For a decade, I've opened every audit the same way: I follow the money. Not the press release, not the token price, not the founder's Twitter thread. The transaction hash. Sometimes it terminates in a flash loan. Sometimes in a reentrancy back door. And sometimes โ far more expensively, though far less visibly โ it terminates in a courtroom in London.
In 2018, Deutsche Bank filed suit in the High Court's Commercial Court against four former employees connected to the Banca Monte dei Paschi di Siena (BMPS) derivatives scandal. Milan's criminal courts had already answered the substantive liability question: Deutsche Bank and Nomura jointly owed compensation for the structured trades code-named "Alexandria" and "Santorini." The bank paid โ roughly โฌ70 million to Italian prosecutors in 2021, with total Italian exposure approaching โฌ110 million. Then it did something that should make every auditor in this industry pause. It reached into its own archaeology and sued the four men who executed the trades. The exploit wasn't a flash loan. It was a balance sheet. And the case now serves as the most detailed autopsy of institutional accountability that crypto has ever been offered โ free of charge, on someone else's legal budget.
The Context: An Old-World Bank, a New-World Lesson
For the segment of this industry that arrived after 2020, Monte dei Paschi is a relic: a Tuscan bank founded before Columbus sailed, which nearly collapsed under the weight of derivatives sold to it by Deutsche Bank and Nomura. The Alexandria and Santorini trades were long-dated, off-balance-sheet structures designed to massage solvency ratios. They worked until they didn't. By 2018, Milan's courts had assigned criminal and civil liability, and Deutsche Bank was on the hook for hundreds of millions.
The named defendants in London are senior: Michele Faissola, former global head of rates trading; Ivor Dunbar, a senior figure in the relevant structured business; and Michele Foresti, former head of structured rates trading, among others. The legal theories are the standard toolkit of English commercial litigation: breach of the duty of fidelity under the employment contract, fraudulent misrepresentation, conspiracy to injure, and restitution for unjust enrichment.
On its face, this is a bank seeking damages from former staff. Underneath the pleading, it is an elaborate exercise in liability transfer โ and it sits inside a regulatory architecture that has shifted, in less than a decade, from institution-level fines to individual accountability. The Senior Managers and Certification Regime (SM&CR), rolled out in 2016, replaced the old Approved Persons Regime and extended personal responsibility to a far wider cohort. The UK Supreme Court's 2017 decision in Ivey v Genting Casinos then redefined dishonesty for civil purposes: no longer a subjective-and-objective double test, but an objective standard applied to the defendant's actual state of knowledge. Read those two changes together, and you can see why Deutsche Bank filed this suit in London rather than Milan or Frankfurt.
I don't read legal complaints the way most analysts do. I read them the way I read vulnerable smart contracts: searching for the assumption that, if perturbed, cascades into failure. Here is what the teardown shows.
Core: The Systematic Teardown
1. The Forum Is the First Vulnerability
Jurisdiction is a risk-arbitrage play. Deutsche Bank had every right to pursue its former employees in Italy, where the underlying conduct occurred and where damage materialized. It chose London. London offers three structural advantages, and they are worth spelling out because each has a direct crypto analogue in the way protocols choose their dispute-resolution venues.
First, English disclosure rules are aggressive. A plaintiff in the Commercial Court can compel the production of internal documents, board minutes, compliance reviews, and email chains with a breadth that German or Italian procedure does not naturally provide. In crypto terms, this is the difference between auditing a protocol with a public block explorer and auditing one where the indexer is owned by the defendant. The bank wants access to its own historical record โ but as a forensic artifact, controlled by a court-sanctioned process.
Second, the Ivey standard objectively lowers the burden of proof on dishonesty. The bank no longer needs to prove that its former employees knew they were doing something wrong. It only needs to prove that, given what they knew, an ordinary honest person would have recognized the conduct as dishonest. That is a materially easier case to make โ and it explains the timing. Ivey was decided in 2017. The London suit was filed in 2018.

