Synopsys, Inc. v. Sunlune Corporation is a federal lawsuit in the Northern District of California about electronic design automation (EDA) software. Synopsys, which licenses chip design tools, sued a chip design customer in January 2024. It alleged that the customer had used counterfeit licence keys to get around the licence key system and to run more copies of its licensed tools than it had bought, and to run a fourth tool that it had never been quoted. The court granted a temporary restraining order, a stipulated preliminary injunction and, after the defendant failed to appear through a lawyer, a default judgment of USD 27,500,000 and a permanent injunction.[1][4][6]
Background
According to the complaint, Synopsys does not sell its software. Customers buy licences that give limited rights to install and use specific programs, subject to a License Key System. A customer needs a licence key file to run each tool. The file names the customer, identifies the licensed software and sets the number of concurrent users permitted. Synopsys alleged that it is the only source of legitimate keys, and that the system can detect suspected piracy and report data such as an IP address or MAC address back to Synopsys, described as “Call-Home Data”.[1]
Sunlune, a privately held chip design company with one office in Santa Clara, California, signed an End-User Software License and Maintenance Agreement with Synopsys on 2023-02-17. The agreement is an overarching contract, and the specific tools, term and number of concurrent uses are set in separate purchase documents. Synopsys quoted 36-month licences for Fusion Compiler, HSPICE and PrimeLib on 2023-04-04, and Sunlune took licences for those three products on 2023-08-04. The complaint states that Sunlune never asked for or received a quotation for IC Compiler II.[1]
The dispute
Synopsys alleged that from about July 2023 until at least 2024-01-08, Sunlune used counterfeit licence keys to access more copies of Fusion Compiler, HSPICE and PrimeLib than its licences allowed, and used counterfeit keys to run IC Compiler II. It alleged over 11,000 instances of counterfeit keys operating under seven usernames.[1]
The complaint pleaded two claims. The first was circumvention of a technological measure that controls access to a copyrighted work, under 17 U.S.C. section 1201(a)(1) (the Digital Millennium Copyright Act, DMCA). The second was breach of the agreement, which the complaint said prohibits use of any licensed product beyond the licence rights and prohibits attempts to circumvent any licence key.[1]
Decision or outcome
- Temporary restraining order, 2024-01-25. Sunlune did not respond to the motion or appear at the hearing. Judge Beth Labson Freeman granted the order, which barred Sunlune from accessing, using, transferring or copying Synopsys software without authorisation. She noted that courts in the district had already held Synopsys’ licence key system to be a technological measure that effectively controls access, citing the InnoGrit case. A separate order granted expedited discovery.[2][3]
- Preliminary injunction, 2024-02-21. The parties stipulated to a preliminary injunction, which the court entered.[4]
- Pro se answer struck, 2024-04-23. Sunlune filed an answer signed by its chief executive. The court struck it because a corporation can appear only through a licensed attorney, and gave the company until 2024-05-23 to appear through counsel. Sunlune did not, a further pro se filing was struck, and the clerk entered default on 2024-06-06.[5]
- Default judgment, 2024-11-15. Synopsys sought relief only under the DMCA claim, and the court dismissed the contract claim without prejudice. A forensic expert’s declaration identified more than 15,000 acts of circumvention, but Synopsys limited its request to the 11,000 pleaded. The court awarded the maximum statutory damages of USD 2,500 per act, USD 27,500,000 in total, and a permanent injunction. It relied on the use of multiple counterfeit keys over multiple servers and devices over a substantial period, on circumvention that continued until April 2024 after the suit was filed, and on evidence that Sunlune deleted shell command history on seven servers the day after the restraining order. The court wrote that it could not “conceive of a more egregious violation” of the provision.[4][6]
- Motion to vacate denied, 2025-05-21. After a writ of execution for USD 27,700,395.78 issued in January 2025, Sunlune appeared through counsel and moved to vacate. The court denied the motion. It found culpable conduct by Sunlune and prejudice to Synopsys from the deleted evidence, and held that this was one of the rare cases where a default judgment should stand.[5]
- Later. On 2025-11-20 the court allowed Sunlune’s counsel to withdraw, and the docket shows further activity after that date.[7]
Because the judgment was entered by default, the court took the pleaded facts as true and Sunlune’s defences were never tested at trial.
Significance for software licensing and SAM practice
The points below are commentary on the court records.
- Overuse by key manipulation is a different category from overuse by miscounting. The complaint did not allege that Sunlune miscounted its seats. It alleged that counterfeit keys defeated the key system. That moves the dispute from a licence true-up to a circumvention claim with statutory damages, and the court’s own reasoning accepted that framing.[1][4]
- Telemetry and licence-server logs are the evidence. Synopsys relied on call-home data and then on forensic imaging of the customer’s servers. A licence server that logs which keys served which checkouts will be examined in the same way in any dispute. See software license audit.
- Timing mattered to the damages finding. The court noted that most acts of circumvention were in August 2023, the month the limited licences were signed, and treated that as a sign that the licence was entered with the intent to gain unauthorised access.[4]
- Conduct after notice. Deleting history files after a restraining order and expedited discovery was a stated ground for the maximum award and for refusing to vacate the judgment.[5]
- Related cases. Other Synopsys cases show the same pattern with different facts, see Synopsys v. InnoGrit and Synopsys v. Ubiquiti. For general practice see license compliance.
Lessons learned
- Using counterfeit licence keys to exceed purchased seats, or to run a product that was never licensed, is pleaded and treated as circumvention of an access control, not only as a contract overuse. The court’s analysis proceeded under the DMCA, and Synopsys elected not to pursue the contract claim.[1][4]
- Statutory damages under the DMCA are counted per act of circumvention, so an overuse that was logged thousands of times can produce a very large exposure. The range in the statute is USD 200 to USD 2,500 per act, and 11,000 acts at the maximum gave USD 27.5 million.[4]
- A company cannot answer a federal complaint without a lawyer, and deleting shell history or logs after a restraining order was cited as part of the grounds for the maximum award. Default followed from the missing counsel, and the spoliation evidence defeated the later request to vacate.[5]