Meghji v. Spadafora

United States Bankruptcy Court, S.D. New York·Decided May 6, 2025·No. 24-03981·Unknown

Opinion

UNITED STATES BANKRUPTCY COURT SOUTHERN DISTRICT OF NEW YORK

In re: NOT FOR PUBLICATION

CELSIUS NETWORK LLC, et al., Case No. 22-10964 (MG)

Post-Effective Date Debtors. Chapter 11

MOHSIN Y. MEGHJI, as Representative for the Post-Effective Date Debtors,

Plaintiff, Adv. Pro. No. 24-03981 (MG)

v.

CHRISTOPHER SPADAFORA and CLOUDFLARE, INC.,

Defendants.

MEMORANDUM OPINION AND ORDER DENYING CLOUDFLARE MOTION TO DISMISS A P P E A R A N C E S: MAYER BROWN LLP Attorneys for Defendant Cloudflare, Inc. 1221 Avenue of the Americas New York, New York 10020 By: Matthew D. Ingber, Esq. Niketa K. Patel, Esq. Joaquin M. C de Baca, Esq. David Yolkut, Esq.

WHITE & CASE LLP Attorneys for Representative of Post-Effective Date Debtors 1221 Avenue of the Americas New York, NY 10020 By: Joshua D. Weedman, Esq. Samuel P. Hershey, Esq. Renza Demoulin, Esq. MARTIN GLENN CHIEF UNITED STATES BANKRUPTCY JUDGE Pending before the Court is the motion to dismiss (the “Motion,” ECF Doc. # 7) of Cloudflare, Inc. (“Cloudflare” or the “Defendant”) seeking entry of an order dismissing all claims asserted against it in the Complaint (the “Complaint,” ECF Doc. #1) filed by Mohsin Meghji ( “Litigation Administrator” or the “Plaintiff”), in his capacity as Litigation Administrator of the estates of the above-captioned debtors and debtors-in-possession (collectively, the “Debtors,” and together with their non-Debtor affiliates “Celsius” or the “Company”) appointed pursuant to the Modified Joint Chapter 11 Plan of Reorganization of Celsius Network LLC and its Debtor Affiliates (the “Plan”). Annexed to the Motion are (i) a

proposed order granting the Motion as Exhibit A; and (ii) a memorandum of law in support of the Motion (ECF Doc. # 8). The Plaintiff filed a memorandum of law in opposition to the Motion (the “Opposition,” ECF Doc. # 16). Cloudflare filed a memorandum of law in further support of the Motion (the “Reply,” ECF Doc. # 21). For the reasons discussed below, the Court: DENIES Cloudflare’s Motion to Dismiss.1 I. BACKGROUND A. The Complaint The Complaint asserts two causes of actions against Defendant Cloudflare, Inc.: (i) negligence and (ii) gross negligence, both arising from an alleged failure to maintain adequate cybersecurity protections related to the issuance and management of API keys for the

BadgerDAO platform. (Complaint ¶ 80-94.)

1 The Court already entered a Memorandum Opinion and Order Denying the motion to dismiss of co- defendant Christopher Spadafora. See Meghji v. Spadafora, 2025 WL 1232578 (MG)(Bankr. S.D.N.Y. April 28, 2025). 1. First Cause of Action: Negligence Celsius first alleges that Cloudflare’s conduct constituted negligence. Celsius alleges that Cloudflare owed a duty to BadgerDAO and all its governing members, including Celsius, to implement adequate security protocols for the issuance of API keys granting access to

BadgerDAO’s API. (Id. ¶ 81.) This duty allegedly arose from Cloudflare’s agreement to secure access to accounts containing sensitive passphrases like API keys. (Id. ¶ 82.) There was a flaw in Cloudflare’s system that initially went unnoticed but was eventually fixed. (Id. ¶ 84.) Celsius claims that all BadgerDAO members, including Celsius, reasonably expected Cloudflare to warn users if a vulnerability may have compromised their sensitive information prior to the flaw being remedied. (Id.) However, Cloudflare did not issue such a warning. (Id.) Accordingly, Celsius claims that Cloudflare breached its duty to BadgerDAO and Celsius by issuing API keys prior to proper account verification and by failing to notify users of the vulnerability after it was discovered. (Id. ¶ 85.) Celsius further alleges that this breach was the proximate and but-for cause of Celsius’

injury. (Id. ¶ 86.) Specifically, the Complaint asserts that a hacker was able to gain unauthorized access to BadgerDAO’s systems by obtaining an API key in mid-September and remained undetected for over two months, ultimately executing a first fraudulent transfer of funds on November 20, 2021. (Id.) As a result, Celsius asserts that Cloudflare’s failure to exercise the degree of care required by industry standards and by a reasonably prudent person under similar circumstances constitutes negligence and caused Celsius to lose more than $50 million in assets stored on the BadgerDAO platform. (Id. ¶ 87-88.) 2. Second Cause of Action: Gross Negligence Celsius further alleges in the second cause of action that Cloudflare’s conduct constituted gross negligence. The Complaint asserts that Cloudflare breached its duty to Celsius when it failed to remedy the known vulnerability in its systems, which created an unreasonable risk of

