North Korea's Cryptocurrency Theft Tactics Are Evolving, with DeFi Being a Prime Target
Less than three weeks after hackers linked to North Korea used social engineering to breach crypto trading firm Drift, another significant exploit was carried out on Kelp, a restaking protocol connected to LayerZero's cross-chain infrastructure. This attack suggests that North Korea-linked hackers are adapting their methods, no longer just seeking vulnerabilities or stolen credentials, but also exploiting fundamental assumptions built into decentralized systems. The combined incidents of Drift and Kelp point to a more organized effort by North Korea to siphon funds from the crypto sector. According to Alexander Urbelis, Chief Information Security Officer and General Counsel at ENS Labs, 'This is not a series of incidents; it is a cadence. You cannot patch your way out of a procurement schedule.' More than $500 million was siphoned across the Drift and Kelp exploits in just over two weeks. The Kelp breach did not involve breaking encryption or cracking keys; instead, attackers manipulated the data feeding into the system, forcing it to rely on compromised inputs and approve transactions that never occurred. The security failure lies in the system's design, where it checks the sender's identity but not the truthfulness of the message. This exploit highlights the issue of configurations that prioritize speed and simplicity over security, such as relying on a single verifier to approve cross-chain messages. The fallout from the Kelp exploit has extended beyond the platform, affecting lending platforms like Aave that accepted impacted assets as collateral, turning a single exploit into a broader stress event. The attack also reveals a gap between the marketing of decentralization and its actual implementation, with single verifiers being centralized points of failure. As North Korea continues to escalate its crypto heists, the focus is shifting towards the less visible but critical layers of crypto infrastructure, such as cross-chain and restaking protocols, which hold significant value and are increasingly targeted.