federal appellate courts have held that bitcoin qualifies as “funds” ([1], [2]), and the IRS treats digital assets as property ([4]).
The obstacle is not eligibility but evidence. USCIS must be able to confirm that the investor lawfully owned the crypto, lawfully acquired it, and can trace it into the new commercial enterprise ([7]).
What does the “path of funds” requirement mean when the capital started as crypto?
USCIS applies the 1998 precedent decisions in Matter of Izummi and Matter of Ho, which denied petitions because the record did not show where the funds originated or how they moved ([8], [9]).
For crypto, that means documenting each step: the original acquisition (fiat purchase, mining, staking, or trading), every wallet and exchange the assets passed through, the sale or conversion to fiat, and the wire into the escrow or project account. A tracing schedule that ties each transaction hash and exchange record to a specific dollar amount is the practical way to satisfy this rule.
What documents does USCIS expect to see for crypto-derived funds?
The statute itself lists business registration records, tax returns, and records of any judgments, and requires identification of every person who transferred funds on the investor’s behalf ([5]). The USCIS Policy Manual sets out separate evidence lists for petitions filed before and after May 14, 2022 ([7]).
For crypto specifically, a complete record typically includes: exchange account statements and KYC confirmations; blockchain transaction records printed to PDF and labeled by transaction hash; evidence of wallet ownership (KYC records, signed messages, or a forensic attestation); tax returns reflecting each disposition; bank records showing the fiat proceeds; and a tracing schedule that links every document to a line item. Links and screenshots alone are a common cause of RFEs.
Can I use crypto that was gifted or lent to me?
Yes, but only if the gift or loan was made in good faith and not to circumvent the source-of-funds rules ([5]). The donor or lender must document the lawful source of their own crypto to the same standard the investor would face, including acquisition history, exchange records, and tax treatment.
The petition should also identify every intermediary who moved the assets or the resulting fiat into the United States, and the transfer itself should be documented on-chain and in the receiving exchange or bank records.
Do proceeds from mining, staking, DeFi, or peer-to-peer trading qualify?
They can, but these sources draw closer scrutiny because they often lack the KYC/AML records that centralized exchanges generate. USCIS has flagged decentralized or peer-to-peer trades as a recurring deficiency in crypto-funded petitions.
Investors relying on these sources should be prepared to prove control of the relevant wallets, produce on-chain records for each reward, trade, or liquidity event, and show that the income was reported for tax purposes. Where crypto proceeds were mixed with other money, USCIS may require the lawful source of every dollar in the commingled account to be documented.
Do I have to prove that taxes were paid on my crypto gains?
Tax compliance is part of the lawful-source analysis. The IRS treats digital assets as property and requires taxpayers to report all sales, exchanges, and dispositions, and to keep records documenting each transaction and its fair market value ([4], [13]).
The absence of tax reporting on the disposals that generated the investment capital is one of the most common issues raised in crypto RFEs. Returns should be reviewed against the tracing schedule before filing, and any omissions addressed with tax counsel before USCIS identifies them.
What happens if USCIS issues an RFE or denies the petition?
An RFE must be answered within the deadline USCIS sets, which cannot exceed 12 weeks; a petition may be denied as abandoned or on the existing record if no response is filed ([17]). The petitioner must establish eligibility by a preponderance of the evidence, meaning the claim is “probably true” ([16]).
The stakes are highest for investors who filed Form I-485 concurrently. If the I-526E is denied, the adjustment application generally fails with it, there is usually no appeal from the adjustment denial, and USCIS policy provides for issuance of a Notice to Appear when the applicant is no longer lawfully present ([19], [20], [21]). Consular processing may not be available as a fallback for nationals of the 75 countries subject to the State Department’s immigrant visa suspension ([22]).
