North Korea's Crypto Theft Tactics Are Expanding, with DeFi Being a Prime Target
Less than three weeks after hackers linked to North Korea used social engineering to breach the crypto trading firm Drift, another major exploit has been carried out, this time targeting Kelp, a restaking protocol connected to LayerZero's cross-chain infrastructure. This attack suggests that North Korea-linked hackers are evolving their tactics, moving beyond exploiting bugs or stolen credentials to manipulating the fundamental assumptions built into decentralized systems. The combined impact of these two incidents points to a more organized effort by North Korea to hijack funds from the crypto sector, with over $500 million siphoned off in just over two weeks. Experts describe this as a 'cadence' rather than isolated incidents, indicating a structured approach to these hacks. The Kelp exploit highlights a significant security failure where attackers manipulated data inputs, forcing the system to approve transactions that did not actually occur, exploiting the system's design rather than breaking encryption. This has led to recommendations for using multiple independent verifiers to approve cross-chain messages, akin to requiring multiple signatures on a bank transfer. The fallout extends beyond Kelp, affecting lending platforms like Aave that accepted impacted assets as collateral, demonstrating how problems can spread across DeFi systems. The incident also reveals a gap between the marketing of decentralization and its actual implementation, with single verifiers being a centralized point of failure in otherwise decentralized systems. Experts caution that decentralization is a series of choices and that the strength of a system lies in its most centralized layer, emphasizing the need for robust security measures to protect against exploits that target the less visible layers of crypto infrastructure.