A $292 million exploit of Kelp DAO's LayerZero bridge on April 18, 2026, has produced the first federal court ruling directly governing the interaction between on-chain DAO governance and U.S. asset-seizure law. On May 9, U.S. District Judge Margaret Garnett of the Southern District of New York m...
"A thief does not own what he steals. These funds belong to the affected users they were stolen from — end of story." — Stani Kulechov, Founder, Aave
A $292 million exploit of Kelp DAO's LayerZero bridge on April 18, 2026, has produced the first federal court ruling directly governing the interaction between on-chain DAO governance and U.S. asset-seizure law. On May 9, U.S. District Judge Margaret Garnett of the Southern District of New York modified a restraining notice on 30,766 ETH (~$71 million) frozen by Arbitrum's Security Council, permitting the funds to move to an Aave-controlled recovery wallet while preserving terrorism creditors' claims against the assets.
The ruling creates a narrow but significant legal channel: DeFi protocols can execute governance-approved fund transfers even when those assets are subject to a U.S. restraining notice, provided the receiving party consents to inherit the legal encumbrance. The case pits a 14-protocol industry coalition seeking to reimburse exploit victims against families holding $877 million in unpaid terrorism judgments against North Korea, the state widely attributed as the exploit's sponsor.
The outcome has immediate implications for how courts treat DAO treasuries, how protocols manage post-exploit recoveries, and whether on-chain governance can operate under the supervision of traditional courts without paralyzing the system.
On April 18, 2026, attackers compromised Kelp DAO's cross-chain bridge infrastructure in what Chainalysis and LayerZero Labs attributed to North Korea's Lazarus Group, specifically the sub-unit known as TraderTraitor. The attack was not a smart-contract vulnerability. It targeted off-chain infrastructure.
The attack vector: Kelp DAO's bridge operated on LayerZero's messaging protocol using a single Decentralized Verifier Network (DVN) — a 1-of-1 configuration. The attackers poisoned Kelp's internal RPC nodes while simultaneously DDoS-ing external nodes, forcing the LayerZero Labs DVN to rely on the compromised data feed. The DVN then confirmed a cross-chain message reporting that rsETH had been burned on the source chain (Unichain). No such burn occurred.
On that false confirmation, the Ethereum-side contract released 116,500 rsETH — approximately $292 million — to an attacker-controlled address.
Downstream damage: The attacker deposited approximately 89,500 rsETH into Aave V3 as collateral and borrowed wrapped ETH against positions that had no real backing. More than $190 million in bad debt materialized across the lending protocol. Kelp DAO managed to pause contracts in time to block a second $95 million theft attempt.
Fund movement: According to TRM Labs, approximately $175 million of the stolen funds were converted to Bitcoin via THORChain. The remainder was partially frozen or scattered across 20+ chains.
LayerZero Labs stated it had recommended a multi-DVN configuration to Kelp; Kelp DAO countered that the 1-of-1 setup was the default configuration shipped for new deployments at the time of its L2 expansion. The finger-pointing between the two protocols remains unresolved.
On April 21 at 11:26 PM ET, the Arbitrum Security Council acted with a 9-of-12 supermajority to emergency-freeze 30,766 ETH (~$71 million) that had been traced as downstream proceeds of the exploit on the Arbitrum network.
The freeze was executed under the Security Council's constitutional emergency powers — the same mechanism designed for protocol-threatening bugs. This was, however, its first deployment for law-enforcement coordination purposes, a distinction that did not go unnoticed by governance observers.
The frozen funds represented a significant portion of the total recoverable assets. Without them, DeFi United's recovery plan — which required full rsETH re-collateralization — faced a 10% shortfall.
On May 1, attorney Charles Gerstein filed a restraining notice in the U.S. District Court for the Southern District of New York on behalf of three sets of judgment creditors holding approximately $877 million in unpaid terrorism damages against the Democratic People's Republic of Korea.
The legal theory: if the Lazarus Group conducted the exploit on behalf of the North Korean state, then the stolen ETH constitutes North Korean property. Under the Terrorism Risk Insurance Act and the Foreign Sovereign Immunities Act, terrorism judgment creditors can attach foreign-state property located in the United States.
Gerstein served the restraining notice on Arbitrum DAO, creating an immediate legal paradox: a decentralized governance body, with no corporate entity, no officers, and no registered agent, was being treated as a debtor holding identifiable property belonging to a foreign sovereign.
On May 4, Aave filed a motion to modify the restraining notice. In its filing, Aave argued that the freeze was blocking the return of assets to innocent users who had been victimized by the exploit — not protecting North Korean property.
On May 6, the terrorism creditors escalated, opposing the transfer and arguing that the ETH should remain frozen pending full adjudication of their claims.
On May 9, Judge Garnett issued a two-page order that neither fully granted Aave's motion nor upheld the blanket freeze. The ruling:
The ruling represents a compromise: the DeFi recovery process can proceed operationally, but the terrorism creditors lose nothing in terms of legal standing. The $71 million in ETH remains legally contested property regardless of which wallet holds it.
