Threat Intelligence

Suspected North Korean DeFi backdoor attack thwarted

Computer keyboard, close-up button of the flag of North Korea.

Thousands of smart contracts with over $10 million in funds were discovered by Venn Network researcher Deebeez to have been compromised with a backdoor in a suspected attack by the North Korean hacking collective Lazarus Group, according to Cybernews.

Despite the months-long exposure of the smart contracts, most of the funds have been recovered following efforts after a 36-hour effort conducted alongside Dedaub and SEAL 911 team researchers, said Deebeez, who noted that threat actors' exploitation of uninitialized ERC1967Proxy contracts enabled not only malicious implementations but also the impersonation of Etherscan UI. "Some protocols reconfigured contracts, others upgraded to withdraw $100Ks safely. We secured major DeFi protocols and bridges before the hacker acted," Deebeez added. Further analysis by Artem Chystiakov revealed the attack to involve proxy contract injection as a nefarious implementation prior to the retrieval of the actual implementation.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds