• Latest
  • Trending
North Korea’s crypto heist playbook is expanding and DeFi keeps getting hit

North Korea’s crypto heist playbook is expanding and DeFi keeps getting hit

April 20, 2026
Payward supports global operation to disrupt crypto fraud and protect clients

Payward supports global operation to disrupt crypto fraud and protect clients

April 20, 2026
Incident Report: Llamarisk, Aave Service Providers Detail Kelp rsETH Hack Across Ethereum and Arbitrum Markets

Incident Report: Llamarisk, Aave Service Providers Detail Kelp rsETH Hack Across Ethereum and Arbitrum Markets

April 20, 2026
AlphaTON Capital Relaunches as Alpha Compute Corp. to Reflect Its Growing AI Compute Business

AlphaTON Capital Relaunches as Alpha Compute Corp. to Reflect Its Growing AI Compute Business

April 20, 2026
TRUMP Token Whales Scoop $5M Ahead of Mar-a-Lago Luncheon, Price Set for Shock Move?

TRUMP Token Whales Scoop $5M Ahead of Mar-a-Lago Luncheon, Price Set for Shock Move?

April 20, 2026
Binance Top Traders Quietly Build Dogecoin Long Exposure

Binance Top Traders Quietly Build Dogecoin Long Exposure

April 20, 2026
Capital City Bank Group, Inc. (CCBG) Stock: Earnings Rise 15% as Deposits Grow and Costs Fall

Capital City Bank Group, Inc. (CCBG) Stock: Earnings Rise 15% as Deposits Grow and Costs Fall

April 20, 2026
Paul Atkins Marks One Year as SEC Chair, Changing Crypto Regulation

Paul Atkins Marks One Year as SEC Chair, Changing Crypto Regulation

April 20, 2026
Ripple Reveals Plan to Make XRP Ledger ‘Quantum-Proof’ by 2028

Ripple Reveals Plan to Make XRP Ledger ‘Quantum-Proof’ by 2028

April 20, 2026
Maryland Emerges as a National Leader in Digital Asset Innovation: Maryland Blockchain Association Celebrates Historic Legislative Sweep

Maryland Emerges as a National Leader in Digital Asset Innovation: Maryland Blockchain Association Celebrates Historic Legislative Sweep

April 20, 2026
  • Privacy Policy
Monday, April 20, 2026
MtRushmoreCrypto - Where Crypto Rocks
  • Home
  • Top News
  • Crypto
  • Crypto Technical Analysis
  • About Us
No Result
View All Result
  • Home
  • Top News
  • Crypto
  • Crypto Technical Analysis
  • About Us
No Result
View All Result
Logo
No Result
View All Result
Home Crypto

North Korea’s crypto heist playbook is expanding and DeFi keeps getting hit

J_News by J_News
April 20, 2026
in Crypto, Top News
0
North Korea’s crypto heist playbook is expanding and DeFi keeps getting hit
0
SHARES
0
VIEWS
Share on FacebookShare on Twitter

Less than three weeks after North Korea-linked hackers used social engineering to hit crypto trading firm Drift, hackers tied to the nation appear to have pulled off another major exploit with Kelp.

The attack on Kelp, a restaking protocol tied into LayerZero’s cross-chain infrastructure, suggests an evolution in how North Korea-linked hackers operate, not just looking for bugs or stolen credentials, but exploiting the basic assumptions built into decentralized systems.

Related articles

Payward supports global operation to disrupt crypto fraud and protect clients

Payward supports global operation to disrupt crypto fraud and protect clients

April 20, 2026
Incident Report: Llamarisk, Aave Service Providers Detail Kelp rsETH Hack Across Ethereum and Arbitrum Markets

Incident Report: Llamarisk, Aave Service Providers Detail Kelp rsETH Hack Across Ethereum and Arbitrum Markets

April 20, 2026

Taken together, the two incidents point to something more organized than a string of one-off hacks, as North Korea continues to escalate its efforts to hijack funds from the crypto sector.

“This is not a series of incidents; it is a cadence,” said Alexander Urbelis, chief information security officer and general counsel at ENS Labs. “You cannot patch your way out of a procurement schedule.”

More than $500 million was siphoned across the Drift and Kelp exploits in just over two weeks.

How Kelp was breached

At its core, the Kelp exploit did not involve breaking encryption or cracking keys. The system actually worked the way it was designed to. Rather, attackers manipulated the data feeding into the system and forced it to rely on those compromised inputs, causing it to approve transactions that never actually occurred.

“The security failure is simple: a signed lie is still a lie,” Urbelis said. “Signatures guarantee authorship; they do not guarantee truth.”

In simpler terms, the system checked who sent the message, not whether the message itself was correct. For security experts, that makes this less about a clever new hack and more about exploiting how the system was set up.

“This attack wasn’t about breaking cryptography,” said David Schwed, COO of blockchain security firm SVRN. “It was about exploiting how the system was set up.”

One key issue was a configuration choice. Kelp relied on a single verifier, essentially one checker, to approve cross-chain messages. That is because it’s faster and simpler to set up, but it removes a critical safety layer.