Sources
[1] United States v. Goklu, No. 24-767 (2d Cir. Apr. 7, 2026), slip op. at 12. https://ww3.ca2.uscourts.gov/decisions/OPN/24-767_opn.pdf
[2] United States v. Freeman, No. 23-1839 (1st Cir. July 29, 2025), slip op. at 17–18 (citing United States v. Murgio, 209 F. Supp. 3d 698 (S.D.N.Y. 2016)). https://www.ca1.uscourts.gov/sites/ca1/files/opnfiles/23-1839P-01A.pdf
[3] FinCEN, FIN-2013-G001, Application of FinCEN’s Regulations to Persons Administering, Exchanging, or Using Virtual Currencies (Mar. 18, 2013), pp. 1–3. https://www.fincen.gov/system/files/shared/FIN-2013-G001.pdf
[4] IRS, Digital Assets (definition; property treatment; reporting of dispositions). https://www.irs.gov/businesses/small-businesses-self-employed/digital-assets
[5] INA § 203(b)(5)(D)(ii), (E)(i), (L), 8 U.S.C. § 1153(b)(5), as compiled by GovInfo (COMPS-1376), pp. 58–60, 78–79. https://www.govinfo.gov/content/pkg/COMPS-1376/pdf/COMPS-1376.pdf
[6] 8 C.F.R. § 204.6(e), (j)(3) (2025). https://www.govinfo.gov/link/cfr/8/204?link-type=pdf§ionnum=6&year=mostrecent
[7] USCIS Policy Manual, Vol. 6, Part G, Ch. 2 (Eligibility Requirements), § A.4 Lawful Source of Funds and standard-of-proof discussion. https://www.uscis.gov/policy-manual/volume-6-part-g-chapter-2
[8] Matter of Izummi, 22 I&N Dec. 169, 194–95 (Assoc. Comm. 1998). https://www.justice.gov/sites/default/files/eoir/legacy/2014/07/25/3360.pdf
[9] Matter of Ho, 22 I&N Dec. 206, 210–11 (Assoc. Comm. 1998). https://www.justice.gov/sites/default/files/eoir/legacy/2014/07/25/3362.pdf
[10] Matter of Soffici, 22 I&N Dec. 158, 164, 168 (Assoc. Comm. 1998). https://www.justice.gov/sites/default/files/eoir/legacy/2014/07/25/3359.pdf
[11] Matter of Treasure Craft of California, 14 I&N Dec. 190 (Reg. Comm. 1972). https://www.justice.gov/sites/default/files/eoir/legacy/2012/08/17/2163.pdf
[12] Matter of Brantigan, 11 I&N Dec. 493 (BIA 1966). https://www.justice.gov/sites/default/files/eoir/legacy/2012/08/27/1553.pdf
[13] IRS, Frequently Asked Questions on Virtual Currency Transactions, Q1, Q4, Q16, Q46. https://www.irs.gov/individuals/international-taxpayers/frequently-asked-questions-on-virtual-currency-transactions
[14] DHS, 2024 DHS AI Use Case Inventory (July 2025 revision), use case DHS-16, “ELIS Evidence Classifier Machine Learning (ML) Tagging Solution” (USCIS; Operation and Maintenance). https://www.dhs.gov/sites/default/files/2025-06/25_07_01_ocio_2024-dhs-ai-use-case-inventory_July_Revision.xlsx
[15] DHS Office of Inspector General, OIG-25-10, DHS Has Taken Steps to Develop and Govern Artificial Intelligence, But More Action is Needed to Ensure Appropriate Use (Jan. 30, 2025), p. 2, Table 1. https://www.oig.dhs.gov/sites/default/files/assets/2025-02/OIG-25-10-Jan25.pdf
[16] Matter of Chawathe, 25 I&N Dec. 369, 375–76 (AAO 2010). https://www.justice.gov/sites/default/files/eoir/legacy/2014/07/25/3700.pdf
[17] 8 C.F.R. § 103.2(b)(1), (b)(8)(iv), (b)(13)(i) (2025). https://www.govinfo.gov/content/pkg/CFR-2025-title8-vol1/pdf/CFR-2025-title8-vol1-sec103-2.pdf
[18] USCIS, EB-5 Immigrant Investor Process (Form I-526E; concurrent Form I-485 filing; conditional residence). https://www.uscis.gov/working-in-the-united-states/permanent-workers/employment-based-immigration-fifth-preference-eb-5/eb-5-immigrant-investor-process
[19] 8 C.F.R. § 245.2(a)(2)(i), (a)(5)(ii) (2025). https://www.govinfo.gov/content/pkg/CFR-2025-title8-vol1/pdf/CFR-2025-title8-vol1-part245.pdf
[20] USCIS Policy Manual, Vol. 7, Part A, Ch. 11 (Decision Procedures) (no appeal from denial of adjustment; motion or renewal in removal proceedings). https://www.uscis.gov/policy-manual/volume-7-part-a-chapter-11
[21] USCIS Policy Memorandum PM-602-0187, Issuance of Notices to Appear (NTAs) in Cases Involving Inadmissible and Deportable Aliens (Feb. 28, 2025), § VI. https://www.uscis.gov/sites/default/files/document/policy-alerts/NTA_Policy_FINAL_2.28.25_FINAL.pdf
[22] U.S. Department of State, Immigrant Visa Processing Updates for Nationalities at High Risk of Public Benefits Usage (updated Feb. 2, 2026). https://travel.state.gov/content/travel/en/News/visas-news/immigrant-visa-processing-updates-for-nationalities-at-high-risk-of-public-benefits-usage.html
The first question clients often ask when cybercriminals get into a company’s online banking system and transfer money from the account is whether or not the bank should be held responsible for the loss.
