North Korea's Crypto Theft Tactics Are Evolving, with DeFi Being a Prime Target

Barely three weeks after North Korea-linked hackers used social engineering to breach the crypto trading firm Drift, another significant exploit was carried out against Kelp, a restaking protocol connected to LayerZero's cross-chain infrastructure. This attack suggests that North Korea-linked hackers are adapting their tactics, moving beyond exploiting bugs or stolen credentials to manipulate the fundamental assumptions underlying decentralized systems. The combined impact of these incidents points to a more organized campaign, as North Korea intensifies its efforts to siphon funds from the crypto sector. According to Alexander Urbelis, Chief Information Security Officer and General Counsel at ENS Labs, 'This is not a series of isolated incidents; it's a systematic approach. You cannot resolve these issues merely by patching them, as they are part of a larger procurement schedule.' Over $500 million was stolen across the Drift and Kelp exploits in just over two weeks. The Kelp breach did not involve breaking encryption or cracking keys; instead, attackers manipulated the data input into the system, forcing it to rely on compromised data and approve non-existent transactions. 'The security failure is straightforward: a signed lie is still a lie,' Urbelis explained. 'Signatures confirm authorship but do not guarantee the truth.' In simpler terms, the system verified the sender of the message but not the message's accuracy. For security experts, this exploit highlights the manipulation of the system's setup rather than the discovery of a new hack. 'This attack wasn't about breaking cryptography; it was about exploiting the system's configuration,' said David Schwed, COO of blockchain security firm SVRN. A key issue was the configuration choice to rely on a single verifier to approve cross-chain messages, which, although faster and simpler to set up, removes a critical safety layer. Following the incident, LayerZero recommended using multiple independent verifiers to approve transactions, similar to requiring multiple signatures on a bank transfer. However, some in the ecosystem have pushed back, stating that LayerZero's default setup was to use a single verifier. 'If you've identified a configuration as unsafe, don't offer it as an option,' Schwed advised. 'Security that depends on everyone reading the documentation and getting it right is not realistic.' The impact has not been limited to Kelp, as its assets are used across multiple platforms, leading to a wider stress event. 'These assets are a chain of IOUs,' Schwed noted. 'And the chain is only as strong as the controls on each link.' When one link breaks, others are affected, with lending platforms like Aave, which accepted the impacted assets as collateral, now dealing with losses. The attack also reveals a gap between the marketing of decentralization and its actual implementation. 'A single verifier is not decentralized; it's a centralized decentralized verifier,' Schwed pointed out. Urbelis broadened the perspective, 'Decentralization is not a property a system has; it's a series of choices. And the stack is only as strong as its most centralized layer.' In practice, this means that even systems appearing decentralized can have weak points, particularly in less visible layers like data providers or infrastructure, where attackers are increasingly focusing. This shift may explain the recent targeting by Lazarus. The group has begun focusing on cross-chain and restaking infrastructure, Urbelis said, the parts of crypto that move assets between systems or allow them to be reused. These layers are critical but complex, often underlying more visible applications, and they tend to hold large amounts of value, making them attractive targets. If earlier crypto hacks focused on exchanges or obvious code flaws, recent activity suggests a move toward the industry's underlying infrastructure, the systems that connect everything together but are harder to monitor and easier to misconfigure. As Lazarus adapts, the biggest risk may not be unknown vulnerabilities but known ones that are not fully addressed. The Kelp exploit did not introduce a new kind of weakness; it showed how exposed the ecosystem remains to familiar vulnerabilities, especially when security is treated as a recommendation rather than a requirement. And as attackers move faster, this gap is becoming both easier to exploit and far more expensive to ignore.