Mcap -- BTC -- ETH -- SOL -- BNB -- XRP -- F&G -- View Market
Loading prices…

Terror Victims Argue Aave Hack Was 'Fraud' to Seize $71M in Frozen ETH

Legal documents and frozen Ethereum tokens representing the terror victims' court battle over Aave hack funds

“What actually happened is that North Korea borrowed assets from users of the ‘Aave Protocol’ and did not pay it back.”

That sentence, from a 30-page opposition brief filed Tuesday in the Southern District of New York, marks a sharp pivot in one of the stranger collisions between state-sponsored hacking and decentralized finance. Lawyers representing victims of North Korean terrorism are no longer calling last month’s $71 million rsETH exploit on Aave a theft. They’re calling it fraud.

The distinction sounds like legal semantics. It is not. If the court accepts the argument, it could give the attackers, widely attributed to the Lazarus Group, legal title to the borrowed Ethereum. And that title, the filing argues, makes the frozen ether seizable as North Korean state property under a federal anti-terrorism statute that has nothing to do with New York property law.

A hearing is scheduled for today, May 6, in a Manhattan federal courtroom. The outcome could reshape how stolen DeFi assets move through the U.S. legal system for years to come.

The terror victims’ attorneys are invoking a principle that predates cryptocurrency by more than a century. Under longstanding U.S. common law, a thief who steals property never obtains title to it. The original owner retains ownership, and the property can be recovered from anyone who later possesses it, even a good-faith buyer.

Fraud works differently. A fraudster who tricks someone into voluntarily transferring property obtains “defeasible title,” meaning real ownership that can later be voided if the fraud is discovered. The legal difference matters because property with title can be transferred, encumbered, or seized in ways that stolen property cannot.

The filing draws an analogy to Charles Ponzi himself: “The law is crystal clear that a fraud victim passes title, not merely possession, to a fraudster… Charles Ponzi obtained, through his now-eponymous scheme, ‘defeasible title’ to his victims’ cash.”

Applied to the rsETH exploit, the argument runs like this: the attacker did not break into Aave’s smart contracts and drain funds directly. Instead, the attacker minted unbacked rsETH tokens on a cross-chain bridge, deposited them as collateral on Aave’s lending markets, and borrowed real ether against those worthless deposits. When Aave’s protocol tried to liquidate the collateral, it discovered the rsETH was worthless.

In the terror victims’ framing, this was not a smash-and-grab. It was a lending transaction induced by deception. Aave’s users (or its protocol, depending on how you view the legal entity question) voluntarily transferred ether to the borrower. The fact that the collateral was fake makes it fraud, not theft.

Why does this help the terror victims? Because if the Lazarus Group obtained title to the ether, even defeasible title, that ether can be characterized as North Korean state property. And North Korean state property held in the United States is subject to seizure under the Terrorism Risk Insurance Act.

TRIA: A Post-9/11 Statute Meets DeFi

The Terrorism Risk Insurance Act was signed into law in 2002, designed to help terror victims collect court judgments against state sponsors of terrorism. The basic idea: if you win a lawsuit against Iran, North Korea, Syria, or another designated state sponsor, you can collect your judgment from any property belonging to that country that’s located in the U.S.

TRIA has been used to seize embassy bank accounts, frozen assets, and other state property. It has never, as far as public records show, been used to seize cryptocurrency from a DeFi protocol.

The terror victims in this case hold existing judgments against North Korea from three separate terrorism cases. Their attorneys argue that the ether frozen on Arbitrum, approximately $71 million worth, qualifies as DPRK state property because the Lazarus Group operates under the North Korean government. Multiple blockchain forensics firms, including Chainalysis and TRM Labs, have attributed the rsETH exploit to Lazarus.

If the court accepts this theory, the earlier legal arguments about New York property law, which formed the basis of Aave’s challenge to the restraining notice, may become irrelevant. Federal law would supersede state law on the question of seizure.

