Civil Law And Crypto Asset Custody Mismanagement Claims In Europe .
Civil Law and Crypto Asset Custody Mismanagement Claims in Europe
1. Introduction
Crypto-asset custody mismanagement claims arise when a cryptocurrency exchange, custodian, wallet provider, broker, or other digital-asset service provider improperly handles assets entrusted to it by a client.
Typical allegations include:
loss or theft of private keys;
unauthorised withdrawals;
failure to segregate customer assets;
commingling of customer and corporate crypto-assets;
improper use or lending of customer crypto-assets;
inadequate wallet security;
failure to respond to suspicious transactions;
failure to freeze or preserve assets;
inaccurate account balances;
failure to return crypto-assets;
insolvency of the custodian;
negligent handling of stablecoins;
failure to maintain adequate custody records;
cyberattack caused by inadequate security;
unauthorised transfer to another wallet.
European crypto-custody law has changed significantly with Regulation (EU) 2023/1114 on Markets in Crypto-assets (MiCA). For regulated crypto-asset service providers, Article 75 imposes detailed custody obligations, including client agreements, custody policies, position registers, segregation of client assets, return procedures and liability for attributable loss. (EUR-Lex)
At the same time, European case law has established that crypto-assets can attract property rights, can potentially be traced, and can be protected through proprietary injunctions and other civil remedies. The leading authorities have so far come particularly from England and Wales, while EU legislation provides the developing regulatory framework.
2. Meaning of Crypto-Asset Custody
Custody exists where a third party holds or controls crypto-assets, or the means of accessing them, on behalf of a client.
For example:
Customer
↓
Crypto exchange
↓
Custodian wallet
↓
Blockchain
The exchange may control:
private keys;
seed phrases;
wallet addresses;
signing mechanisms;
withdrawal permissions.
The customer may merely have a contractual account showing:
10 BTC
without personally controlling the private keys.
This distinction is legally important.
3. Custodial vs Non-Custodial Wallets
Custodial wallet
The service provider controls the private keys or means of access.
Example:
Customer deposits 5 BTC with an exchange.
The exchange controls the wallet.
Non-custodial wallet
The customer controls the private keys.
The provider may merely supply software.
MiCA specifically addresses custody and administration by crypto-asset service providers; hardware or software providers of non-custodial wallets fall outside the relevant custody provisions. (EUR-Lex)
4. Main Legal Relationships
A custody arrangement may involve:
Contract
Customer ↔ Exchange
Property
Customer's proprietary interest in crypto-assets.
Trust/equitable relationship
Potentially relevant under some national legal systems.
Tort/delict
Negligent security or negligent handling.
Restitution
Recovery of assets wrongfully received or retained.
Regulatory law
MiCA and national implementation/supervision.
Insolvency law
Particularly important when the custodian becomes insolvent.
5. MiCA and Crypto Custody
MiCA is now central to European crypto-asset custody regulation.
Article 75 requires a crypto-asset service provider providing custody and administration to have an agreement with the client specifying matters including:
nature of the service;
custody policy;
communication arrangements;
security systems;
fees;
applicable law.
It must also maintain a register of positions corresponding to each client's rights. (EUR-Lex)
6. Segregation of Customer Assets
One of the most important MiCA principles is segregation.
Custodians must:
segregate client crypto-assets from their own holdings;
identify clients' means of access;
maintain appropriate operational segregation;
ensure client assets are legally segregated from the provider's estate according to applicable law.
The purpose is particularly important during insolvency: creditors of the provider should not ordinarily have recourse to crypto-assets held in custody for clients. (EUR-Lex)
7. Custodian Cannot Freely Use Client Assets
Where a provider holds client crypto-assets or the means of access, MiCA requires arrangements designed to safeguard client ownership rights and prevent the provider from using clients' assets for its own account. (EUR-Lex)
Thus, a custody dispute may arise if an exchange:
receives 1,000 BTC from customers → transfers them into its own operational wallet → uses them for its own trading.
