On-chain investigator ZachXBT has accused U.S. litigation firm Gerstein Harrow LLP of attempting to seize approximately $71 million in frozen ether tied to the suspected North Korea-linked Lazarus Group, arguing that the move could directly undermine recovery efforts for the real victims of the 2026 KelpDAO exploit.
The dispute centers on 30,766 ETH that was frozen after the April 2026 attack on KelpDAO. According to the report, Lazarus is suspected of stealing roughly $290 million from the protocol by exploiting a vulnerability in its LayerZero V2 bridge. In response, the Arbitrum Security Council took emergency on-chain action to freeze part of the funds in an effort to stop further laundering.
A legal claim built on an unrelated judgment
ZachXBT says Gerstein Harrow is relying on a 2015 U.S. court judgment in Han Kim et al. v. North Korea to argue that the frozen ETH should be redirected to satisfy that older ruling. The 2015 judgment reportedly stems from the 2000 kidnapping of a South Korean reverend, making it unrelated to the present-day KelpDAO hack.
That disconnect is at the heart of the controversy. If the law firm succeeds, assets frozen in connection with the 2026 exploit could be diverted away from the users and stakeholders directly harmed by the KelpDAO attack. In practical terms, the law firm’s clients could move ahead of the actual hack victims in any recovery queue, despite having no direct connection to the exploit itself.
For a crypto industry already struggling with the complexities of cross-border theft, attribution, and asset recovery, the case introduces another difficult question: when illicit funds are frozen on-chain, who should have first claim over them? ZachXBT’s criticism suggests that using legacy judgments to reach newly frozen assets could create a dangerous precedent, especially in high-profile cases involving state-backed threat actors.
ZachXBT calls the tactic harmful to real victims
ZachXBT, whose investigative work reportedly helped build the evidentiary trail leading to the freeze, did not soften his criticism. He described the strategy as a predatory legal maneuver and said the firm was effectively attempting to benefit from research and tracing work carried out by others in the crypto ecosystem.
His concern goes beyond rhetoric. According to the report, this type of intervention could slow down legitimate recovery efforts, complicate legal proceedings, and create further delays while bad actors continue moving any remaining unfrozen assets. In cases involving sophisticated laundering operations, time is often one of the most important variables. Any delay can weaken the chances of meaningful restitution.
The backlash appears to reflect a broader frustration inside the crypto community. Investigators, protocols, security teams, and victims often work under intense pressure after a major exploit to identify addresses, freeze funds, and coordinate with infrastructure providers. When an unrelated claimant tries to redirect those assets through litigation, many in the industry view it as a direct threat to the principle that recoveries should prioritize those actually harmed by the incident.
Community DAO proposal gains support
In response to the law firm’s reported actions, ZachXBT proposed that the crypto community form a DAO to coordinate legal opposition. While the structure and scope of such an initiative remain unclear, the suggestion received immediate support, highlighting how strongly market participants feel about defending victim recovery rights in major exploit cases.
The DAO idea is significant because it reflects a familiar pattern in crypto: when traditional legal systems move slowly or appear vulnerable to opportunistic claims, communities look for collective coordination models to fund, organize, and support action. In this case, the proposal is not about replacing the courts, but about making sure the voices of real victims are not drowned out by better-resourced legal actors pursuing older and unrelated judgments.
Whether such a coordinated effort would be effective in court is another matter. Still, the proposal underscores how asset recovery in crypto is increasingly becoming a hybrid battlefield, where on-chain enforcement, private investigation, and traditional litigation all intersect.
Lazarus remains a dominant threat in crypto crime
The larger context helps explain why the case is attracting so much attention. The report states that Lazarus Group has stolen more than $6 billion in crypto since 2017, and is responsible for 76% of all crypto hack losses recorded so far in 2026. Those numbers reinforce the scale of the challenge facing both protocols and investigators.
The KelpDAO exploit is not presented as an isolated event. It reportedly followed another major incident in early April 2026, when Lazarus was suspected of stealing roughly $285 million from Drift Protocol. Taken together, these attacks suggest that state-linked cyber operations continue to evolve rapidly, exploiting technical vulnerabilities while also benefiting from the fragmented legal environment that governs digital asset recovery.
That is why the dispute over the frozen $71 million matters beyond a single protocol or a single law firm. It touches on whether emergency freezes can reliably preserve value for direct victims, or whether those assets may become entangled in broader legal contests that have little to do with the original exploit.
A new front in post-hack recovery
For years, post-hack crypto recovery has focused on tracing stolen funds, identifying exchange off-ramps, and persuading blockchain governance bodies or centralized intermediaries to freeze assets when possible. The KelpDAO case shows that even after a successful freeze, the battle may be far from over.
If courts ultimately allow unrelated claimants to attach frozen exploit proceeds through older judgments, future recoveries could become much more complicated. Victims would face not only the technical and jurisdictional barriers posed by sophisticated hackers, but also a second layer of competition from third parties seeking to capture frozen funds through legal channels.
That possibility introduces a troubling dynamic for the industry. Emergency intervention on-chain is often justified as a way to preserve assets for restitution. But if preserved assets can later be diverted elsewhere, confidence in those interventions could weaken. At minimum, the case raises urgent questions about legal priority, fairness, and the treatment of frozen digital assets linked to sanctions, cybercrime, and state-backed hacking groups.
For now, the outcome remains unresolved. What is clear is that the frozen 30,766 ETH has become the center of a wider conflict over who gets paid, who gets protected, and how crypto justice should work when stolen funds are intercepted before they disappear completely. Whether the money eventually reaches the actual KelpDAO victims—or is rerouted through the courts—will likely be watched closely across the digital asset industry.

