A Manhattan federal judge on May 9 cleared Arbitrum DAO to transfer 30,765 ETH ($71 million) to an Aave-controlled wallet, resolving a two-week standoff between decentralized-finance protocols and families holding $877 million in unpaid terrorism judgments against North Korea. The ruling by Judge...
"In the financial crisis, we had to bail out the banks. Here, we came together as an ecosystem to bail ourselves out." — Linda Jeng, Chief Legal and Policy Officer, Aave Labs
A Manhattan federal judge on May 9 cleared Arbitrum DAO to transfer 30,765 ETH ($71 million) to an Aave-controlled wallet, resolving a two-week standoff between decentralized-finance protocols and families holding $877 million in unpaid terrorism judgments against North Korea. The ruling by Judge Margaret Garnett permits the asset transfer while preserving the terrorism creditors' legal claims — a compromise that, for the first time, forces a DeFi protocol to accept court-imposed restrictions on assets passing through its smart contracts.
The case is the latest chapter in the fallout from the April 18 KelpDAO bridge exploit, in which attackers attributed to North Korea's Lazarus Group minted 116,500 unbacked rsETH tokens ($292 million), deposited them as collateral on Aave, and borrowed approximately $230 million in ETH. The exploit triggered $16.2 billion in cumulative Aave outflows, prompted an unprecedented industry-led bailout exceeding $161 million, and forced LayerZero to publicly admit a critical infrastructure failure.
On April 18, 2026, attackers compromised KelpDAO's cross-chain bridge infrastructure in what became the largest DeFi exploit of the year. According to forensic analysis by Chainalysis and TRM Labs, the attack was attributed to North Korea's Lazarus Group.
The attack was not a smart-contract vulnerability. Attackers targeted off-chain infrastructure: the RPC nodes used by LayerZero's decentralized verifier network (DVN). The sequence, according to CoinDesk and Chainalysis reporting:
The critical failure: rsETH was configured with a single verifier — the LayerZero Labs DVN — in a 1-of-1 configuration. No second DVN was required to approve cross-chain transfers.
KelpDAO successfully paused contracts to block a second $95 million theft. Arbitrum's Security Council, coordinating with law enforcement, froze 30,765 ETH of the attacker's downstream funds.
The exploit exposed structural risk in DeFi's largest lending protocol. Before April 18, Aave held approximately $48.5 billion in total deposits, according to DefiLlama. The subsequent outflows:
The broader DeFi ecosystem lost $13.21 billion in TVL within two days of the exploit, according to CoinDesk market data. The contagion spread because rsETH was listed as collateral across multiple protocols — a systemic interconnection that Aave's existing risk frameworks had not adequately assessed.
Aave's bad debt from the exploit was estimated at $124 million to $230 million, depending on how KelpDAO allocated the rsETH shortfall across chains.
Rather than waiting for government intervention or writing off losses, a coalition called "DeFi United" self-organized within days. According to reporting by CoinDesk, The Defiant, and Phemex Research, the seven-protocol coalition pledged the following:
| Contributor | Pledge | Structure | |---|---|---| | Aave DAO | 25,000 ETH | Treasury allocation (governance vote pending) | | Mantle | Up to 30,000 ETH | Credit facility at Lido staking yield + 1%, 3-year term | | Stani Kulechov (Aave founder) | 5,000 ETH (~$11.6M) | Personal contribution | | EtherFi | 5,000 ETH | Direct pledge | | Lido DAO | 2,500 stETH (~$5.8M) | Governance proposal pending | | Golem Foundation | 1,000 ETH | Direct pledge | | BGD Labs | 250 ETH | Direct pledge | | Emilio Frangella (Aave VP Engineering) | 500 ETH | Personal contribution |
Total raised as of May 6: 69,534 ETH ($161 million), according to court filings cited in CoinDesk reporting. A separate tracker showed the DeFi United recovery fund at $327.95 million as of May 6, which includes the frozen 30,765 ETH on Arbitrum in the total.
