North Korea's Cryptocurrency Theft Tactics Are Evolving, with DeFi Being a Prime Target

Less than three weeks after hackers with ties to North Korea used social engineering to breach the cryptocurrency trading firm Drift, another significant exploit has been carried out against Kelp, a restaking protocol connected to LayerZero's cross-chain infrastructure. This attack suggests that North Korea-linked hackers are adapting their methods, no longer just seeking out vulnerabilities or stolen credentials, but also exploiting fundamental assumptions within decentralized systems. The combined impact of these two incidents points to a more organized effort by North Korea to siphon funds from the cryptocurrency sector, indicating a sustained campaign rather than isolated breaches. More than $500 million was stolen across these exploits in just over two weeks. The Kelp breach did not involve breaking encryption but rather manipulating data inputs to force the system to approve non-existent transactions. This highlights a security failure where the system's design allowed for compromised inputs to be trusted, based on the sender's identity rather than the truth of the message itself. Experts view this as exploiting the system's setup rather than introducing a new hack. A key issue was the use of a single verifier for cross-chain messages, a choice that prioritized speed and simplicity over security. In response, recommendations have been made to use multiple independent verifiers, akin to requiring multiple signatures on a financial transaction. However, the default setup of LayerZero, the infrastructure behind Kelp, has been a point of contention, with some arguing it was designed to use a single verifier. The fallout from the Kelp exploit has extended beyond the platform itself, affecting lending platforms like Aave that accepted impacted assets as collateral, thus turning a single exploit into a broader stress event. This situation also reveals a disconnect between the marketing of decentralization and its actual implementation, with centralized elements within supposedly decentralized systems creating vulnerabilities. Decentralization is not an inherent property of a system but rather a series of choices, and the resilience of a system is only as strong as its most centralized component. The focus of attackers like Lazarus has shifted towards the less visible but critical layers of crypto infrastructure, such as cross-chain and restaking protocols, which are complex, hold significant value, and are increasingly targeted. The biggest risk to the crypto sector may not be new, unknown vulnerabilities but rather the failure to fully address known weaknesses, especially when security is treated as optional rather than mandatory. As attackers adapt and move more quickly, the gap between security measures and exploits is becoming both easier to exploit and more costly to ignore.