North Korea's Cryptocurrency Theft Tactics Are Evolving, with DeFi Being a Prime Target
Less than three weeks after hackers linked to North Korea used social engineering to breach the crypto trading firm Drift, another major exploit has been attributed to the nation, this time targeting Kelp, a restaking protocol connected to LayerZero's cross-chain infrastructure. This attack suggests that North Korea-linked hackers are adapting their methods, moving beyond exploiting bugs or stolen credentials to manipulating the fundamental assumptions underlying decentralized systems. The combined impact of these incidents points to a more organized effort by North Korea to siphon funds from the crypto sector, with over $500 million stolen in just over two weeks. Experts describe this as a sustained campaign rather than isolated incidents, with a 'cadence' that implies a planned series of attacks. The Kelp exploit did not involve breaking encryption but rather manipulating the data input into the system, forcing it to approve transactions that did not occur. This highlights a security failure where the system checked the sender's identity but not the truth of the message itself. A key issue was Kelp's reliance on a single verifier to approve cross-chain messages, a configuration choice that removed a critical safety layer. In response, LayerZero has recommended using multiple independent verifiers, akin to requiring multiple signatures on a bank transfer. However, some argue that LayerZero's default setup was to use a single verifier, emphasizing that security should not depend on users following documentation correctly. The impact of the exploit has spread beyond Kelp, affecting lending platforms like Aave that accepted the impacted assets as collateral, turning a single exploit into a broader stress event. This incident also exposes a gap between the marketing of decentralization and its actual implementation, with experts noting that a single verifier is not truly decentralized. Decentralization is seen as a series of choices, and the system's strength is only as good as its most centralized layer. The attack on Kelp and the broader trend of targeting cross-chain and restaking infrastructure suggest that attackers are focusing on the less visible but critical layers of the crypto ecosystem, such as data providers or infrastructure, which can have weak points. This shift may explain why groups like Lazarus are targeting these areas, which are complex, hold large amounts of value, and are increasingly attractive targets. The biggest risk to the crypto sector may not be unknown vulnerabilities but known ones that are not fully addressed, with the Kelp exploit demonstrating how exposed the ecosystem remains to familiar weaknesses, especially when security is treated as a recommendation rather than a requirement.