The answer is almost never simple since account agreements, the Uniform Commercial Code (“UCC”), and mandatory arbitration clauses are generally drafted in such a way as to protect the bank against all liability.
However, the bank does not automatically prevail in all account takeover (“ATO”) cases cases and recovery in many instances turns on what the bank knew, what its systems picked up, and whether it followed its own security procedures.
The Scale of the Problem
Cyber-enabled financial fraud is still increasing at an alarming rate.
In 2025 the FBI’s Internet Crime Complaint Center (“IC3”) received over one million complaints and the amount of money lost was more than $20.8 billion, which represents a 26 percent rise on the figure from the previous year ([1]).
In 2025, business email compromise (“BEC”), which is often the first step leading to account takeover fraud, resulted in 24,768 complaints and reported losses exceeding $3 billion ([2]).
For a great many businesses, one fraudulent transfer can put their operations, their payroll, or the continued existence of the company at risk.
Why the Law Starts Out Favoring the Bank
The idea is that many business owners think they are entitled to the same level of protection as consumers, but they aren’t.
Regulation E provides protection to individual consumers who use personal banking accounts; it usually does not cover commercial accounts held by corporations, partnerships, or other business entities ([3]).
Commercial wire transfers are mainly regulated by Article 4A of the Uniform Commercial Code and by the agreements between the bank and its customer; these agreements are generally drafted in such a way as to assign risk of loss to the to the business.
User Agreements usually state that the customer must protect the credentials, have control over access to the account, and comply with the agreed security procedures.
Accordingly, the bank’s first response is usually simple in that the transaction has been verified with valid credentials and must therefore be viewed as authorized.
The Key Legal Standard
The section of the law that most banks depend on is UCC § 4A-202 ([4]).
A payment order may be analyzed as the customer’s order under that statute even if it had not been authorized, on the condition that (i) the bank’s security procedure was commercially reasonable and (ii) the bank accepted the payment order in good faith and in accordance with that procedure ([5]).
It is important that the bank should have to prove both of these elements.
Commercial reasonableness cannot be judged in a general or abstract way; instead, the analysis takes into account the customer’s circumstances, such as the character of its business, its usual patterns of transaction, the security features available from the bank, and the practices generally followed by similar institutions and customers ([6]).
Even though the statute presents commercial reasonableness as a legal issue, it is generally determined by referring to technical evidence, transaction records, and expert testimony.
If the payment order has not been authorized and fails to meet the requirements of § 4A-202, the bank is generally obliged to return the money together with interest, and this duty cannot be waived by contract ([7]).
Where These Cases Are Won or Lost
The most important evidence is usually obtained from the bank’s own systems.
The federal banking regulators made it clear that financial institutions should use multiple layers of security controls rather than depending just on passwords or single-factor authentication; the regulatory guidance also stresses the importance of fraud detection, monitoring for anomalies, analyzing transactions, and examining unusual customer behavior ([8]).
Modern attacks often manage to get around passwords and even conventional multi-factor authentication.
The Cybersecurity and Infrastructure Security Agency (“CISA”) cautioned that attackers regularly steal usernames, passwords, and one-time authentication codes by means of phishing and social-engineering attacks ([9]).
A claim brought against a bank usually centers on whether the bank noticed the warning signs and did not take action. For example:
- Logins from locations that are unfamiliar or from IP addresses in foreign countries.
- Access from a device that has never been used on this account before.
- Unexpected changes to contact details.
- The size of the transfers is not in agreement with past activity.
- The addition of new beneficiaries right before the transfer took place.
- The bank’s systems have generated internal fraud alerts.
- Calls that were required to be verified had never been made.
The main issue is typically whether the bank carried out procedures which were commercially reasonable and whether it acted in good faith after it had received signs that something was wrong.
Arbitration Is Usually Required
Mandatory arbitration clauses can be found in the majority of business banking agreements.
Arbitration agreements are usually enforceable under the Federal Arbitration Act; it is for this reason that a large number of business account takeover claims are resolved before organizations such as the American Arbitration Association (“AAA”) or JAMS rather than going to court ([10]).
Arbitration does pose some difficulties since discovery is generally more limited than in the case of traditional litigation.
That said, businesses are still able to get important evidence such as authentication logs, fraud alerts, the results of internal investigations, and documentation relating to security procedures.
With proper preparation and expert analysis, these cases can be successfully pursued.
What To Do Immediately
When it is found that an account has been taken over, time is of the essence.
Start by getting in touch with the bank and asking for the transfer to be recalled or reversed immediately ([11]).
Have the bank speak directly to the institution where the money was received and begin all the possible recovery procedures.
