North Korea's Expanding Crypto Hacking Strategy Targets DeFi Platforms

Less than three weeks after hackers linked to North Korea used social engineering to breach crypto trading firm Drift, another major exploit was carried out on Kelp, a restaking protocol connected to LayerZero's cross-chain infrastructure. This attack suggests an evolution in the tactics employed by North Korea-linked hackers, as they now exploit the fundamental assumptions underlying decentralized systems, rather than just seeking out bugs or stolen credentials. The combined incidents indicate a more organized effort by North Korea to intercept funds from the crypto sector, amounting to over $500 million stolen across the Drift and Kelp exploits in just over two weeks. According to Alexander Urbelis, chief information security officer and general counsel at ENS Labs, 'This is not a series of incidents; it is a cadence. You cannot patch your way out of a procurement schedule.' The Kelp breach did not involve breaking encryption but rather manipulating the data feeding into the system, forcing it to rely on compromised inputs and approve non-existent transactions. This security failure exploits the system's design, where signatures guarantee authorship but not the truth of the message. The attack highlights the issue of a single verifier being used to approve cross-chain messages, a configuration choice that removes a critical safety layer. In response, LayerZero has recommended using multiple independent verifiers, similar to requiring multiple signatures on a bank transfer. The fallout from the breach has extended beyond Kelp, affecting lending platforms like Aave that accepted the impacted assets as collateral, thus turning a single exploit into a wider stress event. The incident also exposes the gap between the marketing of decentralization and its actual implementation, with a single verifier not being truly decentralized. As Urbelis noted, 'Decentralization is not a property a system has. It is a series of choices. And the stack is only as strong as its most centralized layer.' The shift in focus towards cross-chain and restaking infrastructure, which are critical but complex and often less visible, makes them attractive targets due to the large amounts of value they hold. As attackers adapt, the biggest risk may not be unknown vulnerabilities but known ones that are not fully addressed, with the Kelp exploit demonstrating how exposed the ecosystem remains to familiar weaknesses, especially when security is treated as a recommendation rather than a requirement.