North Korea's Crypto Theft Tactics are Evolving, with DeFi Being a Prime Target
Less than three weeks after hackers linked to North Korea used social engineering to breach the crypto trading firm Drift, it appears that another major exploit has been carried out, this time targeting Kelp, a restaking protocol connected to LayerZero's cross-chain infrastructure. This attack suggests that North Korea-linked hackers are adapting their tactics, moving beyond exploiting bugs or stolen credentials to manipulating the fundamental assumptions underlying decentralized systems. The combined impact of the Drift and Kelp incidents points to a more organized effort by North Korea to siphon funds from the crypto sector. According to Alexander Urbelis, Chief Information Security Officer and General Counsel at ENS Labs, 'This is not a series of incidents; it is a cadence. You cannot patch your way out of a procurement schedule.' The Kelp exploit did not involve breaking encryption but rather manipulating the data fed into the system, forcing it to rely on compromised inputs and approve non-existent transactions. The security failure lies in the system's design, where it checks the sender's identity but not the validity of the message itself. Experts view this as an exploitation of the system's setup rather than a novel hacking technique. A key issue was the configuration choice to rely on a single verifier for cross-chain messages, which, although faster and simpler, removes a critical safety layer. In response, LayerZero has recommended using multiple independent verifiers, akin to requiring multiple signatures on a bank transfer. However, some argue that LayerZero's default setup was to use a single verifier, and the onus should not be on users to configure it securely. The repercussions of the exploit have extended beyond Kelp, affecting lending platforms like Aave that accepted the impacted assets as collateral, thereby turning a single exploit into a broader stress event. This incident also highlights the disparity between the marketing of decentralization and its actual implementation. As Urbelis notes, 'Decentralization is not a property a system has. It is a series of choices. And the stack is only as strong as its most centralized layer.' The attack on Kelp and similar infrastructure suggests that attackers are shifting their focus towards the less visible but critical layers of the crypto ecosystem, such as cross-chain and restaking infrastructure, which are complex, hold significant value, and are easier to misconfigure. The biggest risk may not be unknown vulnerabilities but known ones that are not fully addressed, and as attackers adapt, the gap between security recommendations and requirements is becoming more exploitable and costly to ignore.