North Korea's Cryptocurrency Theft Tactics are Evolving, with DeFi Being a Prime Target

Less than three weeks after hackers linked to North Korea used social engineering to breach crypto trading firm Drift, another major exploit has been discovered, this time targeting Kelp, a restaking protocol connected to LayerZero's cross-chain infrastructure. This attack suggests a shift in tactics, as North Korea-linked hackers are no longer just looking for vulnerabilities or stolen credentials, but are now exploiting the fundamental assumptions built into decentralized systems. The combined incidents point to a more organized effort by North Korea to hijack funds from the crypto sector, with over $500 million stolen in just over two weeks. According to Alexander Urbelis, chief information security officer and general counsel at ENS Labs, 'This is not a series of incidents; it is a cadence. You cannot patch your way out of a procurement schedule.' The Kelp exploit did not involve breaking encryption or cracking keys, but rather manipulating the data feeding into the system, causing it to approve transactions that never actually occurred. This highlights a security failure where the system checked who sent the message, not whether the message itself was correct. The attack has sparked a reevaluation of the security of DeFi systems, with experts emphasizing the need for multiple independent verifiers to approve transactions. The fallout from the exploit has not been limited to Kelp, with lending platforms like Aave that accepted the impacted assets as collateral now dealing with losses. The incident also exposes a gap between the marketing of decentralization and its actual implementation, with experts noting that decentralization is not a property a system has, but rather a series of choices. As North Korea continues to adapt its tactics, the biggest risk may not be unknown vulnerabilities, but known ones that are not fully addressed.