North Korea's Cryptocurrency Theft Tactics Are Evolving, with DeFi Being a Prime Target

Less than three weeks after hackers linked to North Korea used social engineering to target the crypto trading firm Drift, another major exploit has been carried out against Kelp, a restaking protocol connected to LayerZero's cross-chain infrastructure. This attack suggests that North Korea-linked hackers are evolving their methods, moving beyond exploiting bugs or stolen credentials to manipulating the fundamental assumptions underlying decentralized systems. The combined impact of the Drift and Kelp incidents points to a more organized effort by North Korea to siphon funds from the crypto sector. According to Alexander Urbelis, chief information security officer and general counsel at ENS Labs, 'This is not a series of incidents; it is a cadence. You cannot patch your way out of a procurement schedule.' The Kelp exploit did not involve breaking encryption but rather manipulating the data fed into the system, forcing it to rely on compromised inputs and approve non-existent transactions. This exploit highlights a security failure where the system checked the sender's identity but not the truth of the message itself. Experts view this as exploiting the system's setup rather than a novel hack. A key issue was Kelp's configuration choice to rely on a single verifier for cross-chain messages, which, although faster and simpler, removes a critical safety layer. LayerZero has since recommended using multiple independent verifiers, akin to requiring multiple signatures on a bank transfer. However, some argue that LayerZero's default setup was to use a single verifier, and the onus should be on not shipping unsafe configurations as options. The impact of the Kelp exploit has not been contained and has spread to other platforms, including lending platforms like Aave that accepted the impacted assets as collateral, turning a single exploit into a broader stress event. This incident also reveals a gap between the marketing of decentralization and its actual implementation, with experts arguing that true decentralization is about making choices that prioritize security and that a single verifier is essentially a centralized point in a decentralized system. As attackers, including those linked to North Korea, continue to adapt and focus on less visible but critical layers of the crypto ecosystem like cross-chain and restaking infrastructure, the biggest risk may not be unknown vulnerabilities but known ones that are not fully addressed.