DeFi Incidents and Recovering Digital Assets Through the Courts
Back to blog
Blockchain · July 2026

DeFi Incidents and Recovering Digital Assets Through the Courts

Share

Recovering digital assets after an attack on a DeFi protocol depends on more than blockchain forensics alone. Decisive factors can include a DAO's legal status, the ability to serve process, the court's jurisdiction, the existence of an identifiable intermediary, and the ability to enforce a court order in the state where the assets are actually controlled.

Kelp DAO: when a technical incident becomes an international dispute

On 18 April 2026, an attack on the infrastructure of the Kelp DAO bridge, built using LayerZero, resulted in the unauthorised withdrawal of 116,500 rsETH tokens. At the time of the incident, their value was estimated at approximately $292 million. According to published technical analyses, the attack was not a classic smart-contract bug: the attackers compromised the off-chain infrastructure on which the bridge's sole message verifier depended. Analysts preliminarily linked the activity to the Lazarus Group, though such attribution is not equivalent to a court's final determination of that fact.

On 21 April 2026, the Arbitrum Security Council invoked an emergency mechanism and moved 30,765.67 ETH linked to the exploiter's address to a designated address. The assets were worth roughly $71 million at the time. Their further use in a recovery programme required a decision of the Arbitrum governance system.

In May 2026, representatives of plaintiffs in three cases with unsatisfied judgments against North Korea totalling more than $877 million asserted claims to this ETH. Their position was that, if the link to the Lazarus Group were confirmed, the assets could be treated as North Korean state property available to satisfy those judgments. Aave LLC, on the other hand, argued that the funds should be directed toward restoring affected users' positions.

On 8 May 2026, Judge Margaret M. Garnett of the Southern District of New York modified the restraining notice: the court allowed an on-chain vote to be held and the assets to be transferred to a wallet controlled by Aave LLC, while maintaining restrictions on the funds after the transfer. The court did not finally decide who owns the assets or whether North Korea's creditors may levy on them. The ruling therefore concerned the possibility of moving the assets while preserving legal claims, not a final distribution of the funds.

Exploit, fraud, and theft are not identical concepts

In public materials, different incidents are often lumped together under the word “fraud.” For legal analysis, it is important to distinguish, at minimum: social engineering and deception of the victim; obtaining a private key or seed phrase; exploiting a smart-contract vulnerability; compromising administrative keys or off-chain infrastructure; and laundering or concealing already-stolen assets. The actual mechanism will determine the grounds for the claim, the proper defendants, the evidence required, and the interim relief available.

Whom to sue when a protocol is governed by a DAO

A DAO has no universal legal status. The name “decentralised autonomous organisation” does not by itself determine whether the structure is a legal entity, a simple partnership, an unincorporated association, or merely a technological coordination mechanism. The conclusion depends on the applicable law, the governance model, the involvement of founders and investors, the distribution of income, and actual control.

CFTC v. Ooki DAO. In June 2023, a US federal court entered a default judgment in CFTC v. Ooki DAO. The court held that Ooki DAO could be treated as a “person” within the meaning of the Commodity Exchange Act, as it was an unincorporated association, and imposed a civil penalty of $643,542 together with injunctive relief. The judgment was entered by default and was based, among other things, on the CFTC's properly pleaded allegations, which went unchallenged due to the defendant's non-appearance. CFTC proceedings against the operators of Opyn, ZeroEx, and Deridex were resolved by administrative settlements as early as 7 September 2023 — these cases demonstrate the regulatory approach to specific DeFi protocol operators but do not establish automatic liability for every governance token holder.

Samuels v. Lido DAO. In November 2024, the Northern District of California denied most of the motions to dismiss in Samuels v. Lido DAO. At this procedural stage, the court found sufficient the allegations that Lido DAO could be a general partnership under California law, and that Paradigm, Andreessen Horowitz, and Dragonfly were its partners. This does not mean that every token holder or every governance participant automatically bears joint and several liability. The final circle of partners and the actual grounds for liability remain to be determined based on the evidence.

Kim et al. v. Railgun DAO. The case of Kim et al. v. Railgun DAO, filed in January 2026 in the federal court for the District of Columbia, illustrates the procedural difficulties of serving process on a DAO. The court allowed alternative service; in April 2026, the clerk entered a default, and the plaintiffs moved for default judgment. As of the date of this material, this proceeding should not be presented as a final decision on the merits — it illustrates not the futility of judicial protection, but the need to separately establish the method of service, the DAO's legal personality, and the enforceability of any future judgment.

English courts: proprietary claims, freezing orders, and disclosure

The Property (Digital Assets etc) Act 2025 came into force on 3 December 2025. The Act does not automatically declare all crypto-tokens, stablecoins, or NFTs to be property. It provides that an object cannot be deprived of the status of a thing capable of being personal property merely because it does not fall within things in possession or things in action. The boundaries of this “third category” and the specific rights attaching to digital assets continue to be developed by the courts.