Third, and most cynically, London removes the bank from the Italian context entirely. In Milan, Deutsche Bank was a co-conspirator in the eyes of the court, not a victim. In London, the bank appears as an aggrieved employer whose trust was betrayed. Venue is a narrative tool. The defendants' lawyers know this, and they will fight any subsequent motion on exactly that ground.
2. The Passing-on Problem: A Confession in Two Acts
The single most damaging document in this case is not any trade ticket. It is the settlement agreement Deutsche Bank signed with Italian prosecutors in 2021. The bank paid approximately โฌ70 million to resolve criminal allegations tied to the very same transactions it now blames on its employees. It paid additional sums to civil claimants. That is not the behavior of an institution that believed at the time that four rogue bankers were solely responsible. It is the behavior of an institution buying its way out of its own structural exposure.
Under English agency law, the defense has a sharp argument available: a principal that ratifies the acts of its agent cannot later sue that agent for losses arising from those acts. If Deutsche Bank, through its management and compliance functions, approved or acquiesced in the Alexandria and Santorino structures โ and the settlement payments are powerful evidence of acquiescence โ then the subsequent claim against Faissola, Dunbar, and Foresti is, in substance, an attempt to evade the consequences of its own ratification. The court will be asked to determine where the institution's knowledge ended and the individual's fraud began. That line is not a bright one. In complex financial structures, it is a blur.
This is what I mean when I say the bank's "unclean hands" doctrine matters. An auditor's standard test: would the plaintiff pass a basic due-diligence screen? Here, the historical record is damning. Deutsche Bank has paid billions over the past decade โ for LIBOR manipulation, for sanctions violations, for its role in the 1MDB scandal. The BMPS matter sits inside that pattern. A pattern is not an isolated bug; it is a design flaw. The defendants will present the bank's own compliance history as evidence that the culture, not the individual, was the root cause. The "exploit" here was organizational, and no amount of forum-shopping can refactor that.
3. Evidence Hygiene: Where the Ledger Failed
My own experience tracing the Terra/Luna collapse in 2022 involved identifying the exact block where the liquidity pool drained. The blockchain remembers, but the auditors forget โ and the underlying ledger never lies. That is the luxury of on-chain forensics: every action leaves a trace, immune to selective memory.
Deutsche Bank has no such ledger. It has email servers, Bloomberg chats, risk reports, and a compliance function that apparently had ample opportunity to raise alarms about BMPS-related trades and did not. The suit forces the bank to open its internal evidence-management systems to judicial scrutiny โ and the exposure cuts both ways. If the bank had excellent surveillance systems and failed to act on their outputs, that is negligence at the institutional level. If it lacked the systems, that is a governance failure of a different order. Either way, in court, the bank's own technical infrastructure becomes an exhibit for the defense. This is why the case is a gift to RegTech vendors: the transaction-monitoring and e-discovery gaps it exposes are precisely the weaknesses that better tooling claims to fix. But tooling doesn't fix culture.
Standardization fails when it ignores human chaos. A compliance checklist that gets signed off by the wrong layer of management is not a control. It is a liability-shaped object. The Alexandria and Santorini trades were engineered precisely to evade the visual inspections banks rely on. That is not a coding flaw. It is a human one.
4. The Ivey Standard as a Protocol Specification
Let me be precise about what Ivey v Genting Casinos did. It rewrote the definition of dishonesty for civil fraud claims. The test now runs as follows: establish the defendant's actual state of knowledge or belief; then compare that cognition against the standard of an ordinary decent person. It no longer requires the defendant to have appreciated, at the time, that their conduct was dishonest.
The discipline this imposes is meaningful. In crypto terms, Ivey is a state-machine transition: input your knowledge state, apply the honest-person predicate, output dishonesty. It strips out the subjectivity that makes fraud cases so expensive to litigate. And it has an uncomfortable consequence for the bank. The same objective standard can be applied to the bank's executives who approved the structures. If an ordinary honest person would have paused at the risk reports, then the failure is institutional โ and the Ivey test, far from being a weapon solely for the plaintiff, becomes a tool for the defense to redirect liability upward.
