Unchained
Unchained

Arbitrum Froze $70M From North Korea? Griff Green on the Decision + Miguel Morel on the Hack

KelpDAO’s hackers left telltale signs pointing to one culprit, North Korea. Then, in a surprise move, the Arbitrum Security Council decided to fight back. ======================================================== Thank you to our sponsors! As Bitcoin's application layer, Citrea gives you access

Featured Speakers

Griff Green GuestMiguel Morell Guest

Topics Discussed

Episode Summary

Executive Summary: The episode dissects the KelpDAO/LayerZero exploit that let North Korea’s Lazarus Group mint fake rsETH, drain liquidity from Aave and other DeFi venues, and trigger bad debt and contagion risks across the ecosystem. Miguel Morell of Arkham explains how the funds were tracked and laundered, while Griff Green of Arbitrum details the controversial emergency freeze that recovered $70M via a non-software-upgrade L1 transaction, sparking broader debate over decentralization, security councils, and DeFi governance.

Main Topics: KelpDAO / LayerZero exploit mechanics (Priority: 5/5): The hack used a flaw in the rsETH bridge/verifier flow to fake withdrawals and create undercollateralized token supply that could be used as collateral elsewhere. Aave bad debt and DeFi contagion (Priority: 5/5): The fake rsETH was deposited into Aave, allowing the attacker to withdraw real assets and leaving protocols with worthless collateral and bad debt; the incident also caused fear across other DeFi protocols. Arkham’s detection and Lazarus attribution (Priority: 4/5): Miguel Morell explains how Arkham’s automated monitoring and analysts spotted anomalous nine-figure flows, traced them through Thorchain, and tied the laundering pattern to the Lazarus Group. Arbitrum Security Council freeze (Priority: 5/5): Griff Green describes how Arbitrum used emergency powers and forced inclusion on L1 to move attacker funds to a dead address, freezing about $70M and setting up DAO governance to decide distribution. Decentralization vs. intervention in crypto (Priority: 5/5): The discussion centers on whether protocols can or should intervene like a bank or court in emergencies, and what that means for code law, censorship resistance, and user trust. Security lessons for DeFi infrastructure (Priority: 4/5): Both guests argue for better risk analysis, wallet UX, bridge security, and coordination among security teams; Griff also promotes quadratic funding and the Dow Security Fund to improve ecosystem security.

Key Arguments: Arkham can identify exploit patterns through both automated alerting and human analysts, especially when large anomalous token movements and Thorchain deposits appear. The exploit created bad debt because a bridge-authorized token representation was treated as valid collateral, allowing the attacker to borrow real assets against fake or undercollateralized claims. DeFi contagion works like TradFi crises: once financial products are built on top of the base asset, failures in the underlying trust layer propagate rapidly through composable protocols. Emergency intervention is justified, in Griff Green’s view, when it recovers stolen user funds without harming the broader network; he argues the key accountability layer is social consensus and market expectations. Arbitrum’s freeze was only possible because the attacker left funds idle long enough and because forced inclusion let the council use an Ethereum transaction to affect Arbitrum state without upgrading node software. The controversy is less about the specific freeze and more about what powers security councils should have, how transparent their rules should be, and whether DeFi should build explicit emergency mechanisms. Long-term, the ecosystem needs stronger security tooling, better bridge and wallet UX, more rigorous technical risk analysis, and coordination mechanisms that reduce repeated hacks and fragmented defenses.

Data Points: Restaked ETH created: 116,500 rsETH tokens - Transcript says North Korea exploited the bridge and created this amount of restaked ETH out of thin air. Aave deposit amount: $270 million - Miguel states Lazarus deposited this value of wrapped rsETH into Aave. Aave withdrawal amount: $228 million - Miguel says the attacker withdrew this much wrapped ETH from Aave, creating bad debt. Funds frozen by Arbitrum: $70 million / $71 million - The discussion repeatedly cites roughly $70M-$71M frozen and recoverable by Arbitrum Security Council action. Aave optimal utilization proposal: 92% to 85% - Laura references a proposal to reduce optimal utilization in the affected stablecoin markets. Aave slope two proposal: 10% to 50% - Laura cites a proposal to raise the aggressive interest-rate slope to attract deposits and address the run. L1 transaction delay: 15 minutes - Griff explains Arbitrum’s forced inclusion path waited 15 minutes before the attacker could move funds. Funds left idle: About 48 hours - Griff says the attackers left funds in one address long enough for the freeze opportunity to be used. Security Council size: 12 members - Griff says the Arbitrum Security Council consists of 12 people. Annual turnover: 6 elected members per year - Griff describes the council as transitioning toward annual elections with six new members coming in each year. Quadratic funding round size: $1 million - Griff announces a million-dollar quadratic funding round for the Security Fund. Security projects in round: About 100 - He says nearly 100 security projects are in the funding round. DAO recovery history: $200 million - Griff references prior white-hat recovery work, including rescuing $200M in the parity multi-sig hacks. Public-good distribution threshold: Dunbar number 150 - Griff contrasts quadratic funding and DAO participation against the Dunbar number for decision-making scale.

Pivotal Quotes: "If you can stop North Korea, you do it. If you can recover users' funds, you do it." — Griff Green: Explaining why he supported freezing the stolen funds and viewing it as a justified emergency response. "Ethereum is extremely secure. It's not safe to use." — Griff Green: Summarizing his view that protocol-level security is strong, but UX, bridges, and operational practices still expose users to loss. "The whole kind of concept is a certain number of dollars of ETH, et cetera, are deposited into this bank... and somebody who's at the front of the line to withdraw, they get to take that money out." — Miguel Morell: Describing the bank-run dynamics that emerged on Aave after the exploit.

Implications: The episode signals that DeFi needs stronger bridge risk controls, emergency-response frameworks, and clearer governance norms. It also suggests attackers may adapt faster, while protocols face pressure to balance censorship resistance with user protection.

🔓 Sign Up for Unlimited Episode Search

About Unchained

View all episodes from Unchained