A new White House directive allowing private U.S. companies to conduct offensive cyber operations against foreign criminal hackers is tightly controlled and should not be read as a vigilante license, according to two crypto lawyers who discussed the Aug. 12 presidential memorandum on the DEX in the City podcast.

The memo establishes a National Coordination Center that would run a program for vetted private firms to conduct surveillance and disruptive cyber effects against foreign criminal hacking groups, with government approval and supervision for each operation. Foreign state hackers and groups acting at a government's direction are excluded. Legal analysts have described it as the first U.S. authorization of private-sector offensive cyber operations.

Jane Khodarkovsky, a financial integrity and sanctions expert and former government official, pushed back on the idea that companies would be free to act on their own. Participants will be overseen by the government and effectively become agents of the government, she said. The program requires a $1 million bond or escrow that can be forfeited for breaking the agreement, and approvals are controlled by two executive directors, one from the Justice Department and one from the Department of Homeland Security.

Operations that the government judges likely to cause loss of life or serious injury, or that would amount to a use of force under international law, are barred. Companies must comply with U.S. and international law and get authorization before acting against U.S. persons or systems. Khodarkovsky noted the program includes a 60-day period to develop processes and procedures and annual assessments of whether companies are adhering to them.

Jacob Robinson, host of the Law of Code podcast, framed the program as a modern equivalent of privateering, with cyber letters of marque allowing vetted operators to go after criminals, especially on blockchains. He called it a major step in the right direction if implemented carefully. He cited the roughly $280 million Drift Protocol exploit earlier this year, in which much of the stolen funds moved as Circle's USDC. Robinson said people wanted Circle to freeze the assets, but Circle faces significant legal risk in doing so without a court order or government mandate.

Jessi Brooks, general counsel of Ribbit Capital, was more cautious. She agreed the concept of bringing in the private sector is probably good, but said the devil will be in the details. She warned that without enough technical experts inside the government to supervise the program, otherwise it's just people out there hacking. She also noted the memo does not repeal the Computer Fraud and Abuse Act, leaving the legal boundaries for deputized companies unclear.

Much of the program remains unwritten. Operating procedures are due within 60 days, a status report within 180 days, and a classified annex on intelligence sharing with private companies could be as consequential as the public text, Khodarkovsky said.