The original shortfall was approximately 163,183 ETH. KelpDAO directly recovered 73,700 ETH. The Arbitrum Security Council freeze accounted for 30,765 ETH. The remaining gap of approximately 89,500 ETH was the target for DeFi United contributions.
Mantle's credit facility came with governance strings: Aave would delegate 130,000 AAVE governance tokens to Mantle, giving the Layer 2 protocol a seat at Aave's governance table.
On May 1, attorney Charles Gerstein served a restraining notice on Arbitrum DAO on behalf of families holding approximately $877 million in unpaid default judgments against North Korea for terrorism-related claims. The legal theory: if Lazarus Group stole the funds, and Lazarus Group is a North Korean state actor, then the frozen ETH constitutes North Korean property subject to seizure under the Terrorism Risk Insurance Act (TRIA).
Aave's argument (May 5 filing): The 30,765 ETH "belong to completely blameless third parties." Stolen assets do not confer legal ownership on perpetrators. Aave disputed the North Korea attribution as "conjecture based on unverified reports" and warned that continued freezing risked "cascading liquidations, liquidity outflows, and irreversible user position changes."
Terrorism creditors' argument (May 6, 30-page opposition brief): Attorneys reframed the exploit as fraud, not theft. Under U.S. law, fraudsters obtain "defeasible title" to victims' assets. As the brief argued: "What actually happened is that North Korea borrowed assets from users of the Aave Protocol and did not pay it back, and when the Aave Protocol sought to liquidate North Korea's collateral, the Aave Protocol unhappily discovered that the collateral was worthless."
Arbitrum governance vote (May 8): 182.2 million ARB tokens supported the ETH release, approximately 91% of voting power, in a non-binding Snapshot temperature check.
Court ruling (May 9): Judge Margaret Garnett modified the prior restraining notice to permit the transfer while preserving the terrorism creditors' claims. Key provisions:
The ruling establishes a template: DeFi protocols can be compelled to accept court-imposed asset restrictions, and DAO governance votes can proceed under judicial supervision.
For three weeks after the exploit, LayerZero blamed KelpDAO's configuration choices. On May 9, LayerZero reversed course in a blog post titled with "an overdue apology."
Key admissions, per LayerZero's statement:
Remediation steps announced:
The market response was immediate. According to CoinDesk reporting:
On May 7, Aave Labs announced a fundamental restructuring of its asset listing framework. According to Chief Legal and Policy Officer Linda Jeng: "Out of a crisis like this, it ups our standards."
The new framework expands collateral evaluation beyond financial risk and volatility to include:
Aave committed to publishing a formal playbook establishing minimum standards that projects must meet before listing. The approach mirrors traditional finance's post-2008 reforms, where structured products faced heightened due diligence requirements after systemic failures.
The Aave case is not isolated. The same terrorism judgment creditors have filed separate lawsuits targeting:
These cases collectively test whether DeFi protocols, and entities that participate in their governance, can be held responsible for funds that pass through their smart contracts.
The KelpDAO exploit and its aftermath represent a stress test for DeFi's institutional maturity. The industry's self-organized bailout — mobilizing $161 million in weeks without government intervention — demonstrated operational coordination that did not exist two years ago. The court ruling, however, imposed a reality check: decentralized governance does not operate outside the legal system, and assets that pass through smart contracts remain subject to judicial claims.
The economic implications are straightforward. DeFi protocols that accept cross-chain collateral now face a new risk variable: the legal provenance of assets deposited through bridging infrastructure. Aave's collateral overhaul and LayerZero's security migration are direct responses to this realization. The question is whether the rest of the industry adopts similar standards before the next exploit forces the issue.
The terrorism creditors' legal strategy — pursuing North Korean assets across DeFi protocols — will likely expand. The Railgun and DCG lawsuits test whether governance token holders can be held liable for protocol-level failures to freeze illicit funds. If those cases succeed, the cost of participating in DeFi governance rises materially.