Wilden v. Person Unknown and Huobi Global SA. In Wilden v. Person Unknown and Huobi Global SA [2026] EWHC 1355 (KB), the claimant alleged that an unknown person had fraudulently obtained 32.457826 BTC worth approximately €2.59 million. Experts were able to trace the movement of the Bitcoin through pooling transactions to the infrastructure of the HTX exchange. On 5 June 2026, the High Court continued a proprietary injunction and worldwide freezing order against the unknown person until trial or further order, along with a Bankers Trust disclosure order against Huobi Global — based on a good arguable case, a high risk of further dissipation of assets, and expert evidence that identification remained possible after mixing. This was a decision on interim relief, not a final finding of liability. The court was critical of HTX's lack of cooperation and awarded the claimant £60,993.91 in costs on the indemnity basis. At the same time, a disclosure order does not by itself guarantee actual recovery of the assets, particularly where the intermediary is outside the jurisdiction and does not comply with the court's orders.

Yuen v. Li. In Ping Fai Yuen v. Fun Yung Li & Anor [2026] EWHC 532 (KB), the court confirmed that Bitcoin can be the object of proprietary rights, but declined to extend to it the torts of conversion and trespass to goods, historically tied to physical possession of tangible things. At the same time, the claimant was permitted to amend the claim to rely on other constructs, including proprietary restitution, unjust enrichment, and constructive trust. The court did not finally decide the merits of these alternative claims.

Why a court judgment does not equal asset recovery

Even a well-founded claim and an interim order may not deliver actual recovery. The outcome depends on whether the assets survive, whether they can be linked to specific transactions, whether the exchange holds identifying data, whether the order is recognised in the relevant jurisdiction, and whether the court is able to enforce it. Claims of “guaranteed recovery” of funds in such cases are therefore legally and factually incorrect.

The Ukrainian legal context

Ukrainian law already contains a general property-law basis for digital assets. Article 179-1 of the Civil Code of Ukraine defines a digital thing as a good that exists exclusively in a digital environment and has property value; virtual assets are expressly classified as digital things. The Civil Code's provisions on things apply to them unless otherwise established by law or unless this is inconsistent with the nature of the digital thing.

At the same time, the special Law of Ukraine “On Virtual Assets” No. 2074-IX has not entered into force as of the date of this material. Draft Law No. 10225-d on regulating the circulation of virtual assets was adopted in its first reading on 3 September 2025 and is being prepared for its second reading. Special market regulation and a settled model of civil-law recovery of crypto-assets are therefore still developing. Depending on the circumstances, claims may be analysed for the recovery of property, restitution of unjust enrichment, compensation for damage, recognition of a right, and interim relief — the choice of legal construct depends on how the asset was lost, whether the defendant can be identified, evidence of the victim's entitlement to the digital thing, and the jurisdiction of the person who actually controls the assets.

Practical steps after discovering an incident

Record wallet addresses, transaction hashes, the timing of events, correspondence, screenshots, and technical logs; conduct blockchain forensic analysis as quickly as possible and identify exchanges, bridges, custodians, and other points of control; notify the relevant platforms through official compliance or law-enforcement channels without disclosing unnecessary information to the attacker.

File a report of a criminal offence and ensure proper procedural handling of digital evidence; assess the possibility of obtaining a foreign freezing order, proprietary injunction, or disclosure order in the intermediary's jurisdiction; check whether there is an identifiable legal entity, interface operator, developer, multisig participant, or other party who can be served with process; do not pay funds to persons who promise “guaranteed recovery” or demand an advance payment in cryptocurrency without verifying their identity and authority.

Conclusion

The cases of 2024–2026 show that a decentralised architecture does not eliminate the possibility of judicial protection, but significantly complicates it. What matters most is precisely identifying the mechanism of the incident, preserving digital evidence, rapid asset tracing, the correct choice of defendant and jurisdiction, and the existence of a person or infrastructure capable of enforcing a court order.

Disclaimer. This material is of a purely general informational and analytical nature, does not constitute individual legal advice, and contains no guarantee of digital asset recovery. The legal assessment depends on the facts of the specific case, the applicable law, and the jurisdiction.

Sources: Chainalysis — Inside the KelpDAO Bridge Exploit (23 April 2026); Arbitrum Foundation Forum — Constitutional AIP: Approve Release of Frozen ETH; CoinDesk — Aave launches binding Arbitrum vote to move disputed ETH (12 May 2026); CFTC — Default judgment against Ooki DAO (9 June 2023); CFTC — Orders against Opyn, ZeroEx and Deridex (7 September 2023); Samuels v. Lido DAO, order of 18 November 2024; Kim et al. v. Railgun DAO, D.D.C., No. 1:26-cv-00179; Law Commission — Property (Digital Assets etc) Act 2025 received Royal Assent; Wilden v. Person Unknown and Huobi Global SA [2026] EWHC 1355 (KB); Ping Fai Yuen v. Fun Yung Li & Anor [2026] EWHC 532 (KB); Civil Code of Ukraine, Article 179-1; Law of Ukraine “On Virtual Assets” No. 2074-IX; Verkhovna Rada of Ukraine — Draft Law No. 10225-d record card.