Approximately $71 million in ether recovered from the largest DeFi exploit of 2026 is now the subject of a federal court battle in Manhattan that could define how U.S. law treats stolen and recovered cryptocurrency. On one side: Aave LLC and a coalition of DeFi protocols seeking to return 30,765 ...
"A thief does not gain lawful ownership of stolen property simply by taking possession of it." — Aave LLC, Emergency Motion Filing, SDNY Case No. 1:26-cv-03841 (May 5, 2026)
Approximately $71 million in ether recovered from the largest DeFi exploit of 2026 is now the subject of a federal court battle in Manhattan that could define how U.S. law treats stolen and recovered cryptocurrency. On one side: Aave LLC and a coalition of DeFi protocols seeking to return 30,765 ETH to exploit victims. On the other: three groups of terrorism judgment creditors holding $877 million in unpaid damages against North Korea, who argue the funds constitute North Korean state property because the April 18 KelpDAO hack has been attributed to the Lazarus Group.
The case, pending before Judge Margaret M. Garnett in the Southern District of New York, forces a collision between DeFi's self-help recovery mechanisms and the enforcement machinery of the Foreign Sovereign Immunities Act (FSIA) and the Terrorism Risk Insurance Act (TRIA). Arbitrum DAO voted on May 8 with over 90% support to release the frozen ETH to a recovery consortium, but an eight-day Constitutional AIP delay gives the court a window to block the transfer. The outcome will set precedent for whether recovered hack proceeds can be intercepted by third-party creditors before victims are made whole.
On April 18, 2026 at 17:35 UTC, an attacker exploited a vulnerability in KelpDAO's LayerZero V2 bridge infrastructure. The exploit allowed the minting of 116,500 unbacked rsETH — approximately 18% of the token's circulating supply — by forging a message that tricked Ethereum's OFT adapter into releasing tokens without corresponding burns on the source chain. No underlying ETH changed hands. The tokens were, in effect, created out of nothing.
The attacker deposited 89,567 rsETH into Aave V3 as collateral and borrowed approximately $190 million in ETH and related assets across Ethereum and Arbitrum markets. Additional positions were opened on Compound V3 and Euler. Total debt positions exceeded $236 million across multiple lending venues.
The exploit triggered immediate contagion. Aave's total value locked dropped from $26.4 billion to approximately $20 billion within 48 hours. Over a 3.5-day window, Aave lost $15.1 billion in deposits, falling from $48.5 billion to $30.7 billion as suppliers withdrew funds. The AAVE token fell 18% within 24 hours. DeFi-wide total value locked declined by more than $13 billion in two days, according to CoinDesk reporting.
Bad debt estimates for Aave ranged from $124 million (if losses were shared across all rsETH holders) to $230 million (if concentrated on Layer 2 networks), with Aave-specific bad debt settling at approximately $196 million concentrated in the rsETH-wrapped ether pair on Ethereum.
KelpDAO subsequently blamed LayerZero for approving the bridge configuration that was exploited. KelpDAO has since migrated to Chainlink's CCIP infrastructure.
On April 20 at 11:26 PM ET, Arbitrum's Security Council executed an emergency freeze, transferring 30,766 ETH linked to the exploit into a frozen intermediary wallet accessible only through further governance action. The council stated it acted with "input from law enforcement as to the exploiter's identity" and that the freeze was executed "without impacting any Arbitrum users or applications."
The frozen funds represented roughly one-quarter of the total amount drained. A recovery coalition branded "DeFi United" — comprising Aave, KelpDAO, LayerZero, EtherFi, Compound, Lido, and Ethena — formed to coordinate restitution. The Babylon Foundation committed $3 million in USDT to Aave lending pools as part of stabilization measures. The coalition's stated goal: fully re-collateralize rsETH and compensate affected depositors.
By early May, Aave completed liquidation of the hacker's remaining rsETH-backed loans on both Ethereum and Arbitrum, providing clearer visibility on outstanding bad debt.
On May 1, 2026, attorney Charles Gerstein of Gerstein Harrow LLP served a restraining notice on Arbitrum DAO in the Southern District of New York. Gerstein represents three sets of judgment creditors holding a combined $877 million in unpaid damages awards against North Korea, arising from cases litigated between 2010 and 2016.
The underlying judgments relate to:
The legal theory combines the Foreign Sovereign Immunities Act (FSIA) and the Terrorism Risk Insurance Act (TRIA), which together permit judgment creditors of a state sponsor of terrorism to attach property held by the regime or its agencies and instrumentalities. The plaintiffs argue that:
The plaintiffs further characterized the exploit as "fraud rather than theft," a legal distinction that could affect property ownership analysis under New York law. Under a theft framework, the victim retains title. Under a fraud framework, the property may pass to the defrauding party, making it attachable by that party's creditors.
On May 5, Aave LLC, represented by Morrison Cohen LLP, filed a 29-page emergency motion before Judge Garnett seeking to vacate the restraining notice. The filing advanced three alternative requests:
Aave's core legal argument: a thief does not acquire lawful ownership of stolen property by taking possession of it. Property recovered from a thief during a theft remains the victim's property. Therefore, the frozen ETH belongs to Aave's depositors — the exploit victims — not to North Korea or any entity whose assets can be attached by terrorism creditors.
Aave further argued that the plaintiffs offered "no admissible evidence beyond internet-post hearsay opinions" connecting the attacker to their specific judgment debtor. Attribution to the Lazarus Group, even if accurate, does not automatically establish that the DPRK regime itself — the named judgment debtor — holds a property interest in the funds.
The filing warned that maintaining the freeze could "deepen losses and destabilize DeFi markets already strained by the exploit, increasing the likelihood of cascading liquidations, sustained liquidity outflows, and irreversible changes to user positions."
