North Korea's Cryptocurrency Theft Strategy Expands, Targeting DeFi

Less than three weeks after North Korea-linked hackers used social engineering to breach crypto trading firm Drift, another major exploit has been carried out, this time on Kelp, a restaking protocol connected to LayerZero's cross-chain infrastructure. This attack suggests an evolution in the tactics of North Korea-linked hackers, who are now exploiting fundamental assumptions in decentralized systems, rather than just looking for bugs or stolen credentials. The combined incidents of Drift and Kelp point to a more organized effort by North Korea to hijack crypto funds, with over $500 million stolen in just over two weeks. According to Alexander Urbelis, chief information security officer and general counsel at ENS Labs, 'This is not a series of incidents; it is a cadence. You cannot patch your way out of a procurement schedule.' The Kelp exploit did not involve breaking encryption or cracking keys but rather manipulating the data fed into the system, forcing it to rely on compromised inputs and approve non-existent transactions. Urbelis noted, 'The security failure is simple: a signed lie is still a lie. Signatures guarantee authorship; they do not guarantee truth.' This exploit highlights a configuration issue where Kelp relied on a single verifier to approve cross-chain messages, a choice that, while faster and simpler to set up, removes a critical safety layer. In response, LayerZero has recommended using multiple independent verifiers to approve transactions. The aftermath of the exploit has not been limited to Kelp, as its assets are used across multiple platforms, leading to wider stress events, including lending platforms like Aave dealing with losses. The incident also exposes a gap between the marketing of decentralization and its actual implementation, with David Schwed, COO of blockchain security firm SVRN, stating, 'A single verifier is not decentralized. It’s a centralized decentralized verifier.' Urbelis adds, 'Decentralization is not a property a system has. It is a series of choices. And the stack is only as strong as its most centralized layer.' The shift in focus towards targeting cross-chain and restaking infrastructure, such as those used by Kelp, indicates that attackers are now focusing on the less visible but critical layers of crypto systems, which hold large amounts of value and are increasingly harder to monitor and easier to misconfigure. As North Korea continues to adapt its strategies, the biggest risk may not be unknown vulnerabilities but known ones that are not fully addressed, with the Kelp exploit showing how exposed the ecosystem remains to familiar weaknesses, especially when security is treated as a recommendation rather than a requirement.