CASP Liability for Hacks: When an Exchange is Obliged to Return Stolen Crypto Under EU Law
CASP Liability for Hacks: When an Exchange is Obliged to Return Stolen Crypto Under EU Law
CASP Liability for Hacks: When an Exchange is Obliged to Return Stolen Crypto Under EU Law
Cryptocurrency exchange hacking is no longer a gray area of responsibility.
With the adoption of MiCA and DORA, the EU is establishing a legal framework in which In some cases, CASPs are required to compensate clients for lost assets, rather than simply referring to market risk.
Jurisprudential Consulting Group explains, Where is the legal line between market risk and provider liability?, and when the user can actually demand a refund.
- Mica and customer protection
- DORA and cyber resilience
- responsibility for operational failures
Consultation cost from 250 euros

Why did exchanges almost never return funds in the past?
Historically, crypto platforms have relied on several arguments:
- lack of uniform regulation
- classification of crypto as a high-risk asset
- user agreements
- transfer of responsibility to the client
- lack of cybersecurity standards
Even major incidents rarely resulted in compensation.
What has changed with the introduction of MiCA
Mica introduces direct responsibilities of CASP to protect clients' assets.
Key changes:
- mandatory separation of assets
- storage and control requirements
- operational risk management
- responsibility for internal processes
- protecting clients' interests as a principle
The exchange can no longer completely shift the risk to the user.
DORA's Role in Hacking
DORA complements MiCA by establishing requirements for:
- cyber resilience
- IT risk management
- systems testing
- incident response
- hack reporting
Violation of these requirements increases the liability of CASP.
When hacking becomes an exchange's legal liability
CASP may be required to compensate for the loss of assets if it is established that:
- insufficient security measures
- violation of MiCA or DORA requirements
- key management errors
- internal failures or negligence
- lack of asset segregation
The key criterion is not the fact of hacking itself, but quality of protection.
The difference between custodial and non-custodial services
Liability depends on the storage model.
If assets:
- were under the control of the exchange
- managed custodially
- were stored in CASP hot wallets
the risk of liability is higher.
Under the non-custodial model, the obligation to repay is significantly limited.
Why the User Agreement is No Longer Absolute Protection
Even if terms and conditions:
- limit liability
- point out the risks
- exclude compensation
they cannot contradict the mandatory standards of MiCA and DORA.
Regulatory law takes precedence over contractual clauses.
How regulators and courts evaluate hacking
When analyzing an incident, the following are taken into account:
- compliance with safety standards
- the presence of internal policies
- speed reaction
- transparency of notifications
- compliance with regulatory requirements
PSAP are required to prove that they acted in good faith and professionally.
The role of insurance and reserves
MiCA stimulates:
- operational risk insurance
- formation of reserves
- compensation plans
- protecting clients from system failures
The absence of such mechanisms strengthens the user's position in the dispute.
What does this mean for users?
For clients this means:
- the emergence of a real protection tool
- possibility of regulatory complaints
- strengthening your position in negotiations
- reduction of strength asymmetry
- the need to record the circumstances of the hack
Passive acceptance of losses is no longer the only scenario.
What does this mean for CASP?
For crypto platforms:
- increase in operating costs
- the need to invest in security
- strengthening internal control
- increased demands on governance
- risk of sanctions and compensation
Formal compliance is becoming a dangerous strategy.
Common user misconceptions
Common Mistakes:
- the belief that the stock exchange is always irrelevant
- the belief that crypto is not protected by law
- ignoring regulatory complaints
- confusion between hacking and market risk
MiCA changes the balance in favor of the client, but not automatically.
Practical conclusion for investors and traders
It is important to understand:
- where exactly the assets are stored
- What is the status of the platform?
- does it fall under MiCA?
- How cybersecurity works
- What compensation mechanisms are provided?
The choice of CASP becomes a legal decision.
Сonclusion
In the EU, a hack of a crypto exchange no longer always means that the losses fall on the user.
In case of violation of the requirements of MiCA and DORA, CASP may be obliged to compensate for lost assets.
The key question is not whether a hack occurred, but Was the exchange legally and technically ready for it?.
Jurisprudential Consulting Group Advises clients on CASP liability, disputes with crypto platforms, and regulatory protection of investor rights in the EU.