The legal consequences depend on the contract, applicable property law, MiCA and insolvency circumstances.
8. Custody Policy
A regulated custodian must establish a custody policy designed to protect:
crypto-assets;
rights relating to crypto-assets;
means of access.
The policy should minimise risks arising from:
fraud;
cyber threats;
negligence.
This makes internal custody procedures legally significant evidence in litigation. (EUR-Lex)
9. Custodian Liability for Loss
Article 75(8) MiCA is particularly important.
A custody provider is liable to its clients for loss of crypto-assets or means of access resulting from an incident attributable to the provider.
The liability is capped at the market value of the crypto-asset lost at the time of the loss.
The provider may avoid liability where it demonstrates that the event occurred independently of its service or operations, such as a problem inherent in a distributed ledger that it does not control. (EUR-Lex)
10. Types of Custody Mismanagement
A. Private-Key Mismanagement
The custodian loses:
private key;
recovery key;
seed phrase;
signing authority.
The client can no longer access the asset.
B. Unauthorised Withdrawal
An attacker obtains credentials and transfers:
BTC → attacker's wallet.
The issue becomes whether the custodian:
maintained adequate security;
followed authentication procedures;
detected suspicious activity;
responded promptly.
C. Internal Fraud
An employee may misuse custody access.
Possible claims include:
breach of contract;
negligence;
dishonest assistance;
breach of fiduciary duty where applicable;
proprietary recovery.
11. Case Law 1 — AA v Persons Unknown
AA v Persons Unknown and Others
[2019] EWHC 3556 (Comm)
This is one of the foundational European crypto-asset cases.
An insurer had paid Bitcoin as a ransom following a cyberattack.
The insurer subsequently sought recovery and proprietary remedies.
The High Court considered whether Bitcoin could constitute property.
Bryan J concluded that crypto-assets such as Bitcoin could be treated as property, applying the traditional criteria associated with property law. (Bailii)
Importance
This was crucial because proprietary remedies generally require a proprietary interest.
Once crypto-assets are recognised as property, courts can potentially use:
proprietary injunctions;
freezing orders;
tracing;
following;
asset-preservation remedies.
Principle
Crypto-assets such as Bitcoin can attract property rights under English law.
12. Case Law 2 — Vorotyntseva v Money-4 Ltd
Vorotyntseva v Money-4 Ltd t/a Nebeus.com
[2018] EWHC 2596 (Ch)
The claimant transferred substantial amounts of Bitcoin and Ethereum to a cryptocurrency business.
She became concerned that the cryptocurrency might be dissipated.
The High Court granted a freezing order and proprietary protection.
The court was satisfied that cryptocurrency could be the subject of a proprietary injunction. (Bailii)
Importance for custody claims
This case is particularly useful where:
customer deposits crypto-assets with a custodian → custodian may dissipate them.
It demonstrates that the court can protect identifiable crypto-assets pending determination of the underlying dispute.
Principle
Crypto-assets can be protected through proprietary and freezing remedies where the relevant requirements are satisfied.
13. Case Law 3 — Tulip Trading Ltd v Bitcoin Association
Tulip Trading Ltd v Bitcoin Association for BSV & Others
[2023] EWCA Civ 83
The claimant alleged that hackers had stolen its private keys, leaving it unable to access substantial Bitcoin holdings.
It argued that blockchain developers owed fiduciary and/or tortious duties requiring them to assist in restoring access.
The Court of Appeal allowed the claim to proceed at the jurisdictional stage because there was an arguable case concerning duties owed by developers to cryptocurrency owners. (Bailii)
Importance
Tulip demonstrates that crypto-asset disputes are not limited to traditional exchange/customer relationships.
They may also raise questions involving:
developers;
network control;
private keys;
access;
fiduciary duties;
tort;
property rights.
Important qualification
The case should not be read as establishing that every blockchain developer owes fiduciary duties to every token holder.
It concerned whether such duties were sufficiently arguable for the litigation to proceed.
