North Korea's Cryptocurrency Theft Tactics Are Evolving, With DeFi Being a Prime Target
Less than three weeks after hackers linked to North Korea used social engineering to breach the crypto trading firm Drift, another major exploit has been attributed to the nation, this time targeting Kelp, a restaking protocol connected to LayerZero's cross-chain infrastructure. This attack signifies an evolution in the tactics employed by North Korean hackers, shifting from exploiting bugs or stolen credentials to manipulating fundamental assumptions in decentralized systems. The combined incidents of Drift and Kelp suggest a more organized effort by North Korea to siphon funds from the cryptocurrency sector. According to Alexander Urbelis, Chief Information Security Officer and General Counsel at ENS Labs, 'This is not a series of incidents; it is a cadence. You cannot patch your way out of a procurement schedule.' More than $500 million was lost across these two exploits in just over two weeks. The Kelp breach was unique in that it did not involve breaking encryption or cracking keys; instead, attackers manipulated the data input into the system, forcing it to rely on compromised data and approve non-existent transactions. As Urbelis noted, 'The security failure is simple: a signed lie is still a lie. Signatures guarantee authorship; they do not guarantee truth.' This exploit highlights the system's vulnerability to manipulation rather than a sophisticated new hack. David Schwed, COO of blockchain security firm SVRN, echoed this sentiment, stating, 'This attack wasn’t about breaking cryptography; it was about exploiting how the system was set up.' A key issue was the configuration choice to rely on a single verifier to approve cross-chain messages, a decision made for simplicity and speed but one that removes a critical safety layer. In response, LayerZero has recommended using multiple independent verifiers, akin to requiring multiple signatures on a bank transfer. However, some argue that LayerZero's default setup was to have a single verifier, and the onus is on the company not to provide unsafe configurations as options. The ripple effects of the exploit have extended beyond Kelp, as its assets are utilized across multiple platforms, creating a chain of IOUs where the strength of the chain is only as robust as the controls on each link. When one link breaks, others are affected, leading to lending platforms like Aave facing losses after accepting impacted assets as collateral, thereby turning a single exploit into a broader stress event. The incident also exposes the disparity between the marketing of decentralization and its actual implementation. As Schwed pointed out, 'A single verifier is not decentralized; it’s a centralized decentralized verifier.' Urbelis expanded on this, saying, 'Decentralization is not a property a system has. It is a series of choices. And the stack is only as strong as its most centralized layer.' This means that even seemingly decentralized systems can have weak points, particularly in less visible layers such as data providers or infrastructure, which are increasingly the focus of attackers. The recent targeting by the Lazarus group of cross-chain and restaking infrastructure, critical but complex layers that move assets between systems or allow them to be reused, underscores this shift. These layers are not only vital but also hold significant value, making them attractive targets. The evolution of crypto hacks, from targeting exchanges or obvious code flaws to focusing on the industry's underlying infrastructure, suggests a move toward exploiting known vulnerabilities that are not fully addressed. The Kelp exploit did not reveal a new kind of weakness but demonstrated how exposed the ecosystem remains to familiar ones, especially when security is treated as a recommendation rather than a requirement. As attackers adapt and move faster, this gap becomes both easier to exploit and more costly to ignore.