North Korea's Cryptocurrency Theft Tactics Are Evolving, with DeFi Being a Prime Target
Less than three weeks after hackers linked to North Korea used social engineering to target the crypto trading firm Drift, another major exploit has been carried out against Kelp, a restaking protocol connected to LayerZero's cross-chain infrastructure. This suggests a shift in tactics, with hackers now exploiting fundamental assumptions built into decentralized systems, rather than just looking for bugs or stolen credentials. The combined impact of these two incidents points to a more organized effort by North Korea to siphon funds from the crypto sector, with over $500 million stolen in just over two weeks. The attack on Kelp involved manipulating data inputs to force the system to approve transactions that never occurred, highlighting a security failure in the system's design. Experts describe this as exploiting the system's setup rather than a new hack, emphasizing the need for multiple independent verifiers to approve transactions. The fallout has affected not just Kelp but also other platforms like Aave, exposing a gap between the marketing of decentralization and its actual implementation. The incident reveals that even seemingly decentralized systems can have weak points, particularly in less visible layers, and that known vulnerabilities can be just as risky as unknown ones if not fully addressed.