North Korea's Expanding Crypto Theft Tactics are Targeting DeFi

Less than three weeks after North Korea-linked hackers used social engineering to breach crypto trading firm Drift, another major exploit has been carried out on Kelp, a restaking protocol connected to LayerZero's cross-chain infrastructure. This attack suggests an evolution in the tactics of North Korea-linked hackers, who are no longer just looking for bugs or stolen credentials, but are now exploiting the fundamental assumptions built into decentralized systems. The two incidents together point to a more organized effort by North Korea to hijack funds from the crypto sector, with over $500 million stolen in just over two weeks. The Kelp exploit did not involve breaking encryption or cracking keys, but rather manipulated the data feeding into the system, forcing it to rely on compromised inputs and approve transactions that never occurred. This highlights a security failure where the system checked the authorship of messages, not their truthfulness. The exploit was made possible by a configuration choice that relied on a single verifier to approve cross-chain messages, removing a critical safety layer. In response, LayerZero has recommended using multiple independent verifiers to approve transactions. The fallout from the exploit has not been limited to Kelp, with lending platforms like Aave that accepted the impacted assets as collateral now dealing with losses. This incident exposes a gap between the marketing of decentralization and its actual implementation, with even seemingly decentralized systems having weak points, especially in less visible layers. The attack also highlights a shift in focus towards the 'plumbing' of the crypto industry, the systems that connect everything together but are harder to monitor and easier to misconfigure. As attackers continue to adapt, the biggest risk may not be unknown vulnerabilities, but known ones that are not fully addressed, with the gap between security recommendations and requirements becoming increasingly easy to exploit and expensive to ignore.