14. Case Law 4 — Fetch.AI v Persons Unknown
Fetch.AI Ltd & Anor v Persons Unknown Category A & Others
[2021] EWHC 2254 (Comm)
The claim arose from fraudulent access to cryptocurrency accounts maintained with Binance.
The attackers allegedly manipulated trades at substantial undervalues and transferred crypto-assets away, causing losses exceeding US$2.6 million. (Bailii)
The court granted various forms of relief, including:
proprietary injunction;
worldwide freezing order;
disclosure orders;
Bankers Trust relief.
Importance for custody
The case demonstrates how courts can intervene where a cryptocurrency account has been compromised and assets have been moved through exchanges.
Principle
Crypto-asset exchanges can become important targets for disclosure and preservation orders when misappropriated assets pass through their systems.
15. Case Law 5 — D'Aloia v Persons Unknown
D'Aloia v Persons Unknown
[2022] EWHC 1723 (Ch)
The claimant alleged that he had been deceived into transferring USDT and USDC to fraudsters.
The High Court considered:
cryptocurrency property;
situs of crypto-assets;
jurisdiction;
tracing;
Bankers Trust relief.
The court held that there was a good arguable case that the crypto-assets were situated in England because the claimant was domiciled there and applied the analysis previously developed in Ion Science. (Bailii)
Importance
For cross-border custody litigation, this is significant because a crypto-asset may move through wallets and exchanges located in different countries.
The court nevertheless needs a legal framework for deciding:
Where is the asset legally situated?
Principle
The domicile of the owner may provide an important connecting factor for the situs of a crypto-asset under English private international law.
16. Case Law 6 — Piroozzadeh v Persons Unknown
Piroozzadeh v Persons Unknown Category A & Others
[2023] EWHC 1024 (Ch)
This is especially important for exchange custody and commingling.
The claimant's Tether had passed through cryptocurrency exchanges.
At one exchange, deposited Tether was transferred into a central unsegregated hot wallet.
The exchange explained that users received a credit balance rather than retaining a specifically segregated proprietary interest in particular Tether units.
The court examined the consequences of this pooling structure for tracing and proprietary remedies. (Bailii)
Importance
This case shows a fundamental custody problem:
Does the customer own the specific crypto-assets deposited, or merely possess a contractual right against the exchange?
The answer can determine whether a customer can:
trace particular tokens;
assert proprietary rights;
claim against pooled assets;
rely on constructive-trust principles.
Principle
Commingling and exchange pooling can fundamentally affect proprietary recovery and tracing.
17. Case Law 7 — D'Aloia v Persons Unknown, 2024
D'Aloia v Persons Unknown Category A & Others
[2024] EWHC 2342 (Ch)
This later trial-level decision is particularly important because the court directly addressed the nature of USDT.
The court concluded that USDT attracts property rights under English law and described it as a distinct form of property, rather than simply a traditional chose in action or chose in possession.
The court also considered:
tracing;
following;
constructive trusts;
unjust enrichment;
exchange liability;
suspicious transactions;
KYC/AML controls.
The claimant nevertheless failed to prove that his particular USDT had reached the relevant Bitkub wallet. (Bailii)
Major principle
Recognising crypto-assets as property does not automatically establish that a claimant can identify and trace his particular crypto-assets.
This distinction is extremely important.
18. Case Law 8 — Osbourne v Persons Unknown
Osbourne v Persons Unknown & Another
[2022] EWHC 1021 (Comm)
The case concerned NFTs and the question of their legal location.
The court followed the developing approach that crypto-assets could be treated as located where their owner was domiciled, following the reasoning in Ion Science and related authorities. (Bailii)
Relevance
Although the dispute involved NFTs rather than conventional custody, it illustrates how courts approach:
digital asset situs;
jurisdiction;
cross-border proprietary claims.
19. Case Law 9 — Ion Science
Ion Science Ltd & Duncan Johns v Persons Unknown
Commercial Court, 21 December 2020
This unreported decision is frequently cited in subsequent English crypto-asset litigation.