LayerZero has since recommended using multiple independent verifiers to approve transactions in the fallout, similar to requiring multiple signatures on a bank transfer. Some in the ecosystem have pushed back on that framing, saying that LayerZero’s default setup was to have a single verifier.

“If you’ve identified a configuration as unsafe, don’t ship it as an option,” Schwed said. “Security that depends on everyone reading the docs and getting it right is not realistic.”

The fallout has not stayed limited to Kelp. Like many DeFi systems, its assets are used across multiple platforms, meaning problems can spread.

“These assets are a chain of IOUs,” Schwed said. “And the chain is only as strong as the controls on each link.”

When one link breaks, others are affected. In this case, lending platforms like Aave that accepted the impacted assets as collateral are now dealing with losses, turning a single exploit into a wider stress event.

Decentralization marketing

The attack also exposes a gap between how decentralization is marketed and how it actually works.

“A single verifier is not decentralized,” Schwed said. “It’s a centralized decentralized verifier.”

Urbelis puts it more broadly.

“Decentralization is not a property a system has. It is a series of choices,” he said. “And the stack is only as strong as its most centralized layer.”

In practice, that means even systems that appear decentralized can have weak points, especially in the less visible layers like data providers or infrastructure. Those are increasingly where attackers are focusing.

That shift may explain Lazarus’ recent targeting.

The group has begun zeroing in on cross-chain and restaking infrastructure, Urbelis said, the parts of crypto that move assets between systems or allow them to be reused.

These layers are critical but complex, often sitting underneath more visible applications. They also tend to hold large amounts of value, making them attractive targets.

If earlier waves of crypto hacks focused on exchanges or obvious code flaws, recent activity suggests a move toward what could be called the industry’s plumbing, the systems that connect everything together, but are harder to monitor and easier to misconfigure.

As Lazarus continues to adapt, the biggest risk may not be unknown vulnerabilities, but known ones that are not fully addressed.

The Kelp exploit did not introduce a new kind of weakness. It showed how exposed the ecosystem remains to familiar ones, especially when security is treated as a recommendation rather than a requirement.

And as attackers move faster, that gap is becoming both easier to exploit and far more expensive to ignore.

Read more: North Korean hackers are running massive state-sponsored heists to run its economy and nuclear program



Source link

ShareTweetShareShare

Related Posts

Payward supports global operation to disrupt crypto fraud and protect clients

Payward supports global operation to disrupt crypto fraud and protect clients

by J_News
April 20, 2026
0

TL;DR Payward supported Operation Atlantic, a coordinated international law enforcement effort led by the UK’s National Crime Agency and co-led...

Incident Report: Llamarisk, Aave Service Providers Detail Kelp rsETH Hack Across Ethereum and Arbitrum Markets

Incident Report: Llamarisk, Aave Service Providers Detail Kelp rsETH Hack Across Ethereum and Arbitrum Markets

by J_News
April 20, 2026
0

Key Takeaways: According to Llamarisk, an attacker exploited Kelp’s Layerzero V2 bridge on April 18, 2026, minting 116,500 rsETH without...

AlphaTON Capital Relaunches as Alpha Compute Corp. to Reflect Its Growing AI Compute Business

AlphaTON Capital Relaunches as Alpha Compute Corp. to Reflect Its Growing AI Compute Business

by J_News
April 20, 2026
0

Alpha Compute Corp. (NASDAQ: ALP) (formerly AlphaTON Capital Corp., NASDAQ: ATON) (“Alpha Compute” or the “Company”), a technology leader in...

TRUMP Token Whales Scoop $5M Ahead of Mar-a-Lago Luncheon, Price Set for Shock Move?

TRUMP Token Whales Scoop $5M Ahead of Mar-a-Lago Luncheon, Price Set for Shock Move?

by J_News
April 20, 2026
0

Key Takeaways:Large holders accumulated over $5M worth of TRUMP tokens ahead of the April 25 luncheon.On-chain data indicates aggressive withdrawals...

Binance Top Traders Quietly Build Dogecoin Long Exposure

Binance Top Traders Quietly Build Dogecoin Long Exposure

by J_News
April 20, 2026
0

Binance’s top traders are leaning more aggressively toward the long side in Dogecoin, even as broader price action remains muted....

Load More

Enter your email address:

Delivered by FeedBurner

Quick Navigate

  • Home
  • Crypto
  • Crypto Technical Analysis
  • Top News
  • Thank You
  • Store
  • About Us

Top News

Payward to acquire Bitnomial, creating a fully CFTC-licensed derivatives platform

Report: NYDIG Close to Buying Alcoa’s Massena New York Smelter Site for Bitcoin Mining Operations

XRP Just Settled $291 Million On-Chain, Almost Nothing Hit Binance: Find Out What’s Happening

© 2021 mtrushmorecrypto - Crypto Related News Blog

We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept”, you consent to the use of ALL the cookies.
Do not sell my personal information.
Cookie SettingsAccept
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT
No Result
View All Result
  • Home
  • Top News
  • Crypto
  • Crypto Technical Analysis
  • About Us

© 2021 mtrushmorecrypto - Crypto Related News Blog