This is a meaningful escalation. When the restraining notice was first served on Arbitrum DAO, the legal battle centered on whether frozen crypto could be “property” subject to a New York restraining order, and whether the DAO had sufficient control over the funds to be bound by such an order. We covered that dispute when it first emerged. The TRIA argument shifts the ground entirely. It treats the ether as foreign government property, subject to a federal collection regime that operates independently of state-law questions about protocol control.

The filing invokes Charles Ponzi as precedent: “The law is crystal clear that a fraud victim passes title, not merely possession, to a fraudster.” If the court agrees, the ether becomes North Korean state property seizable under federal law.

Aave’s Standing Problem: Do Protocols Control User Assets?

The terror victims’ attorneys also challenged whether Aave has any right to contest the freeze in the first place. They pointed to Aave’s own terms of service, which state that the protocol does not have “possession, custody or control” over user assets.

This is a core claim of decentralized finance. DeFi protocols market themselves as non-custodial, meaning users retain control of their funds at all times. The protocol is just software; it doesn’t hold your keys, doesn’t have admin access to your wallet, can’t freeze your account.

That claim is now being used against Aave in court. If Aave doesn’t control user assets, the terror victims argue, then Aave has no property interest being harmed by the restraining order. And without a property interest, Aave may lack standing to challenge the freeze.

The argument creates an awkward bind for DeFi protocols. The industry has spent years emphasizing non-custodial architecture as a feature, distinguishing itself from centralized exchanges that hold user funds and face regulatory scrutiny for doing so. But that same non-custodial framing now undermines Aave’s ability to intervene when a third party claims its users’ assets.

There’s a second irony here. The $71 million at issue was frozen precisely because Arbitrum developers did exercise some form of emergency control after the exploit. If no one could intervene, the funds would have been cashed out through mixers and bridges long ago. The very fact that the ether is frozen suggests some entity, whether Arbitrum’s sequencer operators, Aave’s governance, or both, had enough control to stop the outflow.

Courts will likely scrutinize this tension closely. The “we don’t control user assets” argument may work for regulatory classification, but it may not work when a protocol wants to challenge a legal action affecting those same assets.

The Broader Context: $500 Million Drained, $328 Million Raised

The $71 million frozen on Arbitrum represents a fraction of the damage the Lazarus Group inflicted on DeFi last month. The broader rsETH exploit drained roughly $230 million from Aave’s lending markets. And that exploit was itself part of a larger campaign. In the three weeks ending in late April, Lazarus-linked attackers drained more than $500 million from DeFi protocols, hitting Drift and Kelp DAO in addition to Aave.

The industry’s response has been coordinated, and fast. DeFi United, a recovery fund that Aave itself participates in, has raised $327.95 million as of Tuesday morning. That’s more than four times the $71 million at issue in the Manhattan courtroom.

The terror victims’ attorneys noted this figure in their filing. It suggests, they argued, that the affected Aave users may not actually need the frozen ether. The DeFi United fund could make them whole even if the court seizes the funds for the terror victims.

Whether that argument influences the court’s decision is unclear. A judge might reasonably say that the source of potential repayment is irrelevant to the legal question of who owns the frozen assets. But it does shift the moral framing of the dispute. This is not a case where terror victims would be taking funds from ordinary DeFi users with no other recourse. The industry has already mobilized to cover the losses.

Legal documents and frozen Ethereum tokens representing the court battle over the Aave rsETH exploit funds

The DeFi United fund’s existence also raises a question the court may not address but that matters for the industry: why is an informal coalition of protocols raising hundreds of millions of dollars to cover losses from an exploit attributed to a state-sponsored hacking group? The answer, at least in part, is that there’s no government backstop, no FDIC insurance, no formal mechanism for recovering losses from protocol failures or attacks. DeFi is self-insuring because it has no other option.

The May 6 hearing will not necessarily produce a final ruling. The court could issue a preliminary decision on the restraining order, schedule further briefing, or request additional evidence on the fraud-versus-theft question or the TRIA applicability.

