According to reports from CoinWorld:
The White House has announced that the U.S. will allow vetted private companies to participate in offensive cyber operations against international criminal organizations and hackers for the first time. This arrangement is outlined in a recently released presidential memorandum, aimed at leveraging private sector capabilities to combat cyber threats targeting Americans, such as ransomware, financial fraud, and sexual extortion.
Executable Monitoring and Destructive Actions
The memorandum indicates that participating companies may engage in intelligence gathering, including monitoring using spyware, and may also execute destructive actions, such as destroying the data or systems of criminal organizations. However, this policy does not permit companies to conduct "reverse hacking" independently; such actions must still fall under the framework led by the federal government.
This marks a significant shift in the long-standing restrictions on private sector cyber attacks in the U.S. Under current federal computer intrusion laws, companies and individuals are generally prohibited from initiating cyber attacks or disruptive actions on their own. Previous administrations have maintained that the private sector can defend against attacks but cannot take proactive measures.
Participation Thresholds and Approval Requirements
According to the memorandum, the government will issue operational guidelines in the next two months, clarifying the conditions that participating companies must meet. The document states that the program will consider companies of various sizes, including smaller private firms that are better suited for executing specialized tasks.
Participating companies must pay a $1 million escrow bond. If the government determines that a company has violated the operational rules, this fund will be forfeited. The memorandum also requires the federal government to establish procedures to prevent any actions from targeting U.S. citizens or systems located within the U.S.
Each operation must be approved by representatives from the U.S. Department of Justice and the Department of Homeland Security and can only be carried out under federal government supervision. If participating companies detect urgent cyber attacks targeting U.S. critical infrastructure, they must immediately report to the government, with targets including power grids and water supply systems.
Legal Controversies and Rising External Risks
Reports indicate that this policy is still in its early stages, and the specific operational mechanisms have not yet been fully established, which may lead to legal challenges in the future. Opponents have long argued that private companies should not be involved in government-led hacking operations, as this could lead to diplomatic friction and even accusations from foreign governments of U.S. companies conducting cross-border attacks.
Cybersecurity professionals have also warned that U.S. citizens participating in such operations may face risks of prosecution, detention, or being classified as irregular combatants overseas. Even if such accusations are unfounded, the policy itself may provide foreign governments with grounds for criticism.
Background Pointing to Iran and AI Cyber Attacks
The Trump administration did not specify the exact reasons for this decision, only stating that Americans and U.S. businesses face an escalating cyber threat. Reports have noted that several states in the U.S. have recently reported cyber attacks on water supply infrastructure, with U.S. intelligence officials privately attributing some incidents to Iran-backed hackers.
Meanwhile, the U.S. and other countries are also dealing with a wave of automated cyber attacks driven by AI. Companies like Anthropic, OpenAI, Meta, and the UK AI Safety Institute have previously stated that cutting-edge models have breached technical limitations and executed cyber attacks during testing. This has further intertwined cybersecurity policy with AI risk governance.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.





























![[Editorial] The Rails Are Laid Before the World Notices](/public-static/8_1497610e7c.png?format=avif)