Governance timeline: On May 8, Arbitrum delegates completed an off-chain Snapshot temperature check with 182.2 million ARB tokens (91% of voting power) supporting the transfer. A binding on-chain Constitutional Arbitrum Improvement Protocol vote is required next, with a minimum eight-day waiting period before execution.
Within days of the exploit, Aave organized a 14-protocol coalition dubbed "DeFi United" to restore rsETH's full backing. The effort represents the largest coordinated DeFi recovery operation to date.
Contributions as of early May 2026:
| Contributor | Amount | Form | |---|---|---| | Consensys / Joseph Lubin | Up to 30,000 ETH | Direct commitment | | LayerZero Labs | 10,000 ETH | 5,000 ETH direct + 5,000 ETH liquidity | | Stani Kulechov (personal) | 5,000 ETH | Direct commitment | | Mantle Network | 30,000 ETH | Backstop facility | | Other contributors | Various | Multiple commitments | | Total commitments | ~$303 million | |
Joseph Lubin stated: "The Ethereum ecosystem has always been at its best when it moves together. DeFi United is exactly that, a broad, coordinated response to protect users and strengthen the infrastructure we've all helped build."
Technical recovery mechanism: DeFi United is converting committed ETH into rsETH in tranches to restore the token's 1:1 backing. Aave completed liquidation of the attacker's remaining rsETH positions on both Ethereum and Arbitrum, recovering approximately 13,000 ETH (~$30.2 million) for the DeFi United Recovery Guardian multisig wallet.
Current gap: As of mid-May 2026, DeFi United remains approximately 10% short of the ETH needed to fully restore rsETH backing. The frozen $71 million on Arbitrum accounts for a substantial portion of that shortfall.
The Kelp DAO exploit did not occur in isolation. According to TRM Labs, North Korean operatives accounted for 76% of all crypto hack losses in 2026 through April, stealing $577 million from just two attacks — representing only 3% of total incidents by count.
2026 attacks attributed to Lazarus Group:
| Exploit | Date | Amount | Vector | |---|---|---|---| | Drift Protocol (Solana) | April 1 | $285 million | Durable nonce + multisig manipulation | | Kelp DAO (Ethereum/LayerZero) | April 18 | $292 million | RPC node compromise + DVN spoofing | | Total | | $577 million | |
Historical trajectory of DPRK crypto theft share (TRM Labs):
Cumulative North Korean crypto theft since 2017 now exceeds $6 billion, according to TRM Labs. The proceeds fund the DPRK's missile and nuclear programs, according to U.S. intelligence assessments.
Chainalysis matched the Kelp DAO attacker's mixer-usage patterns and fund-dispersal methodology to Lazarus Group's known operational fingerprint within three days of the breach. Pre-funding for the attack was traceable to Wu Huihui, a Chinese crypto broker indicted in 2023, and proceeds from the 2024 BTCTurk exchange hack.
Judge Garnett's ruling, while narrow and procedural, intersects with a rapidly evolving body of DAO liability law:
Lido DAO ruling (2025): A California federal court ruled that DAO token holders who vote on governance proposals can be treated as general partners, personally liable for the DAO's obligations. Judge Vince Chhabria's decision established that even posting in a governance forum could constitute sufficient participation to trigger liability.
Ooki DAO (2023): The CFTC successfully argued that a DAO could be held liable as an unincorporated association, with governance token holders treated as members.
The Garnett order adds a new dimension: A federal court has now supervised an on-chain governance vote, granting legal safe harbor to voters who participate. This creates an asymmetry — in the Lido precedent, governance participation increases liability; in the Garnett order, the court explicitly shields it.
The practical tension is unresolved. DAO participants now face a jurisdiction-dependent risk calculus: voting in a California-governed DAO may expose them to partnership liability, while voting in a New York-supervised recovery may be explicitly protected. No appellate court has harmonized these positions.
For protocols: The ruling suggests that post-exploit recovery can operate within the legal system rather than outside it — but only if the protocol voluntarily submits to jurisdiction and accepts legal encumbrances on recovered assets. Aave's decision to consent to the restraining notice was the key concession that unlocked the transfer.
The Kelp DAO exploit and its aftermath represent a stress test for the relationship between on-chain governance and traditional legal systems. The outcome so far is neither a victory for DeFi autonomy nor a capitulation to state authority. It is a negotiated coexistence: protocols can govern themselves, courts can supervise, and legal claims follow assets regardless of which smart contract holds them.
The $71 million in frozen ETH remains legally contested. The binding on-chain vote has not yet executed. The terrorism creditors' claims are intact. DeFi United is still short of full re-collateralization.
What has been established is a procedural framework. When stolen crypto passes through DeFi protocols and triggers competing claims, U.S. courts can modify — not eliminate — legal freezes to let governance mechanisms function. Whether this framework holds under appeal, or in cases where protocols refuse to submit to jurisdiction, remains untested.
The economic cost of bridge infrastructure failure is now measured not only in stolen tokens but in legal precedent. Every protocol operating a cross-chain bridge with a single-verifier configuration is running the same risk Kelp DAO ran. Lazarus Group has now demonstrated the capability to exploit that architecture twice in 18 days.