White House memo puts private cyber retaliation under government control
A White House memorandum signed by President Donald Trump on Aug. 12 could change how crypto firms respond to hackers, but two crypto lawyers say it is much tighter than the early reaction implied.
The memo would create a program under a new National Coordination Center, allowing vetted private U.S. firms to go after foreign criminal hacking groups online. The work could include surveillance and disruptive cyber effects operations, but only with government approval and supervision. Foreign state hackers, and groups acting at a government’s direction, are excluded.
“Agents of the government, not free agents”
On the Aug. 18 episode of DEX in the City, host Jessi Brooks of Ribbit Capital spoke with Jane Khodarkovsky, a financial integrity and sanctions expert who previously worked in government, and Jacob Robinson, host of the Law of Code podcast.
Khodarkovsky pushed back on the idea that the memo gives private companies a blank check. In her view, participants would be tightly supervised and would function as “agents of the government,” not independent actors.
She pointed to several safeguards built into the program: each participating company must post a bond or escrow of at least $1 million, which can be forfeited if the company breaks its agreement. Two executive directors, one from the Justice Department and one from the Department of Homeland Security, would control approvals. The memo also bars operations the government believes could cause loss of life, serious injury, or amount to the use of force under international law.
Khodarkovsky said the program is also designed for ongoing review. The first 60 days are meant to establish processes and procedures, and each year the government will assess whether companies are still following them. She said the memo is not about vigilante justice or a general permission slip to act simply because an attack is being prevented. The document requires compliance with U.S. and international law, and companies would need authorization before acting against U.S. persons or systems.
Robinson calls it a modern digital privateering model
Robinson took a more favorable view, describing the program as a long-overdue tool for crypto. He compared it to privateering, the centuries-old practice of governments authorizing private ships to attack enemies at sea, and argued that the industry needs a digital version.
On the show, he said “cyber letters of marque” could let vetted operators pursue criminals, especially on blockchains, and called it a “huge, huge step in the right direction” if the details are done properly.
He said the need is rooted in speed. When a protocol is drained, the people best positioned to react are often private parties, but they have little legal cover to act. Robinson pointed to the roughly $280 million Drift Protocol exploit earlier this year, when much of the stolen value moved in Circle’s USDC. People were calling for Circle to freeze it, he said, but Circle faces major risk if it does something like that without a court order or a government mandate.
Brooks says the details will decide the outcome
Brooks was more cautious. She agreed that bringing in the private sector is probably a good idea in principle, but said “the devil’s gonna be in the details.”
Her main concern is oversight capacity. If the government does not have enough technical experts to supervise the program, she said, then it could amount to little more than “people out there hacking.”
She also noted that the memo does not repeal the Computer Fraud and Abuse Act, so the legal limits on what deputized companies can actually do still have to be spelled out.
All three panelists said a lot remains unwritten. Operating procedures are due within 60 days and a program status report within 180 days. Khodarkovsky also flagged a classified annex governing how intelligence agencies share information with private companies, saying it could matter as much as the public text.
Related: DEX in the City: The CFTC’s Kalshi Rescue and the Limits of Emergency Power