Second, submit a complaint to the FBI’s IC3. The FBI states that its Recovery Asset Team froze about $679 million in fraudulent transfers in 2025, which corresponds to a 58 percent success rate for attempted recovery actions ([12]).
Also, make sure all the evidence is preserved, such as emails, text messages, authentication records, call logs, and the affected devices.
Fourth, send the bank a written notice and ask it to keep all the logs, alerts, and records related to the incident.
Finally, take the time to carefully go through the account agreement and keep record of all the contractual and statutory notice deadlines.
How Dilendorf Law Firm Helps
The Dilendorf Law Firm deals with cases involving account takeovers and cyber-fraud for businesses.
We help our clients with filing reports under IC3, carrying out recovery operations, conducting forensic investigations, preserving evidence, and making claims against financial institutions.
If needed, we initiate arbitration proceedings and collaborate with experienced cybercrime investigators and expert witnesses in order to examine bank security procedures, transaction records, and fraud-detection systems.
Contact Us
At Dilendorf Law Firm, we represent businesses affected by cyber fraud, including business email compromise (BEC), online banking account takeovers, and fraudulent wire transfers.
Our attorneys assist clients with emergency fund recovery efforts, IC3 reporting, forensic investigations, preservation of digital evidence, and claims against financial institutions.
We regularly represent companies in disputes involving unauthorized wire transfers, account takeovers, and bank liability under the Uniform Commercial Code.
If your business has suffered a fraudulent wire transfer or online banking compromise, prompt action is critical. Contact us at +1 212 457 9797 or email us at info@dilendorf.com.
This article is for general informational purposes only and does not constitute legal advice. Reading it does not create an attorney-client relationship with Dilendorf Law Firm. Attorney Advertising.
Sources
[1] FBI Internet Crime Complaint Center, 2025 Internet Crime Report, p. 6 (total complaints, losses, and year-over-year increase). https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf
[2] FBI IC3, 2025 Internet Crime Report, pp. 7–8, 25–26 (business email compromise complaints and losses). https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf
[3] Consumer Financial Protection Bureau, Regulation E, 12 CFR § 1005.2(b)(1), (e) (definitions of “account” and “consumer”). https://www.consumerfinance.gov/rules-policy/regulations/1005/2
[4] Uniform Commercial Code § 4A-202, Authorized and Verified Payment Orders (Legal Information Institute, Cornell Law School). https://www.law.cornell.edu/ucc/4A/4A-202
[5] Uniform Commercial Code § 4A-202(b) (payment order effective as the customer’s order if security procedure commercially reasonable and bank acted in good faith and in compliance with it). https://www.law.cornell.edu/ucc/4A/4A-202
[6] Uniform Commercial Code § 4A-202(c) (factors for commercial reasonableness). https://www.law.cornell.edu/ucc/4A/4A-202
[7] Uniform Commercial Code § 4A-204(a)–(b), Refund of Payment and Duty of Customer to Report (Legal Information Institute, Cornell Law School). https://www.law.cornell.edu/ucc/4A/4A-204
[8] Federal Financial Institutions Examination Council, Authentication and Access to Financial Institution Services and Systems, Interagency Guidance, Aug. 11, 2021, §§ 4–6 and Appendix (as published by the Federal Reserve Board). https://www.federalreserve.gov/frrs/guidance/authentication-and-access-to-financial-institution-services-and-systems-interagency-guidance.htm
[9] Cybersecurity and Infrastructure Security Agency, Phishing Resistant MFA is Key to Peace of Mind, Apr. 12, 2023. https://www.cisa.gov/news-events/news/phishing-resistant-mfa-key-peace-mind
[10] 9 U.S.C. § 2, Validity, irrevocability, and enforcement of agreements to arbitrate (Legal Information Institute, Cornell Law School). https://www.law.cornell.edu/uscode/text/9/2
[11] FBI Internet Crime Complaint Center, Business Email Compromise (What To Do In Case Of A BEC Incident). https://www.ic3.gov/CrimeInfo/BEC
[12] FBI IC3, 2025 Internet Crime Report, p. 17 (Recovery Asset Team / Financial Fraud Kill Chain). https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf
If your crypto was stolen, you are dealing with the fastest-growing loss category that the FBI tracks.
This article explains (i) what the FBI’s 2024 and 2025 numbers show; (ii) how the 4 most common thefts work; (iv) what recovery realistically looks like given individual facts/circumstances of your case; and (iv) when a crypto fraud lawyer should be involved.
What the FBI’s 2024 and 2025 numbers show
Crypto losses have been exploding.
In 2024, the FBI’s Internet Crime Complaint Center (IC3) received 149,686 complaints referencing cryptocurrency with $9.3 billion in losses, a 66 percent increase in losses over 2023 ([2]).
