North Korea's Expanding Crypto Theft Strategy Continues to Target DeFi
Less than three weeks after North Korea-linked hackers used social engineering to breach crypto trading firm Drift, hackers linked to the nation appear to have carried out another major exploit with Kelp. The attack on Kelp, a restaking protocol tied to LayerZero's cross-chain infrastructure, suggests an evolution in the tactics of North Korea-linked hackers, who are now exploiting the fundamental assumptions built into decentralized systems, rather than just looking for bugs or stolen credentials. The two incidents together point to a more organized effort by North Korea to hijack funds from the crypto sector, with over $500 million siphoned off in just over two weeks. According to Alexander Urbelis, chief information security officer and general counsel at ENS Labs, 'This is not a series of incidents; it is a cadence. You cannot patch your way out of a procurement schedule.' The Kelp exploit did not involve breaking encryption or cracking keys, but rather manipulating the data feeding into the system, causing it to approve transactions that never actually occurred. This highlights a security failure where 'a signed lie is still a lie,' as Urbelis noted, and signatures guarantee authorship but not truth. The system checked who sent the message, not whether the message itself was correct, making this less about a clever new hack and more about exploiting how the system was set up. A key issue was a configuration choice, with Kelp relying on a single verifier to approve cross-chain messages, which is faster and simpler but removes a critical safety layer. The fallout has extended beyond Kelp, affecting lending platforms like Aave that accepted impacted assets as collateral, and exposing a gap between the marketing of decentralization and its actual implementation. As David Schwed, COO of blockchain security firm SVRN, said, 'A single verifier is not decentralized, it's a centralized decentralized verifier.' This incident shows that even systems that appear decentralized can have weak points, especially in less visible layers, and that known vulnerabilities not fully addressed pose a significant risk as attackers adapt and move faster.