It concerned cryptocurrency fraud and issues including:
proprietary relief;
jurisdiction;
crypto-asset situs.
The court adopted the approach that the situs of a crypto-asset could be connected to the domicile of its owner. That reasoning was subsequently relied upon in D'Aloia and Osbourne. (Bailii)
Qualification
Ion Science is an unreported first-instance decision, so it should not be treated as equivalent to a final appellate precedent.
20. Case-Law Table
| Case | Year | Main issue | Custody relevance |
|---|---|---|---|
| Vorotyntseva v Money-4 | 2018 | Crypto held by platform; freezing/proprietary relief | Very high |
| AA v Persons Unknown | 2019 | Crypto as property | Fundamental |
| Ion Science | 2020 | Situs/jurisdiction of crypto | High |
| Fetch.AI | 2021 | Exchange accounts, fraud and disclosure | Very high |
| D'Aloia | 2022 | Tracing, situs, exchange involvement | Very high |
| Tulip Trading | 2023 | Lost private keys and developer duties | High |
| Piroozzadeh | 2023 | Exchange pooling and tracing | Very high |
| D'Aloia | 2024 | USDT property, tracing and exchange liability | Very high |
| Osbourne | 2022 | NFT situs | Analogical |
21. Custody and Property Rights
The central legal question is:
Who owns the crypto-assets while they are in custody?
There are several possibilities.
Model 1 — Direct proprietary ownership
The customer owns identifiable crypto-assets held by the custodian.
Model 2 — Trust structure
The custodian holds assets for customers under a trust.
Model 3 — Contractual entitlement
The customer has a contractual claim for an equivalent amount of crypto.
Model 4 — Mixed/pooled model
Customer deposits are pooled and the customer receives a contractual credit.
Piroozzadeh demonstrates why the distinction matters. (Bailii)
22. Segregated Custody
Suppose:
Customer A:
10 BTC
Customer B:
20 BTC
Custodian:
separate wallets for A and B.
Tracing may be easier.
If instead:
A + B + C assets → single omnibus wallet
then identification may become much more difficult.
MiCA therefore places substantial emphasis on segregation and clear identification of clients' assets. (EUR-Lex)
23. Omnibus Wallets
An omnibus wallet contains crypto-assets belonging to multiple customers.
It is not automatically unlawful.
But it creates legal and evidentiary difficulties concerning:
ownership;
tracing;
insolvency;
proportional distribution;
customer priority.
The contract and applicable national property/insolvency law become particularly important.
24. Commingling
Commingling occurs when:
Customer assets + custodian assets
are combined.
This can create serious problems during insolvency.
Example:
Customer assets:
€100 million equivalent crypto
Custodian's own assets:
€50 million
Total wallet:
€150 million.
If €30 million disappears, the legal question becomes:
Whose assets were lost?
The answer may depend upon segregation, records, tracing and national property law.
25. Custodian Insolvency
Insolvency is one of the most important custody risks.
Suppose an exchange becomes insolvent.
The court may need to determine:
Which crypto-assets belong to customers?
Which belong to the exchange?
Were assets segregated?
Were customer assets pledged?
Were they lent to third parties?
Does the customer have proprietary rights?
Or merely an unsecured contractual claim?
MiCA's segregation rules are designed in part to protect clients in such circumstances. (EUR-Lex)
26. Unauthorized Use of Customer Assets
A serious custody claim may arise where a provider uses client assets:
Customer deposits 100 BTC.
↓
Custodian lends 80 BTC to an affiliated company.
↓
Affiliate becomes insolvent.
↓
Customer demands 100 BTC.
This raises:
breach of contract;
breach of custody obligations;
property claims;
restitution;
insolvency;
potentially regulatory liability.
27. Private-Key Management
Private-key management is central to custody.
Potential failures include:
one employee controlling the only key;
inadequate multi-signature arrangements;
failure to maintain backups;
key theft;
insecure storage;
unauthorised access;
loss of recovery credentials.