Judge Garnett scheduled a remote hearing for May 6 at 11:00 AM. As of publication, no public ruling from that hearing has been confirmed.
On May 8, Arbitrum's on-chain governance vote closed with decisive results: 90.5% of participating tokens (173.9 million ARB) voted in favor of releasing the 30,765 ETH to DeFi United for victim restitution. Only 1,700 ARB tokens (less than 0.01%) voted against. The remaining 18.1 million tokens (9.4%) abstained.
The funds are earmarked for the coordinated industry recovery effort led by Aave, KelpDAO, LayerZero, EtherFi, and Compound.
However, the vote does not trigger immediate transfer. Because the proposal was structured as a Constitutional AIP under Arbitrum's governance framework, an eight-day delay is mandatory before execution. This delay — intended as a safeguard against governance attacks — now serves a different function: it gives the Manhattan federal court time to issue an order blocking the transfer before the ETH moves.
The proposal includes indemnification protections, an unusual provision that highlights the legal uncertainty surrounding the release. Arbitrum's governance participants are, in effect, voting to release funds that a U.S. court may order them not to release.
The economic toll extends beyond the $71 million in frozen ETH:
| Metric | Figure | |---|---| | Total exploit value (KelpDAO) | $292 million | | Aave-specific bad debt estimate | $124–230 million | | Aave TVL decline (48 hours) | $6.6 billion | | Aave deposit outflow (3.5 days) | $15.1 billion | | DeFi-wide TVL decline (2 days) | $13+ billion | | AAVE token decline (24 hours) | -18% | | Frozen ETH under dispute | 30,765 ETH (~$71 million) | | Terrorism creditor claims | $877 million | | Aave's requested bond if freeze maintained | $300 million |
The $71 million in frozen ETH represents a fraction of total losses but carries disproportionate systemic importance. It is the largest identifiable recovery pool and the centerpiece of DeFi United's restitution plan. If diverted to terrorism creditors, the coalition's ability to make depositors whole diminishes materially, and the signal it sends — that recovered hack proceeds are subject to third-party seizure — would alter the risk calculus for every future DeFi recovery effort.
From an economic value perspective, the case exposes a structural gap in DeFi's self-help recovery model. The protocols that froze, recovered, and organized restitution of stolen funds did so outside any legal framework. They now face the consequence: a legal system that does not recognize their recovery mechanisms as having superior claim to the assets.
The case raises at least four unresolved legal questions:
1. Who owns recovered crypto after an exploit? Under traditional property law, stolen property remains the victim's. But the terrorism creditors argue the exploit constituted fraud, not theft — a distinction that could transfer ownership to the attacker (and, by extension, to the attacker's sovereign principal). No U.S. court has ruled on this question in a DeFi context.
2. Can a DAO be served with a restraining notice? The plaintiffs treated Arbitrum DAO as an entity that can receive and comply with New York civil process. Aave's filing challenges this implicitly. If DAOs can be restrained by state court orders, every DAO with a U.S. nexus becomes subject to similar claims.
3. Does Lazarus Group attribution equal DPRK state property? The FSIA and TRIA allow attachment of property belonging to a foreign state or its agencies and instrumentalities. Even if Lazarus Group conducted the exploit, the legal question is whether the specific funds in question are "property of" North Korea within the meaning of the statute. Aave argues the plaintiffs have not met this evidentiary burden.
4. What happens when DAO governance conflicts with a court order? Arbitrum's governance voted to release the ETH. A U.S. court may order the opposite. The eight-day Constitutional AIP delay provides a buffer, but the underlying tension — between on-chain governance and off-chain legal authority — has no established resolution framework.
If the terrorism creditors prevail, the implications are significant. Any crypto recovered from a state-sponsored hack could become a target for pre-existing judgment creditors, effectively creating a lien on all Lazarus Group proceeds regardless of who the actual victims are. This would disincentivize the kind of rapid, coordinated recovery that DeFi United executed, since recovered funds would face immediate legal encumbrance.
If Aave prevails, the ruling would affirm that exploit victims retain superior title to recovered assets, preserving the economic logic of DeFi's emerging self-help recovery model. But it would also limit the reach of FSIA/TRIA enforcement into DeFi — a result that may draw legislative attention.
The $71 million frozen on Arbitrum is small relative to the $292 million total exploit and insignificant against the $877 million in terrorism judgments. But the case's importance is structural, not monetary. It will determine whether DeFi's emerging norms for exploit recovery — freeze, coordinate, restitute — can coexist with established legal frameworks for sovereign debt enforcement.
The economic logic favors Aave's position. Exploit victims deposited real assets into a protocol; those assets were stolen via a bridge vulnerability; a portion was recovered through coordinated action. Diverting those recovered funds to unrelated creditors — however sympathetic their claims — breaks the chain of restitution and imposes costs on the wrong parties. It also creates a perverse incentive: protocols would be discouraged from recovering stolen funds if those funds immediately become targets for third-party claims.
But the legal logic is less clear. The FSIA and TRIA were designed to ensure that state sponsors of terrorism cannot hide behind sovereignty to shield their assets. If the Lazarus Group did conduct this exploit on behalf of the DPRK, the statute contemplates exactly this kind of attachment. The question is whether "property of" the DPRK extends to stolen crypto that the victims and their protocols have already moved to recover.
Judge Garnett's ruling — whenever it comes — will not resolve the broader tension between on-chain governance and off-chain law. But it will establish the first data point in what is likely to become a recurring collision. DeFi protocols that operate self-help recovery systems should prepare for the possibility that U.S. courts will assert jurisdiction over recovered assets, regardless of how they were frozen or who voted to release them.
The eight-day clock is ticking.