This is the hidden architecture of the case. The bank chose a legal framework that lowers the bar for personal accountability, without pausing to consider that the framework would also apply to its own decision-makers. That is a classic audit error: modeling your adversary's constraints without modeling your own.
5. The Insurance Lever and the Settlement Trap
There is another strategic layer visible only from the inside. Standard D&O insurance policies exclude coverage for fraud and intentional misconduct. If Deutsche Bank's former employees are named in a suit alleging fraudulent misrepresentation, their insurance coverage may be void โ meaning their legal fees come out of pocket. That is a massive settlement lever. A defendant facing an expensive, multi-year trial without insurance backing is a defendant who settles. Several of the original defendants have already resolved their claims, and the pattern suggests strategic concession rather than vindication. The bank may be willing to accept quiet settlements with some defendants in exchange for a public judgment that establishes precedent against the rest.
But here is the trap. A settlement is not a verdict. If the case ends in confidential resolution โ as many of these matters do โ the market loses the evidentiary record. The blockchain remembers, but the settlement agreement, by design, forgets. No public judgment means no binding precedent, no disclosure of the bank's internal review, and no answer to the question regulators and investors actually care about: was this a handful of bad actors, or was this the institution?
The Contrarian Angle: What the Bulls Got Right
Now for the uncomfortable part. The bull case for this kind of litigation is not entirely wrong โ and crypto should hear it.
Take SM&CR seriously. Whatever its flaws, the UK's individual-accountability regime has materially raised the cost of misbehavior for senior finance professionals. Certification, fitness-and-propriety assessments, and the prospect of personal enforcement are not theater. They are incentives. When a bank sues its own employees, it is borrowing the authority of that regime to deal with its own past โ and that is a form of accountability, even if impurely motivated.
Similarly, Ivey's objective dishonesty test represents a genuine advance in legal technology. It removes the defendant's self-serving testimony as the lodestone of intent. It asks, simply: what would an honest person, with this knowledge, have done? For an industry that complains about the difficulty of proving fraud, the standard is a gift.
Crypto has no equivalent machinery. Our accountability mechanisms are weaker: DAO contributors sign no fidelity contracts; protocol designers embed disclaimers instead of personal liability; auditors publish warnings, not guarantees. When a protocol collapses, the founders rarely face personal consequences on the same scale as a London fraud suit. Logic is binary; trust is a spectrum. The blockchain can prove a transaction, but it cannot prove a state of mind. That is a real limitation โ and the banks have caught up on exactly this dimension.
The flaw in the bull case is the assumption that litigation produces truth. It produces outcomes โ usually settlements. Deutsche Bank's suit is already functioning as a regulatory risk-management tool: by suing its employees, the bank can demonstrate to the FCA's individual-accountability enforcement team that it is serious about internal accountability. The suit is a signal, not a solution. A trial might have exposed the real distribution of blame. A settlement buries it. The bull case collapses into the same structural problem that plagues all institutional accountability: the incentives favor resolution over revelation.
Takeaway: Read the Docket, Not the Press Release
The next eighteen months will determine whether this case produces a judgment or a whisper. If Deutsche Bank continues the pattern of strategic settlements, the accountability signal dissipates. If a court rules on the merits, the cascade will be felt far beyond Frankfurt: D&O markets will reprice, employment contracts will grow clawback clauses, and the SM&CR's personal-liability framework will become the template for banks worldwide.
My advice to crypto teams is unglamorous. Study this case the way you would study a high-severity vulnerability. Codify personal liability in contributor agreements. Require professional indemnity for core engineers. And understand that no immutability is absolute: the people you work with are later liable for what they signed, regardless of where the tokens moved. In code, silence is the loudest vulnerability โ and in this litigation, the silence is a settlement clause, drafted by lawyers, witnessed by nobody, and designed to make โฌ70 million worth of institutional responsibility disappear. The question is not whether Deutsche Bank wins or loses. The question is whether anyone will ever know what actually happened inside that bank โ and whether the people who watch from this industry will build something better before they are forced to explain their own Alexandria on the stand.