EU regulatory technical standards and supervisory requirements increasingly focus on detailed segregation and safeguarding arrangements, including cryptographic-key controls and multi-signature systems. (EUR-Lex)
28. Cyberattack
A cyberattack does not automatically eliminate custodian liability.
The legal question may be:
Was the incident attributable to the custodian?
Relevant evidence includes:
authentication procedures;
multi-factor authentication;
key management;
withdrawal controls;
monitoring;
incident response;
employee access;
penetration testing.
Under MiCA Article 75, attribution is central to liability for custody losses. (EUR-Lex)
29. Suspicious Transactions
Suppose:
A customer normally withdraws:
€5,000/day.
Suddenly:
€5 million crypto withdrawal.
The custodian's systems detect:
unusual IP;
new wallet;
unusual transaction size;
rapid transfers.
If the provider ignores obvious warning signals, the claimant may argue that the provider failed to comply with its contractual or regulatory duties.
The D'Aloia litigation illustrates how exchange controls, suspicious activity, KYC and withdrawal controls can become relevant to proprietary claims. (Bailii)
30. Tracing
Tracing is particularly important in cryptocurrency litigation.
Example:
Customer
↓
100 USDT
↓
Wallet A
↓
Wallet B
↓
Exchange C
↓
Wallet D.
If the claimant can establish the movement of the identifiable asset, proprietary remedies may become available.
But blockchain visibility does not automatically mean legal tracing succeeds.
The claimant must prove the relevant chain of transactions.
31. Following vs Tracing
These concepts should be distinguished.
Following
Tracks the asset itself through successive hands.
Tracing
Identifies the value of the claimant's property in another asset or mixed fund.
D'Aloia 2024 expressly considered both concepts and recognised that crypto-assets can in principle be followed or traced, subject to proof. (Bailii)
32. Blockchain Evidence
Blockchain records can provide:
transaction hash;
wallet address;
timestamp;
amount;
destination address;
transaction history.
But expert evidence may still be necessary to establish:
ownership;
control;
attribution;
wallet linkage;
identity of exchange customers.
33. The Problem of Wallet Ownership
A blockchain shows:
Wallet X sent 100 USDT to Wallet Y.
It does not necessarily show:
Person A owns Wallet X.
Therefore, litigation often requires:
exchange KYC information;
IP records;
device records;
email records;
transaction records;
expert blockchain analysis.
34. Custody Records
MiCA requires custody providers to maintain a register of client positions and record movements. (EUR-Lex)
This creates an important evidentiary tool.
A customer can potentially compare:
blockchain record
with
custodian's internal position register.
A mismatch can become evidence of:
accounting error;
unauthorised transaction;
custody failure;
internal fraud.
35. Failure to Return Crypto-assets
Another straightforward custody claim arises where:
Customer requests withdrawal.
The custodian refuses or cannot return the assets.
Potential explanations include:
compliance investigation;
court order;
technical failure;
insolvency;
insufficient liquidity;
alleged breach of terms.
MiCA expressly requires necessary procedures for returning crypto-assets or the means of access to clients as soon as possible. (EUR-Lex)
36. Contractual Duties
A custody agreement may specify:
withdrawal rights;
storage method;
security procedures;
asset segregation;
fees;
permitted uses;
applicable law;
liability limitations.
The claimant should first identify the exact contractual promise.
37. Tort/Delict
A parallel negligence/delict claim may arise where:
security was inadequate;
employee controls were deficient;
withdrawal monitoring failed;
foreseeable cyber risks were ignored.
Whether a separate tort/delict claim exists depends on the applicable national law.
38. Fiduciary Duties
A claimant may argue that a custodian owes fiduciary obligations.
This is highly fact-sensitive.
Tulip Trading illustrates the difficulty of establishing novel fiduciary duties in the crypto ecosystem. The Court of Appeal allowed the relevant argument to proceed, but the case should not be read as establishing a universal fiduciary duty for crypto developers or custodians. (Bailii)
39. Unjust Enrichment
Suppose:
Exchange receives customer crypto-assets.
but:
retains them after the contractual basis for retention disappears.
