ADVERTISEMENT

Events

IAMTN Annual Summit 2026
14 Oct 26
London
Money20/20 USA 2026
18 Oct 26
Las Vegas

Fiduciary Duty in a World Without Intermediaries

For centuries, financial systems have relied on intermediaries standing between people and their money. A bank holds deposits while a broker executes trades. These relationships create a basic legal expectation: if you’re given power over another person’s money, you may owe that person duties of care and loyalty.  

Crypto was designed to eliminate that premise. Users can hold their own private keys and trade through a smart contract instead of relying on a broker. The same logic applies to Decentralized Autonomous Organizations (DAOs), where people manage financial products collectively rather than through a single institution. That raises a difficult legal question: if there is no obvious intermediary, who then is responsible when something goes wrong?

The answer is becoming increasingly important as regulators and courts confront fiduciary duty in DeFi, self-custody, and decentralized governance.

Image showing The core fiduciary duties - on DeFi Planet

Why Fiduciary Relationships Exist

A fiduciary relationship exists when one person has accepted a position where another person reasonably depends on them to act in that person’s interests. The classic example is a trustee managing money for beneficiaries; the trustee cannot secretly use the assets for personal gain simply because the beneficiary cannot see what happens behind the scenes.

The law therefore imposes a demanding standard of loyalty, requiring good faith and the avoidance of conflicts between personal interests and the interests of the person being served.

This is why fiduciary law matters in finance. It is designed for situations where power and vulnerability are unequal. The problem is that DeFi deliberately tries to remove that relationship. A smart contract doesn’t promise to look after anyone, and a liquidity pool doesn’t care about anyone’s financial situation. A DAO may have thousands of token holders who never know each other, raising the strange possibility that no one owes fiduciary responsibility even when someone’s actions can devastate other people’s assets.

Can a DAO Really Be Responsible?

Image showing DAO Use Cases - on DeFi Planet

A DAO is often presented as a community governed by code and token voting, but courts are increasingly refusing to assume that calling something “decentralized” makes legal responsibility disappear, and one of the clearest warnings came from the CFTC’s case against Ooki DAO. 

In 2023, a federal court entered default judgment against Ooki DAO after finding that the DAO operated a platform offering retail commodity transactions without complying with the Commodity Exchange Act. The court treated the DAO as a defendant capable of being held legally responsible.

That case did not establish that every DAO owes fiduciary duties, but it did establish something more basic but extremely important: putting an organization on a blockchain does not automatically place it outside the legal system. The bZx DAO litigation provides another useful example.

Users sued the bZx DAO and related parties after a security incident caused roughly $55 million in losses. In 2023, the federal court allowed negligence claims against the DAO to proceed and found that the plaintiffs had sufficiently alleged that the DAO owed them a duty to exercise reasonable care in managing the protocol’s security.

A duty of care is not automatically a fiduciary duty, as fiduciary obligations normally demand a deeper relationship involving loyalty and the acceptance of responsibility for another person’s interests. Recent litigation shows how unsettled this area remains, and in a 2026 Delaware case involving the ICHI protocol and oneTokens, the court rejected a claimed fiduciary-duty basis because the allegations described an arm’s-length commercial relationship rather than an accepted position of trust. So the emerging lesson is not that DAOs automatically become fiduciaries but that courts are examining what a DAO actually does rather than accepting decentralization as a legal shield.

Protocol Designers as Fiduciaries?

Imagine a team controls the software that billions of dollars depend on, where the developers can change the code, publish upgrades, or sometimes influence how the system responds to a crisis. Are they simply programmers, or could they become protocol designers as fiduciaries?

The Tulip Trading case brought this question into the open. The claimant, Tulip Trading Limited, is a Seychelles-registered company controlled by Dr Craig Wright, who has spent years claiming in courts around the world to be Satoshi Nakamoto, Bitcoin’s pseudonymous creator. Tulip claimed the developers behind several Bitcoin-related networks owed it a duty after losing access to roughly $4 billion in Bitcoin following an alleged hack of Wright’s home computer system, one that removed the private keys needed to control the funds. Tulip argued the developers, given their control over the relevant networks, could implement a software patch to help recover the assets, and that failing to do so amounted to a breach of duty.

The High Court initially rejected the argument that the alleged facts gave rise to a duty of care, but the Court of Appeal later held that the claim raised a serious issue that should not have been dismissed at that stage. It did not finally declare that Bitcoin developers are fiduciaries, but instead, it recognized that the relationship raised a sufficiently serious legal question for further consideration.

If a small group has continuing control over software, users depend heavily on that control, and those developers exercise meaningful discretion over other people’s property, the argument becomes harder to dismiss. Academic and law-reform work is now examining precisely this question, including whether software developers and DAO participants can owe these obligations.