harm to all users of BadgerDAO, including Celsius. (Id. ¶ 92.) Specifically, Cloudflare had been informed of this vulnerability and was aware that it allowed malicious actors to potentially access the developer-end or API of its clients’ platforms—many of which, like BadgerDAO, were used to safeguard significant sums of customer funds. (Id.) By failing to immediately remedy the vulnerability, and by subsequently failing to notify users that their APIs, and therefore their funds, might have been compromised, Cloudflare created an unreasonable risk of harm to its users, including BadgerDAO, and in turn, to BadgerDAO’s users, including Celsius. (Id.) Cloudflare’s failure to act was therefore grossly negligent. (Id. ¶ 93.) As a result of Cloudflare’s alleged breach and its failure to exercise even slight care or diligence in fixing a known issue that had been reported on multiple occasions or notifying

BadgerDAO of a vulnerability, Celsius claims it has suffered damages, amounting to over $50 million in assets, following the hack of the BadgerDAO platform. (Id. ¶ 94.) B. The Cloudflare’s Motion to Dismiss Cloudflare filed the Motion to dismiss all claims asserted against it in the Complaint. (Motion at 1-2.) Cloudflare argues that Celsius fails to state both a negligence claim and a gross negligence claim. (Id.) Cloudflare argues that it owes no legal duty to Celsius, as there was no direct relationship, contract, or special connection between them. (ECF Doc. #8 at 16-21.) This absence of relationship, Cloudflare alleges, is fatal to the negligence claim. (Id. at 16.) Cloudflare claims that New York law recognizes an exception to the general rule that there is no duty to protect others from injuries caused by third parties if there is a special relationship exists, either between either between defendant and a third-person tortfeasor that encompasses defendant’s actual control of the third person’s actions, or between defendant and plaintiff that

requires defendant to protect plaintiff from the conduct of others. (Id. at 20.) Cloudflare claims Celsius failed to allege either form of special relationship as Cloudflare had no contacts or dealings either with the criminal hackers or with Celsius. (Id.) Furthermore, Cloudflare claims Celsius failed to allege any breach by Cloudflare because it has failed to plausibly allege that Cloudflare owed it any duty of care. (Id. at 23.) Celsius’ negligence claim fails for the additional and independent reason, Cloudflare argues, that Plaintiff’s allegations on causation are “reed-thin,” and that certain actions by BadgerDAO, third-party hackers, or Celsius are intervening causes to Cloudflare’s breach. (Id. at 24-25.) Cloudflare further contends that Celsius’ gross negligence claim fails for the same reasons as its ordinary negligence claim, and additionally lacks the heightened culpability

Free access — add to your briefcase to read the full text and ask questions with AI

Meghji v. Spadafora, (N.Y. 2025).

Meghji v. Spadafora (Meghji v. Spadafora) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related

Bell Atlantic Corp. v. Twombly
550 U.S. 544 (Supreme Court, 2007)
Ashcroft v. Iqbal
556 U.S. 662 (Supreme Court, 2009)
Kiobel v. Royal Dutch Petroleum Co.
621 F.3d 111 (Second Circuit, 2010)
Farash v. Continental Airlines, Inc.
574 F. Supp. 2d 356 (S.D. New York, 2008)
Hamilton v. Beretta U.S.A. Corp.
750 N.E.2d 1055 (New York Court of Appeals, 2001)
Lauer v. City of New York
733 N.E.2d 184 (New York Court of Appeals, 2000)
Hamilton v. Accu-Tek
62 F. Supp. 2d 802 (E.D. New York, 1999)
Abacus Fed. Sav. v. Adt SEC.
967 N.E.2d 666 (New York Court of Appeals, 2012)
In Re Methyl Tertiary Butyl Ether (Mtbe) Products
739 F. Supp. 2d 576 (S.D. New York, 2010)
Colnaghi, U.S.A., Ltd. v. Jewelers Protection Services, Ltd.
81 N.Y.2d 821 (New York Court of Appeals, 1993)
Abacus Federal Savings Bank v. ADT Security Services, Inc.
967 N.E.2d 666 (New York Court of Appeals, 2012)
Eiseman v. State
511 N.E.2d 1128 (New York Court of Appeals, 1987)
Abacus Federal Savings Bank v. ADT Security Services, Inc.
77 A.D.3d 431 (Appellate Division of the Supreme Court of New York, 2010)
Rand & Paseka Mfg. Co. v. Holmes Protection, Inc.
130 A.D.2d 429 (Appellate Division of the Supreme Court of New York, 1987)
Hanover Insurance v. D & W Central Station Alarm Co.
164 A.D.2d 112 (Appellate Division of the Supreme Court of New York, 1990)
Hamilton v. Beretta U.S.A. Corp.
264 F.3d 21 (Second Circuit, 2001)