But whatever happens, the case is setting precedent in real time. Several questions are now on the table that DeFi developers and lawyers will be watching closely:

First, can exploit proceeds be characterized as “fraud” under U.S. law in a way that creates title, even temporarily? If so, stolen DeFi funds may be more vulnerable to seizure by judgment creditors than previously assumed.

Second, does TRIA apply to cryptocurrency attributed to state-sponsored hacking? If the court accepts that Lazarus Group exploits generate North Korean state property, this could open a new avenue for terror victims to collect judgments from any future DPRK-linked hacks.

Third, can DeFi protocols challenge legal actions affecting “their” users’ funds if those protocols disclaim control over user assets? The standing question could have implications far beyond this case, affecting everything from subpoena responses to regulatory enforcement actions.

Fourth, how does a recovery fund like DeFi United factor into loss allocation? If the industry can make victims whole, does that change the equities of a seizure dispute? Or is it irrelevant to the legal ownership question?

These are not academic questions. DeFi protocols hold tens of billions of dollars in user deposits. State-sponsored hacking is not going away; the Lazarus Group alone has stolen more than $2 billion in cryptocurrency since 2018, according to estimates from the FBI and blockchain analytics firms. The intersection of terror-victim litigation, federal seizure statutes, and decentralized protocol architecture is going to produce more cases, not fewer.

For now, approximately $71 million in ether sits frozen on Arbitrum, claimed by terror victims who want compensation for North Korean atrocities and by Aave users who deposited their assets in a protocol that was supposed to be trustless. The hearing today may not resolve whose claim is stronger. But it will almost certainly clarify what legal tools are available to pursue stolen crypto through U.S. courts.

The crypto industry has often argued that its systems are beyond the reach of traditional legal mechanisms. Today’s hearing is a test of that claim.

Bottom line
Lawyers for North Korean terror victims are arguing the $71 million rsETH exploit was fraud, not theft, which would give them a path to seize the frozen ether as DPRK state property under federal anti-terrorism law. A Manhattan federal court hearing on May 6 could set precedent for how stolen DeFi funds move through the U.S. legal system.

Sources

Frequently asked questions

Why does it matter if the Aave hack was fraud versus theft?

Under U.S. law, fraudsters who acquire property through deception can obtain legal title to it, even if that ownership can later be reversed. If the court classifies the rsETH exploit as fraud rather than theft, the attackers would have held legal title to the borrowed ether, which could then be seized as North Korean state property under the Terrorism Risk Insurance Act.

What is the Terrorism Risk Insurance Act and how does it apply here?

TRIA is a post-9/11 federal law that allows people who win court judgments against state sponsors of terrorism to collect those judgments from any U.S.-held property belonging to that country. The terror victims’ lawyers argue the frozen ether qualifies as North Korean state property because the Lazarus Group, which carried out the exploit, operates under the DPRK government.

How much money is at stake in the Aave frozen funds dispute?

The dispute centers on approximately $71 million in ether that Arbitrum developers intercepted before the attackers could cash it out. The broader exploit drained roughly $230 million from Aave’s lending markets.

Does Aave have legal standing to challenge the asset freeze?

The terror victims’ lawyers argue Aave may lack standing because its own terms of service state it does not have possession, custody, or control over user assets. This is a core principle of decentralized finance that could work against Aave in this case.

Will Aave users who lost funds in the exploit get their money back?

Possibly through a separate channel. DeFi United, an industry recovery fund that Aave participates in, has raised $327.95 million as of May 6, more than four times the $71 million frozen in the legal dispute.

When will the court decide on the frozen Aave funds?

A hearing was scheduled for May 6, 2026, in a Manhattan federal court. The judge’s ruling could determine whether terror victims can seize the funds or whether they return to Aave’s protocol.
Share:
Twitter Facebook LinkedIn Reddit WhatsApp Telegram Email