In 2025, crypto complaints rose to 181,565 and losses to $11.366 billion, up 21 percent and 22 percent respectively(with 18,589 complainants each losing more than $100,000) ([1]).
| Year | Complaints involving cryptocurrency | Reported losses | Cryptocurrency investment fraud losses |
|---|---|---|---|
| 2024 | 149,686 | $9.3 billion | $5.8 billion (41,557 complaints) |
| 2025 | 181,565 | $11.366 billion | $7.228 billion (61,559 complaints) |
Source: FBI IC3, 2024 Internet Crime Report, pp. 35–36; 2025 Internet Crime Report, pp. 52–53.
Crypto investment fraud was “the highest source of financial losses to Americans in 2025 with $7.2 billion reported in losses” ([1]).
In both years, people aged 60+ reported the largest sharre of cryptocurrency losses ([1], [2]).
How crypto is stolen: four patterns
Exchange thefts. FBI assigned theft of apprx. $1.5 billion in crypto from the exchange Bybit on or about February 21, 2025, to North Korea.
Stolen assets were “dispersed across thousands of addresses on multiple blockchains” within days ([3]).
Bridge exploits. FBI confirmed that the Lazarus Group was responsible for the $100 million theft from Harmony’s Horizon bridge in June 2022 ([4]). The FBI has also described criminals “exploiting a signature verification vulnerability” in a token bridge, causing approximately $320 million in losses ([5]).
SIM-swap attacks. FBI describes SIM swapping as a technique in which criminals “target mobile carriers to gain access to victims’ bank accounts, virtual currency accounts, and other sensitive information,” through social engineering, insider payoffs, or phishing ([6]). In 2021 alone, IC3 received 1,611 SIM-swap complaints with adjusted losses of more than $68 million ([6]).
Since November 2023, Federal Communications Commission (“FCC”) rules require wireless providers to use secure methods of authenticating a customer before moving a number to a new device or carrier.
Furthertemore under the FCC rules, a carrier has to notify customers immediately of any SIM change or port-out request ([7]). Whether a carrier met those obligations is often the central question in a SIM-swap case.
Pig butchering. The Financial Crimes Enforcement Network (“FinCEN”) describes these schemes as long-term confidence scams in which victims are enticed to invest in fake platforms, shown fake profits, and then told to pay “purported taxes or early withdrawal fees” before the scammer disappears with everything ([8]). IC3 Unit reported that these scams are “largely perpetrated by organized criminal enterprises based in Southeast Asia” ([1]).
What recovery could looks like
Speed matter in crypto theft cases. The FBI’s Recovery Asset Team initiated 3,900 Financial Fraud Kill Chain incidents in 2025. Furthermore, the IC3 report shows that FBI helped freezing $679 million of the $1.16 billion in attempted theft (58% success rate) ([1]).
The FBI asks victims to file at ic3.gov “regardless of the amount lost” and to “include the full transaction details.” Because IC3 may be able to assist financial institutions and law enforcement in freezing funds ([1]). In the Harmony case, a portion of the stolen funds was frozen “in coordination with some of the virtual asset service providers” ([4]).
FBI is equally clear about the limits. Exchanges “only freeze accounts based on internal processes or in response to legal process,” private recovery companies “cannot issue seizure orders,” and victims “can also choose to pursue civil litigation to seek recovery of their funds” ([9]).
Beware recovery scams
Victims are targeted a second time. FBI warns that fraudulent recovery services “charge an up-front fee and either cease communication with the victim after receiving an initial deposit or produce an incomplete or inaccurate tracing report,” and that “Law enforcement does not charge victims a fee for investigating crimes” ([9]).
In August 2025, the FBI updated its warning about fictitious law firms that impersonate real lawyers.([10]). Verify any lawyer independently before sending documents or money.
When to involve a crypto fraud lawyer
Involve counsel as soon as the theft is discovered.
From that point, several things are happening at once: (i) IC3 complaint with complete transaction data; (ii) freeze requests to exchanges and banks; (iii) all evidence should be preserved; and (iv) case evaluation of claims against parties involved.
Depending on the facts/circumstances, those parties could include (i) crypto exchange (e.g., Coinbase, Crypto.com, Kraken, etc.) under its user agreement; (ii) wireless carrier; (iv) a bridge or protocol operator; (iv) the counterparty whose systems were compromised; or (v) stablecoin issuers (e.g., Circle or Tether) in cases where it’s appropriate to contact them to freeze stolen stablecoins and issue new ones to the victims through the court order.
Each claim has its own forum, deadlines, and proof requirements. None of the claims should be assumed to be available without full legal review.
