North Korea Accused of Massive $290M Crypto Heist
State-sponsored North Korean cybercriminals allegedly siphoned more than $290 million in cryptocurrency from yield-generating protocol Kelp DAO over the weekend, utilizing a bridge vulnerability to pull off the largest digital asset heist of the year. The massive exploit, which targeted the platform’s idle investor funds, has triggered a high-stakes finger-pointing battle between key infrastructure providers in the decentralized finance (DeFi) space.
How the $290 Million Kelp DAO Exploit Unfolded
On Monday, interoperability protocol LayerZero publicly accused North Korean state actors of orchestrating the devastating attack. This incident officially surpasses a previous $285 million exploit at the Drift crypto exchange earlier this year, making it the most severe security breach of the year so far. According to reports, hackers stole the massive sum by targeting the connection between the decentralized networks.
In a detailed statement shared in its post on X, LayerZero explained that the perpetrators manipulated the LayerZero bridge, which serves as the communication pathway allowing different blockchains to transfer instructions. The attackers successfully weaponized Kelp DAO’s specific security setup, which lacked multi-signature verification requirements for authorizing transactions. This security gap allowed the hackers to easily authorize and execute fraudulent fund transfers without triggering security alarms.
The TraderTraitor Connection
Security investigators have already identified strong digital fingerprints linking the incident to state-sponsored actors. LayerZero pointed to “preliminary indicators” that strongly implicate TraderTraitor, a notorious elite hacking collective operated by the North Korean government specifically to target high-value cryptocurrency platforms and decentralized finance protocols.
The Blame Game: Kelp DAO Fires Back at LayerZero
Rather than accepting responsibility for the configuration oversight, Kelp DAO swiftly responded by deflecting the blame back onto LayerZero. The protocol team argues that LayerZero’s own default security configurations are the root cause of the vulnerability, setting off an intense debate within the Web3 community regarding security responsibilities between cross-chain bridges and the applications that build on them.
North Korea’s Growing $6 Billion Crypto Empire
This latest attack highlights a highly lucrative, state-sanctioned cyber warfare strategy. Over the last several years, hacking syndicates working directly under Kim Jong Un’s regime have turned cryptocurrency theft into a primary source of national revenue. Last year, North Korean cybercriminals successfully plundered over $2 billion in digital assets. Since 2017, the regime’s cumulative haul from global crypto exploits has reached an astronomical $6 billion, posing an ongoing existential threat to the global DeFi ecosystem.
