North Korea's Cryptocurrency Theft Strategy Expands, Targeting DeFi
Less than three weeks after hackers linked to North Korea used social engineering to breach the crypto trading firm Drift, another major exploit has been attributed to the nation, this time targeting Kelp, a restaking protocol connected to LayerZero's cross-chain infrastructure. This attack signifies an evolution in the tactics employed by North Korea-linked hackers, who are now exploiting fundamental assumptions built into decentralized systems, rather than merely seeking out bugs or stolen credentials. The combined incidents of Drift and Kelp suggest a more organized effort by North Korea to siphon funds from the cryptocurrency sector. According to Alexander Urbelis, Chief Information Security Officer and General Counsel at ENS Labs, 'This is not a series of incidents; it is a cadence. You cannot patch your way out of a procurement schedule.' The Kelp exploit, which did not involve breaking encryption or cracking keys, manipulated the data feeding into the system, forcing it to rely on compromised inputs and approve transactions that never occurred. This highlights a security failure where 'a signed lie is still a lie,' as signatures guarantee authorship but not truth. The system checked the sender of the message, not the message's accuracy, making this exploit more about manipulating the system's setup than about a novel hacking technique. A key issue was the configuration choice of relying on a single verifier to approve cross-chain messages, which, although faster and simpler to set up, removes a critical safety layer. In response, LayerZero has recommended using multiple independent verifiers to approve transactions, akin to requiring multiple signatures on a bank transfer. However, some have argued that LayerZero's default setup was to have a single verifier, raising questions about the balance between ease of use and security. The fallout from the Kelp exploit has extended beyond the platform itself, as its assets are utilized across multiple platforms, leading to a wider stress event. Lending platforms like Aave, which accepted the impacted assets as collateral, are now dealing with losses. This incident also exposes the gap between the marketing of decentralization and its actual implementation, with a single verifier not being truly decentralized. As Alexander Urbelis noted, 'Decentralization is not a property a system has. It is a series of choices. And the stack is only as strong as its most centralized layer.' The targeting of cross-chain and restaking infrastructure by groups like Lazarus indicates a shift towards attacking the less visible but critical layers of the crypto ecosystem, such as data providers or infrastructure, where weak points can exist, especially in complex systems that move assets between systems or allow them to be reused. These layers are not only critical but also hold large amounts of value, making them attractive targets. The recent activity suggests a move towards targeting the 'plumbing' of the crypto industry, the systems that connect everything together but are harder to monitor and easier to misconfigure. As attackers adapt, the biggest risk may not be unknown vulnerabilities but known ones that are not fully addressed, with the Kelp exploit demonstrating how exposed the ecosystem remains to familiar weaknesses, especially when security is treated as a recommendation rather than a requirement.