The customer may potentially consider restitutionary remedies.
However, unjust enrichment depends on the applicable national law and the precise relationship between the parties.
40. Constructive Trust
A constructive trust may be relevant where:
assets were obtained through wrongdoing;
identifiable crypto-assets remain traceable;
the recipient's knowledge/notice is sufficient;
applicable national law recognises the relevant remedy.
D'Aloia and related litigation demonstrate how constructive-trust arguments have been developed in cryptocurrency disputes. (Bailii)
But a constructive trust should not be assumed merely because an exchange possesses cryptocurrency belonging to someone else.
41. The Importance of Piroozzadeh
Piroozzadeh provides an important warning.
The claimant argued that the exchange controlled the claimant's cryptocurrency.
But the exchange's evidence showed that deposited Tether was:
swept into a central unsegregated pool.
The court examined the legal consequences of that arrangement and the effect on tracing. (Bailii)
Therefore:
“The exchange has my cryptocurrency” does not necessarily prove “the exchange holds my identifiable property on trust.”
The contractual structure matters.
42. Custody and Insolvency
Suppose an exchange fails with:
€500 million customer crypto;
€100 million proprietary crypto;
€300 million liabilities.
The critical legal question is whether customers have:
Proprietary claim
“Those assets belong to us.”
or
Personal claim
“The exchange owes us an equivalent amount.”
The first may provide significantly different insolvency protection from the second.
43. MiCA and Insolvency Protection
MiCA's segregation framework is designed to prevent customer crypto-assets from being treated simply as part of the provider's own estate.
Article 75 requires legal and operational segregation and aims to prevent the provider's creditors from having recourse to client assets held in custody, subject to applicable law. (EUR-Lex)
44. Liability Cap
A particularly important MiCA rule is the liability cap.
Where the provider is liable for loss under Article 75(8), its liability is capped at:
market value of the crypto-asset lost at the time the loss occurred.
This is different from asking:
“What would the asset be worth five years later?”
The relevant statutory valuation point is the time of loss. (EUR-Lex)
45. Volatility
Crypto-assets can change value dramatically.
Example:
At loss:
Bitcoin = €40,000.
Six months later:
Bitcoin = €70,000.
A claimant may argue for €70,000.
But a statutory liability rule may use a different valuation point.
Therefore:
Date of loss can become a major damages issue.
46. Stablecoins
Stablecoins such as USDT create additional issues.
A claimant may argue:
“USDT is essentially equivalent to USD.”
But legal analysis must distinguish:
token;
issuer's obligations;
exchange credit;
wallet balance;
underlying reserve;
contractual entitlement.
The 2024 D'Aloia decision treated USDT as property capable of proprietary rights under English law. (Bailii)
47. Cross-Border Custody
A modern custody arrangement may involve:
Customer — France
Exchange — Germany
Custodian — Luxembourg
Wallet infrastructure — Switzerland
Blockchain — decentralised
This creates questions about:
jurisdiction;
applicable law;
property situs;
insolvency;
enforcement.
48. Crypto-Asset Situs
Traditional property law usually asks:
Where is the asset located?
For crypto-assets this is difficult because there is no single physical location.
English cases such as Ion Science, D'Aloia and Osbourne have used the domicile of the owner as an important connecting factor. (Bailii)
This remains an evolving area rather than a universally harmonised European rule.
49. Jurisdiction Clauses
Custody contracts should be examined for:
exclusive jurisdiction;
arbitration;
governing law;
consumer jurisdiction provisions.
A customer may be located in France while the exchange is incorporated elsewhere.
The jurisdiction clause can therefore become decisive.
50. Arbitration
A custody agreement may contain:
“All disputes shall be resolved by arbitration.”
The arbitration agreement may govern:
contractual custody disputes;
loss of crypto-assets;
withdrawal disputes;
service failures.
But mandatory statutory and insolvency rules can still affect the substantive dispute.