How Dilendorf Law Firm helps
Max Dilendorf has practiced cryptocurrency and digital asset law since 2017 and is crypto native: he understands wallets, exchanges, bridges, and on-chain tracing from the inside, not from a textbook.
Dilendorf Law Firm has handled more than 130 complex cybercrime matters involving stolen crypto, including theft from exchanges, SIM-swap attacks, crypto bridge exploits, and pig-butchering schemes.
The firm works with a team of retired law enforcement expert witnesses, including retired FBI IC3 specialists, to trace stolen assets, investigate intrusions, and coordinate IC3, FBI, and Secret Service reporting for U.S. and non-U.S. clients.
Max and his team also represent crypto and AI founders on complex asset protection projects for cryptocurrency and against AI-enabled cyber risks, so they see both sides: how assets are protected before an attack and how they are pursued after one.
Whatever the crypto fraud issue, Max and his team can help with the most challenging cases.
Contact US
If your crypto has been stolen, contact Dilendorf Law Firm through our contact page, call +1 212 457 9797, or email info@dilendorf.com.
This article is for general informational purposes only and does not constitute legal advice. Reading it does not create an attorney-client relationship with Dilendorf Law Firm. Attorney Advertising.
Frequently asked questions
How much crypto was stolen in 2025 according to the FBI?
IC3 recorded 181,565 complaints involving cryptocurrency and $11.366 billion in losses in 2025, a 22 percent increase in losses over 2024 ([1]). Cryptocurrency investment fraud alone accounted for $7.228 billion across 61,559 complaints ([1]). In 2024 the figures were 149,686 complaints and $9.3 billion ([2]).
Can stolen cryptocurrency be recovered?
Sometimes, and the odds improve with speed and complete information. The FBI’s Recovery Asset Team helped freeze $679 million of $1.16 billion in attempted fraudulent transfers in 2025 ([1]). Exchanges freeze accounts only through internal processes or legal process, and civil litigation is a separate route the FBI itself identifies ([9]). No lawyer or company can guarantee recovery.
What should I do first if my crypto was stolen from an exchange?
Contact the exchange immediately, preserve every record, and file an IC3 complaint with the full transaction details, including wallet addresses, transaction hashes, amounts, and timestamps ([1]). The FBI asks that complaints be filed “regardless of the amount lost” ([1]). Then have counsel review the exchange’s user agreement for your remedies.
What should I do after a SIM-swap attack?
The FBI’s steps are to contact your carrier immediately to regain your number, change passwords on your online accounts, alert your financial institutions to suspicious logins or transactions, and report to your local FBI field office and ic3.gov ([6]). FCC rules adopted in November 2023 require carriers to authenticate customers securely before a SIM change and to notify them immediately of any request ([7]).
Is a crypto bridge exploit a crime I can report?
Yes. The FBI encourages investors who suspect their DeFi investments were stolen to report through IC3 or a local field office ([5]). The FBI has attributed major bridge thefts, including the $100 million Harmony Horizon bridge theft, to the North Korean Lazarus Group, and some funds were frozen with the cooperation of virtual asset service providers ([4]).
How do I know if I was a victim of pig butchering?
FinCEN describes the pattern: unsolicited contact, a relationship built over time, an invitation to invest through a platform the scammer controls, fake profits, and then demands for “purported taxes or early withdrawal fees” before the scammer cuts off contact ([8]). The FBI reports these schemes are run largely by organized criminal enterprises in Southeast Asia ([1]).
How can I tell a real crypto fraud lawyer from a recovery scam?
The FBI’s red flags include up-front fees for “tracing,” promises to recover funds, claimed affiliation with law enforcement, impersonation of real lawyers, and fictitious documents on a legitimate firm’s letterhead ([9], [10]). Law enforcement never charges victims a fee ([9]). Verify a lawyer’s identity and bar admission independently before sharing anything.
Why hire a lawyer who has practiced crypto law since 2017?
Crypto theft cases turn on technical facts: how a wallet was drained, how a bridge was exploited, how a carrier authenticated a SIM change, or how funds moved across chains. Max Dilendorf has practiced cryptocurrency and digital asset law since 2017, and Dilendorf Law Firm has handled more than 130 complex cybercrime matters involving stolen crypto with a team of retired law enforcement expert witnesses, including retired FBI IC3 specialists.
