North Korea's Cryptocurrency Theft Tactics Are Evolving, with DeFi Being a Prime Target
Less than three weeks after hackers linked to North Korea used social engineering to target the crypto trading firm Drift, another significant exploit has been carried out against Kelp, a restaking protocol connected to LayerZero's cross-chain infrastructure. This attack suggests that North Korea-linked hackers are adapting their methods, no longer just seeking out bugs or stolen credentials, but exploiting fundamental assumptions within decentralized systems. The combined incidents of Drift and Kelp point to a more organized effort by North Korea to intercept funds from the crypto sector, amounting to over $500 million in just over two weeks. According to Alexander Urbelis, chief information security officer and general counsel at ENS Labs, 'This is not a series of incidents; it is a cadence. You cannot patch your way out of a procurement schedule.' The Kelp exploit did not involve breaking encryption but rather manipulating data inputs to force the system to approve non-existent transactions. This highlights a security failure where the system verified the sender but not the truth of the message. Experts view this as exploiting the system's setup rather than introducing a new hack. A key issue was Kelp's reliance on a single verifier for cross-chain messages, a faster and simpler setup that removes a critical safety layer. In response, LayerZero has recommended using multiple independent verifiers, akin to requiring multiple signatures on a bank transfer. However, some argue that LayerZero's default setup was to use a single verifier, and the problem lies in shipping unsafe configurations as options. The impact of the exploit has not been isolated to Kelp, as its assets are used across multiple platforms, leading to a wider stress event affecting lending platforms like Aave that accepted the impacted assets as collateral. This incident also reveals a gap between the marketing of decentralization and its actual implementation, with centralized elements within supposedly decentralized systems creating vulnerabilities. Experts like Urbelis and David Schwed, COO of blockchain security firm SVRN, emphasize that decentralization is a series of choices and that the stack is only as strong as its most centralized layer. The attack on Kelp and the broader trend of targeting cross-chain and restaking infrastructure indicate a shift towards exploiting the less visible but critical layers of crypto, such as data providers or infrastructure, which can hold large amounts of value and are attractive targets. As Lazarus, a group linked to North Korea, continues to adapt and target these areas, the biggest risk may not be unknown vulnerabilities but known ones that are not fully addressed, making the gap between security recommendations and requirements both easier to exploit and more expensive to ignore.