The cryptocurrency market is facing intensified scrutiny over legal accountability as a major exploit exposes vulnerabilities beyond the hacked platform itself. A class action lawsuit filed on April 14 focuses on whether Circle Internet Financial had a duty to act following the April 1 breach of the Drift Protocol, a Solana-based decentralized exchange. The complaint centers on alleged failures related to USDC and Circle’s Cross-Chain Transfer Protocol (CCTP) during the movement of stolen funds.
Rather than focusing on how the exploit began, the lawsuit targets what allegedly happened after the theft. Gibbs Mura, A Law Group, the firm that filed the suit, stated: “The lawsuit charges Circle Internet Financial with knowingly permitting the attackers, reportedly tied to North Korea’s government, to offload $230 million of their spoils over the course of several hours by using Circle’s own stablecoin USDC and its blockchain bridge CCTP, instead of freezing the funds.” This allegation places Circle’s infrastructure at the center of the dispute and frames the case around whether technical control over stablecoin flows and bridge activity can create legal exposure during an active hack.
Circle’s Response: Legal Limits vs. Technical Capability
Circle addressed the situation on April 10, emphasizing legal limits tied to freezing funds and its broader compliance obligations. In a published statement, the company stressed: “When Circle freezes USDC, it is not because we have decided, unilaterally or arbitrarily, that someone’s assets should be taken from them. It is because the law requires us to act.” The firm maintained that USDC operates within established regulatory frameworks, meaning any intervention must be authorized by relevant legal authorities. It also pointed to a gap between available technical capabilities and current legal structures, indicating that faster coordinated responses would require regulatory changes rather than unilateral action by issuers.
Drift Collapse Deepens Pressure Across DeFi
The Drift Protocol was compromised through pre-signed administrative transactions prepared weeks in advance. Attackers later executed those permissions to seize governance control and drain funds, stealing approximately $286 million within minutes. The breach allegedly involved fake collateral, durable nonce accounts, and social engineering tied to protocol signers. The exploit followed the removal of a timelock safeguard days earlier, which typically delays administrative actions.
Separately, Tether moved to stabilize the situation with a $150 million support plan following the exploit, highlighting how major stablecoin issuers may intervene differently during crisis events. The law firm stated Drift’s total value locked fell from about $550 million to under $250 million after the attack, with at least 20 other DeFi protocols reporting indirect losses tied to Drift exposure, while the DRIFT token declined more than 40%. The case could become an important test of how courts view the responsibilities of crypto infrastructure providers after high-value breaches. The law firm noted: “After the exploit, attackers allegedly bridged more than $230 million in stolen USDC from Solana to Ethereum using Circle’s own infrastructure — across 100+ transactions over eight hours. Circle allegedly took no action to freeze the funds, despite having the technical and contractual authority to do so.”
This claim may shape the debate over whether issuers and bridge operators are passive service providers or active control points during crisis events. For now, the lawsuit remains pending, and its early status means the allegations have not been tested in court.