51. Consumer Claims
Where a retail customer uses an exchange, consumer-protection rules may become relevant.
Questions include:
transparency of terms;
unfair contractual terms;
limitation clauses;
withdrawal rights;
disclosures;
dispute resolution.
The analysis differs from a sophisticated institutional investor negotiating a bespoke custody agreement.
52. Institutional Custody
Institutional customers may have detailed agreements covering:
cold storage;
hot storage;
multi-signature approval;
transaction limits;
insurance;
segregation;
audit rights;
business continuity.
A failure to follow these procedures can create a strong contractual case.
53. Evidence in Custody Litigation
Important evidence includes:
Blockchain evidence
transaction hashes;
wallet addresses;
block numbers;
transaction history.
Custodian records
account statements;
position registers;
withdrawal records;
wallet logs.
Security records
login history;
IP addresses;
authentication logs;
MFA records.
Internal records
incident reports;
compliance alerts;
KYC records;
AML investigations.
Contractual records
custody agreement;
terms and conditions;
risk disclosures;
custody policy.
54. Expert Evidence
Blockchain experts may need to determine:
whether assets can be followed;
whether assets were mixed;
whether a wallet is controlled by a particular exchange;
whether a transaction is connected to the claimant;
whether an apparent transfer is genuine;
whether funds remain identifiable.
The D'Aloia 2024 litigation demonstrates how weaknesses in blockchain-tracing evidence can defeat a proprietary claim even where the underlying fraud is accepted. (Bailii)
55. Common Defences
A custodian may argue:
1. No breach
The provider complied with the custody agreement.
2. External cyberattack
The loss was caused by an independent attack.
3. No attribution
The incident was outside the provider's control.
4. No proprietary interest
The customer had only a contractual claim.
5. No tracing
The claimant cannot identify its assets.
6. Good-faith receipt
The exchange received assets without sufficient notice of wrongdoing.
7. Contractual limitation
Liability is limited under the agreement.
8. Regulatory freeze
Assets were frozen pursuant to legal requirements.
9. Contributory fault
The customer compromised credentials or security.
56. Custody Mismanagement vs Fraud
These should be separated.
Fraud by third party
A scammer steals cryptocurrency.
Custody mismanagement
The custodian itself:
failed to secure the wallet;
failed to segregate assets;
failed to detect suspicious withdrawals;
misused customer assets.
Mixed situation
A third-party hacker steals assets because the custodian's security controls were inadequate.
This is often the most complicated category.
57. Key Legal Issues
A court will generally need to determine:
Was there a custody contract?
What exactly was held?
Who owned it?
Who controlled the private keys?
Were customer assets segregated?
Was there commingling?
What caused the loss?
Was the loss attributable to the custodian?
Can the crypto-assets be traced?
Which law governs?
Which court has jurisdiction?
What remedy is available?
58. Practical Example
Facts
A German investor deposits:
20 BTC
with a European crypto exchange.
The exchange places customer BTC into an omnibus wallet.
An employee uses the private key to transfer:
5 BTC
to a third-party wallet.
The exchange later becomes insolvent.
Possible claims
The investor could potentially examine:
Contract
Was there a promise to safeguard the 20 BTC?
MiCA
Were client assets properly segregated and safeguarded?
Property
Does the investor retain proprietary rights?
Tracing
Can the 5 BTC be identified?
Restitution
Can the transferred assets be recovered?
Insolvency
Are the investor's assets outside the exchange estate?
Damages
What is the legally recoverable value?
59. Applying the Cases
AA
Supports the proposition that crypto-assets can be property.
Vorotyntseva
Supports proprietary protection and freezing relief.
Fetch.AI
Demonstrates disclosure and preservation mechanisms involving exchanges.
D'Aloia 2022
Addresses situs and cross-border jurisdiction.
Piroozzadeh
Shows the difficulties created by exchange pooling.
Tulip Trading
Demonstrates the possible significance of private-key loss and novel duties.
D'Aloia 2024
Provides detailed treatment of USDT property and tracing.