Sources
[1] FBI Internet Crime Complaint Center, 2025 Internet Crime Report, pp. 6, 8, 11, 17, 52–53. https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf
[2] FBI Internet Crime Complaint Center, 2024 Internet Crime Report, pp. 4, 35–36. https://www.ic3.gov/AnnualReport/Reports/2024_IC3Report.pdf
[3] FBI IC3, Public Service Announcement, “North Korea Responsible for $1.5 Billion Bybit Hack,” Feb. 26, 2025. https://www.ic3.gov/psa/2025/psa250226
[4] FBI, Press Release, “FBI Confirms Lazarus Group Cyber Actors Responsible for Harmony’s Horizon Bridge Currency Theft,” Jan. 23, 2023 (updated Feb. 6, 2023). https://www.fbi.gov/news/press-releases/fbi-confirms-lazarus-group-cyber-actors-responsible-for-harmonys-horizon-bridge-currency-theft
[5] FBI IC3, Public Service Announcement, “Cyber Criminals Increasingly Exploit Vulnerabilities in Decentralized Finance Platforms to Obtain Cryptocurrency, Causing Investors to Lose Money,” Aug. 29, 2022. https://www.ic3.gov/PSA/2022/PSA220829
[6] FBI IC3, Public Service Announcement, “Criminals Increasing SIM Swap Schemes to Steal Millions of Dollars from US Public,” Feb. 8, 2022. https://www.ic3.gov/PSA/2022/PSA220208
[7] Federal Communications Commission, News Release, “FCC Adopts Rules to Protect Consumers’ Cell Phone Accounts,” Nov. 15, 2023 (FCC 23-95). https://docs.fcc.gov/public/attachments/DOC-398483A1.pdf
[8] FinCEN, Alert FIN-2023-Alert005, “FinCEN Alert on Prevalent Virtual Currency Investment Scam Commonly Known as ‘Pig Butchering’,” Sept. 8, 2023, pp. 1–4. https://www.fincen.gov/system/files/shared/FinCEN_Alert_Pig_Butchering_FINAL_508c.pdf
[9] FBI IC3, Public Service Announcement, “Increase in Companies Falsely Claiming an Ability to Recover Funds Lost in Cryptocurrency Investment Scams,” Aug. 11, 2023. https://www.ic3.gov/PSA/2023/psa230811
[10] FBI IC3, Public Service Announcement, “Fictitious Law Firms Targeting Cryptocurrency Scam Victims Offering to Recover Funds” (update), Aug. 13, 2025. https://www.ic3.gov/PSA/2025/PSA250813
Family limited partnerships (“FLPs”) are often used in estate planning and asset protection. When properly structured, an FLP can centralize family asset management, restrict transfers, separate management rights from economic rights, and make it harder for a creditor of one partner to reach specific partnership property.
But FLPs are not perfect asset protection structures. Courts may respect the partnership form and still allow a creditor to reach the debtor-partner’s economic interest.
In some cases, a charging order can lead to foreclosure or sale of the partnership interest itself.
The key distinction is between partnership property and the partner’s interest in the partnership. A creditor may be blocked from directly seizing partnership assets, but the debtor-partner’s economic rights may still be vulnerable.
A Creditor Usually Cannot Seize Partnership Assets Directly
The starting point is that a judgment against an individual partner is not the same as a judgment against the partnership.
In Crocker National Bank v. Perroton, 208 Cal. App. 3d 1, 255 Cal. Rptr. 794 (Cal. Ct. App. 1989), the California Court of Appeal explained:
“A creditor with a judgment against a partner but not against the partnership ordinarily cannot execute directly on partnership assets or on the partner’s interest in the partnership.”
That rule is important for FLP planning. It means that a personal creditor of one partner generally cannot simply levy on partnership real estate, investment accounts, or other assets merely because that partner owes a personal debt.
The court also explained why the charging order remedy exists. It was designed to prevent disruption of the partnership business and protect the interests of the other partners:
“It was to prevent such ‘hold up’ of the partnership business and the consequent injustice done the other partners resulting from execution against partnership property that the quoted code sections and their counterparts in the Uniform Partnership Act and the English Partnership Act of 1890 were adopted.”
This is one reason FLPs can provide meaningful protection: the charging-order remedy is designed to prevent a personal creditor of one partner from disrupting the partnership business or executing directly against partnership property.
However, that protection is not absolute; the creditor may still reach the debtor-partner’s economic interest through a charging order and, in some circumstances, seek sale or foreclosure of that interest.
The Creditor’s Remedy Is Usually a Charging Order
Because the law generally protects partnership property from direct execution for the personal debt of one partner, a creditor usually must proceed in a more limited way. Instead of seizing partnership assets, the creditor typically seeks a charging order against the debtor-partner’s partnership interest.
In Crocker Nat’l Bank v. Perroton, 208 Cal. App. 3d 1, 6, 255 Cal. Rptr. 794 (Cal. Ct. App. 1989), the court explained:
“Therefore, a judgment creditor must seek a charging order to reach the debtor partner’s interest in the partnership.”
A charging order does not usually give the creditor control over the partnership or direct ownership of partnership property. Instead, it allows the court to charge the debtor-partner’s economic interest with payment of the unsatisfied judgment.
