|
News North Korean hackers linked to $290M heist from cryptocurrency platformLazarus Group allegedly manipulated KelpDAO’s cross-chain bridge for biggest theft this year, weeks after $285M heist North Korean cybercriminals were allegedly behind the theft of over $290 million from the decentralized finance (DeFi) platform KelpDAO on Saturday, Pyongyang’s second major cryptocurrency heist in April and largest virtual theft so far this year. In a statement released Monday, KelpDAO supplier LayerZero said TraderTraitor — a unit of North Korea’s Lazarus Group — was the “likely” culprit behind the attack on KelpDAO’s cross-chain bridge, a system facilitating the movement of digital assets between different blockchain networks. After infiltrating verification systems, the attackers reportedly drained 116,500 rsETH — a digital token backed by locking the virtual currency ether on a blockchain — from KelpDAO, a liquid restaking protocol that allows users to protect assets across multiple chains and earn additional rewards. The attackers quickly used the assets stolen through faked transactions as collateral on DeFi lending platforms to borrow real funds, which sent shockwaves throughout the broader digital currency ecosystem and triggered more than $13 billion in panic withdrawals by the affected services’ users. The damage could have been even greater had the attack not been discovered immediately, according to Meir Dolev, the co-founder of blockchain security firm Cyvers. “[Kelp DAO] was just 3 minutes away from losing an additional $100M, saved only by a rapid-response blacklist that blocked the attacker before their second attempt,” he said on social media on Sunday. KelpDAO has yet to confirm whether North Korea was behind the attack, but the incident follows the theft of over $285 million earlier this month from the Solana-based trading protocol Drift, which was also attributed to DPRK operatives. HOW THE ATTACK UNFOLDED At the center of Saturday’s heist was the manipulation of a system used to verify transactions between blockchains, after attackers infiltrated the external infrastructure of LayerZero, which provides cross-chain technology to KelpDAO. Rather than breaching the core system’s code, the attackers manipulated remote procedure call (RPC) nodes, which are underlying communication lines used to verify transactions, according to LayerZero. By feeding false data about non-existent withdrawals into the system and disrupting backup channels, they were able to trick the verifier into approving transactions that never actually occurred. The attackers’ malicious software was also designed to “self-destruct” after the theft, deleting files and logs to obscure the attackers’ trail, according to LayerZero. To complete the attack, TraderTraitor reportedly flooded the remaining data sources with junk traffic through a distributed denial-of-service (DDoS) attack, forcing the verifier to rely on the poisoned ones. LayerZero pointed to supposed flaws in KelpDAO’s security as the main vulnerability, adding that the breach did not spread to other assets or applications using LayerZero’s infrastructure. The firm stressed that the scale of the theft was ultimately enabled by KelpDAO’s use of a single verifier, rather than multiple independent verifiers to reduce the risk of a single point of failure. “A properly hardened configuration would have required consensus across multiple independent verifiers, rendering this attack ineffective,” the company said. In an initial post-incident report on Monday, KelpDAO challenged LayerZero’s criticisms of its Decentralized Verifier Network (DVN) configuration. “The 1-of-1 DVN setup is the configuration documented in LayerZero’s documentation and shipped as the default for any new [Omnichain Fungible Token] deployment,” the staking service said, referring to a LayerZero standard that enables a single token to exist across multiple blockchains. KelpDAO added that it is still working with partner organizations to analyze and mitigate the impact of the theft, including LayerZero and impacted DeFi lending services. Edited by Bryan Betts © Korea Risk Group. All rights reserved. |