60. Case-Law Principles in Simple Language
| Principle | Authority |
|---|---|
| Crypto-assets can be property | AA |
| Crypto can receive proprietary protection | Vorotyntseva |
| Exchange-related fraud can justify disclosure/freezing relief | Fetch.AI |
| Owner's domicile can be relevant to crypto situs | D'Aloia 2022 |
| Private-key loss can generate novel duty arguments | Tulip Trading |
| Exchange pooling affects tracing | Piroozzadeh |
| USDT can attract property rights | D'Aloia 2024 |
| NFT/crypto situs can be analysed through owner's domicile | Osbourne |
61. Relationship Between MiCA and Case Law
The cases largely developed before or alongside the emergence of the EU's harmonised MiCA regime.
MiCA now adds specific statutory obligations for regulated custodians.
Therefore, a modern European custody dispute may involve:
Common/private law
MiCA
national property law
national insolvency law
private international law
The cases remain useful because MiCA does not eliminate questions of:
ownership;
tracing;
unjust enrichment;
proprietary remedies;
causation;
damages.
62. Important Limitation
The major caution is that much of the leading reported crypto-property jurisprudence comes from England and Wales, which is not an EU Member State.
Accordingly:
English crypto cases are highly persuasive comparative European authorities, but they are not automatically binding throughout the EU.
For an EU Member State, the court must also consider:
its own civil code;
property law;
contract law;
insolvency law;
MiCA;
applicable EU private-international-law rules;
national crypto-asset regulation.
This distinction is especially important in a comparative “Civil Law in Europe” answer.
63. Six Core Cases to Remember
If an examination question asks for at least six cases, the strongest set is:
1. Vorotyntseva v Money-4 Ltd
[2018] EWHC 2596 (Ch)
Crypto held by a platform; freezing and proprietary relief.
2. AA v Persons Unknown
[2019] EWHC 3556 (Comm)
Crypto-assets can constitute property.
3. Fetch.AI Ltd v Persons Unknown
[2021] EWHC 2254 (Comm)
Fraudulent crypto transfers; exchange disclosure and preservation.
4. D'Aloia v Persons Unknown
[2022] EWHC 1723 (Ch)
Crypto situs, jurisdiction and proprietary recovery.
5. Piroozzadeh v Persons Unknown
[2023] EWHC 1024 (Ch)
Exchange pooling, commingling and tracing.
6. Tulip Trading Ltd v Bitcoin Association
[2023] EWCA Civ 83
Lost private keys and potential duties within cryptocurrency networks.
Additional modern authority
D'Aloia v Persons Unknown [2024] EWHC 2342 (Ch) — especially important for USDT, property rights, tracing and exchange liability. (Bailii)
64. Conclusion
Crypto-asset custody mismanagement litigation in Europe is developing at the intersection of traditional civil/property law and specialised digital-asset regulation.
The fundamental legal structure is:
Custody Contract → Ownership → Segregation → Security → Mismanagement → Loss → Causation → Tracing → Proprietary/Personal Remedies
The most important modern regulatory development is MiCA, which expressly requires regulated custody providers to safeguard client ownership rights, maintain custody policies and client position records, segregate customer assets from their own assets, maintain return procedures, and accept liability for attributable losses subject to the statutory framework. (EUR-Lex)
The case law adds the private-law dimension. AA v Persons Unknown recognises crypto-assets as property; Vorotyntseva demonstrates proprietary and freezing protection; Fetch.AI demonstrates exchange-related disclosure and preservation remedies; D'Aloia addresses situs and tracing; Piroozzadeh demonstrates the difficulties created by pooled exchange wallets; and Tulip Trading explores potential duties surrounding control of blockchain networks. (Bailii)
Final revision formula
Crypto Custody + Property Rights + Segregation + Private-Key Security + Contract + MiCA + Tracing + Exchange Pooling + Insolvency + Cross-Border Jurisdiction + Damages = Crypto Asset Custody Mismanagement Litigation in Europe

comments