The court then described what a charging order can do:
“Through a charging order, the court may charge the debtor’s interest in the partnership with payment of the unsatisfied judgment, plus interest. The court may also appoint a receiver of subsequent profits or other money due to the debtor partner.”
In practical terms, the charging order does not necessarily give the creditor control over the FLP. But it may redirect distributions that would otherwise go to the debtor-partner.
In Madison Hills Ltd. Partnership II v. Madison Hills, Inc., 35 Conn. App. 81, 84–85, 644 A.2d 363 (Conn. App. Ct. 1994), the Connecticut Appellate Court made the same point:
“The charging order leaves the partnership intact but diverts to the judgment creditor the debtor partner’s share of the profits.”
The court also emphasized the limits of a charging creditor’s rights:
“It is important to note that a charging creditor does not become a full partner, is not entitled to manage the partnership, and has no right to attach specific partnership property.”
This distinction is critical. A charging creditor may not step into the shoes of a full partner. The creditor may not automatically receive management rights. But the creditor may still reach economic rights attached to the debtor-partner’s interest.
A Charging Order Can Lead to Sale of the Partnership Interest
The major risk is that a charging order may not be the end of the enforcement process.
In Crocker, the creditor obtained a judgment against Jon Perroton and then obtained a charging order against his limited partnership interest. When the charging order did not result in payment, the creditor moved for sale of Perroton’s interest in the partnership.
The court noted:
“As of November 1985, Crocker had received no monies as a result of the charging order against Turn-Key Storage. Therefore, on November 26, 1985, Crocker moved for an order of sale of Perroton’s interest in Turn-Key Storage.”
The court ultimately allowed the sale of the debtor-partner’s interest, while distinguishing that interest from the partnership’s own property:
“We conclude that the authorities support the order for sale of a judgment debtor partner’s partnership interest as distinct from the property of the limited partnership, where the creditor has shown that it was unable to obtain satisfaction of the debt under the charging order, and where the remaining partner, here the general partner Bette Perroton, has consented to the sale.”
This is a key lesson for FLP planning. The partnership assets may be protected from direct execution, but the debtor-partner’s interest may still be charged and sold if the facts and governing law support that remedy.
The Purchaser Does Not Necessarily Receive Full Partner Rights
The sale of a partnership interest does not necessarily mean that the purchaser becomes a full partner or gains control over the partnership. In Crocker, the court explained:
“Just as a charging order cannot grant the creditor a greater interest in the partnership than that of the debtor partner at the time of the order . . . a supplementary order for sale, does not allow the purchaser to acquire more rights in the partnership than the debtor partner possessed.”
The court also noted:
“Further, both the limited partnership agreement and the consent to the sale by Bette Perroton make clear that a purchaser of Perroton’s limited partnership interest would have rights to profits and losses, but would not become a substituted limited partner in the partnership, absent consent by the general partner.”
This is where careful drafting matters. A well-drafted FLP agreement may limit what a creditor or purchaser receives, but it may not prevent the creditor from reaching the debtor-partner’s transferable economic interest.
Foreclosure of the Partnership Interest
Madison Hills shows another important risk: foreclosure. There, the creditor sought a charging order and strict foreclosure of the debtor’s partnership interest. The trial court ordered that “the partnership interest be foreclosed unless redeemed by the defendant prior to April 15, 1993.”
On appeal, the Connecticut Appellate Court confirmed that foreclosure was available:
“Foreclosure is one of the orders available to charging creditors.”
The court further concluded:
“We conclude, therefore, that the UPA does permit a charging creditor to enforce its charging order through strict foreclosure.”
For FLP planning, this is significant. A charging order may begin as a remedy limited to distributions, but in some jurisdictions and under some circumstances, it may lead to foreclosure of the debtor-partner’s interest.
Conclusion
Family limited partnerships can be useful estate planning and asset protection tools, but they are not creditor-proof.
Courts may protect partnership assets from direct seizure while still allowing a creditor to reach the debtor-partner’s economic interest through a charging order, sale, or foreclosure.
The key is careful planning. FLPs should be properly structured, funded, and documented before creditor issues arise. A well-drafted partnership agreement can limit what a creditor or purchaser receives, but it cannot eliminate all enforcement risk.
Contact Us
At Dilendorf Law Firm, we provide tailored legal solutions for high-net-worth individuals and families seeking to preserve wealth, maintain control, and plan for future generations.
We help U.S. and non-U.S. clients with estate planning, asset protection, family limited partnerships, domestic and international trust structures, and creditor-risk analysis.
If you’re considering a Family Limited Partnership as part of your estate or asset protection strategy, our team is here to help. Contact us at +1 212 457 9797 or email us at info@dilendorf.com.