What About Wallet Providers?

A self-custodial wallet generally means the user controls the private key, the provider does not hold the assets in the way a bank holds a customer’s deposit. If you lose the key, the wallet company may be unable to recover your funds, which is the basic bargain behind self-custody and duty of care. You gain control, but you also accept responsibility.

The SEC’s 2026 staff statement distinguishes self-custodial wallets from arrangements where a provider possesses or controls customer assets. It describes a genuinely self-custodial wallet as one where the provider cannot access the user’s private key or independently initiate, reverse, or block transactions, which is why self-custody is not simply a technical feature but a redistribution of responsibility.

If a bank loses your money because of an internal failure, legal and regulatory mechanisms may provide compensation, but if you approve a malicious smart contract transaction from your own wallet, the situation can be radically different. Without an intermediary, no one may stand between you and the consequences.

Self-Custody Does Not Mean Everyone Is Off the Hook

This does not mean users should accept every loss as their own fault, as there is a major difference between voluntarily accepting the risks of self-custody and being misled by a company controlling the interface through which that self-custody operates.

Suppose a wallet clearly tells you that you are signing a transaction worth $100, but the software secretly changes the transaction to transfer $10,000. Calling the wallet “non-custodial” should not automatically settle the legal question. 

The relevant question may become: who controlled the software, what did they promise, what information did they provide, what could they reasonably have prevented, and how much did users depend on them? That is a much more useful framework than simply asking whether the protocol is decentralized.

Regulation Is Rebuilding Some Intermediaries

Regulators appear to be moving in this direction; the UK’s new crypto regime is particularly interesting. The FCA published its final crypto rules in June 2026, with the broader regime expected to come into force on 25 October 2027. The FCA says DeFi will be assessed case by case where there is an identifiable controlling entity, with future guidance expected to address indicators of decentralization, operational resilience and financial-crime risks.

This is effectively an attempt to answer the intermediary problem without pretending every blockchain is a bank. The question becomes whether someone has enough control, responsibility or influence to justify regulation and which approach could eventually shape who owes fiduciary duty in P2P systems.

A genuinely peer-to-peer system where neither party controls the other may not create the same relationship as a platform that selects transactions, controls information, sets rules and earns fees from users. The word “P2P” therefore tells us surprisingly little about legal responsibility.

The Real Future of Fiduciary Duty in DeFi

The most likely future is not that every developer, token holder, or wallet company becomes a fiduciary; that would make decentralized software almost impossible to operate. Nor is it realistic to assume everyone can escape responsibility simply because the software uses a blockchain; a more practical approach is to examine power, control, dependence, and promises that could shift responsibilities.

A developer who publishes open-source code and has no continuing control looks very different from a company that secretly controls upgrade keys. A DAO with thousands of independent participants looks different from a small group that controls governance while presenting the system as decentralized, and a wallet that merely stores a private key looks different from an interface that recommends investments and routes transactions.

This is ultimately what the debate over fiduciary duty in DeFi is about: crypto removed many traditional intermediaries, but it did not remove power relationships because someone still writes the code. Someone controls the interface, governs the treasury, decides which proposal reaches a vote, and profits from users’ activity.

And that may produce the most important principle for decentralized finance: removing the middleman does not necessarily remove responsibility. It may simply make responsibility harder to identify.

Disclaimer: This article is intended solely for informational purposes and should not be considered trading or investment advice. Nothing herein should be construed as financial, legal, or tax advice. Trading or investing in cryptocurrencies carries a considerable risk of financial loss. Always conduct due diligence.

Enjoyed this? Bookmark DeFi Planet, explore related topics, and follow us on Twitter, LinkedIn, Facebook, Instagram, Threads, and CoinMarketCap Community for seamless access to high-quality industry insights.

Take control of your crypto portfolio with DEFI PLANET PRO, DeFi Planet’s suite of analytics tools.

ADVERTISEMENT
ADVERTISEMENT

Spotlight

ETH $2,733.00 +0.56% POLY $792.15 +0.00% APE $748.09 +0.00% FET $226.49 +0.00% GTC $2,668.91 +0.00% LINK $12.92 +1.69% BTC $85,932.39 +2.02% UNI $8.87 -0.80% PERP $47.36 +0.00% QNT $68.24 +9.69% ETH $2,733.00 +0.56% POLY $792.15 +0.00% APE $748.09 +0.00% FET $226.49 +0.00% GTC $2,668.91 +0.00% LINK $12.92 +1.69% BTC $85,932.39 +2.02% UNI $8.87 -0.80% PERP $47.36 +0.00% QNT $68.24 +9.69%
-
00:00
00:00
Update Required Flash plugin
-
00:00
00:00