A U.S. court in California has ruled in favor of plaintiffs who alleged that the bZx protocol, and governance token-holding members of its decentralized autonomous organization (DAO), were negligent and liable for losses resulting from a hack that drained its treasury.
The putative class action against bZx, its founders, software developers Leveragebox LLC and Hashed Labs LLC was initiated in July 2022.
While the court dismissed some of the claims, such as claims that founders Tom Bean and Kyle Kistner are personally liable for breaching fiduciary duty, the fact that it allowed the negligence claims to proceed has created a landmark ruling in the relatively murky topic of the liability of governance token holders in DAOs.
The case stems from the $55 million hack of decentralized finance (DeFi) lender bZx in 2021, which resulted because a developer downloaded an email attachment containing malware. Not only did the attacker drain the wallet of the BZRX token, but other digital assets like ether. This is on top of other hacks the protocol suffered in 2020, one of which was for $8 million, while two others that occurred were for $630,000 and $350,000.
As a response to the hack, the bZx DAO passed a governance motion to compensate token holders 1:1 for their lost BZRX tokens and a debt repayment plan which would repay holders for their other stolen crypto. The time horizon of this repayment plan was unacceptable for holders, hence the class-action lawsuit.
The bZx DAO later rebranded to Ooki DAO, which many – including courts – have called its successor. In late 2022, the DAO’s co-founders paid $250,000 to settle a case with the Commodity Futures Trading Commission (CFTC) regarding off-exchange tokenized margin trading and lending services.
What fiduciary duty and care does a DAO have?
Before the court was the question of whether all persons holding BZRX tokens are part of a general partnership.
At the core of the case are how the concepts of fiduciary duty (the obligation to act in the best interest), the duty of care (the obligation to act without negligence), as well as joint and several liability (a responsibility that is shared by multiple parties), apply to the concept of a DAO and governance token holders. While existing case law has created plenty of guidance on how these concepts apply to traditional finance (TradFi) partnership structures like general and limited partnerships, DAOs are something of an undiscovered country given their unique structure.
The plaintiffs, citing California law, argued that general partnerships exist when there is an “association of two or more persons to carry on as co-owners of a business for profit,” including the caveat that partnerships can be unintentional, which is held up by case law.
The court found that the bZx protocol meets the definition of a general [artnership because of how the token holders can both suggest and vote on governance proposals, including hiring and dispersing treasury assets to token holders in the same way that a corporation authorizes dividends.
“Given this context, the Court disagrees that recognizing the bZx DAO as a general partnership would be a ‘radical expansion and alteration of long-standing principles of partnership law,’” the ruling reads.
And with this comes the liability that arises out of a general partnership. The involvement that token holders have in the business via participation in governance protocols also means they have a duty of care, the court found, including that the protocol was properly maintained and had sufficient security measures.
Are DAO founders personally liable?
The next question before the courts was whether the founders themselves are liable for the DAO, and if they could be held responsible for their inaction and negligence.
This is where the concept of joint and several liability comes into play. Joint and several liability refers to the legal concept where multiple parties can be held responsible for the same negligent action, and each party can be held liable for the entire amount of damages, regardless of their individual contribution.
If this concept were to be applied to the DAO’s founders, that means each defendant, in theory, would have been held responsible for the damages suffered by the plaintiffs due to the $55 million hack.
But the court found that complaints against developers Leveragebox LLC and Hashed Labs LLC failed to provide the necessary elements to establish claims of negligence, breach of fiduciary duty, and joint and several liability.
"Because Plaintiffs have failed to allege that the Moving Defendants had actual authority to control the bZx DAO, the Court finds that Plaintiffs have failed to allege joint and several liability,” the docket reads.
Separately, a claim against founder Tom Bean was dismissed because the court found that the plaintiffs hadn’t brought sufficient evidence to show that a California court had jurisdiction over him.
However, the court said that it would be receptive to an amended pleading which presents a new argument about jurisdiction.
The leader in news and information on cryptocurrency, digital assets and the future of money, CoinDesk is an award-winning media outlet that strives for the highest journalistic standards and abides by a strict set of editorial policies. In November 2023, CoinDesk was acquired by Bullish, a cryptocurrency exchange, which in turn is owned by Block.one, a firm with interests in a variety of blockchain and digital asset businesses and significant holdings of digital assets including bitcoin and EOS. CoinDesk operates as an independent subsidiary, and an editorial committee, chaired by a former editor-in-chief of The Wall Street Journal, is being formed to support journalistic integrity.
Learn more about Consensus 2024, CoinDesk's longest-running and most influential event that brings together all sides of crypto, blockchain and Web3. Head to consensus.coindesk.com to register and buy your pass now.