The recent six-month infiltration campaign at Drift has sent shockwaves through the crypto industry, which is still reeling from billion-dollar exploits. A pressing question has emerged: what drives North Korea to repeatedly target crypto, and why does its approach differ from other state-sponsored hacking operations? According to security experts, crypto provides the regime with a vital revenue stream.

"North Korea lacks the luxury of patience due to comprehensive international sanctions, necessitating hard currency to fund weapons programs," explained Dave Schwed, chief operating officer at SVRN. The UN and multiple intelligence agencies have confirmed that crypto theft is a primary funding mechanism for North Korea's nuclear and ballistic missile development. This urgency explains why North Korean hackers execute large-scale, traceable heists on public blockchains instead of quietly using crypto to evade sanctions like other state actors.

The answer, Schwed argues, lies in the structural differences between North Korea and other nations. Unlike Russia and Iran, which have functioning economies and use crypto as a payment rail, North Korea has almost nothing to sell due to sanctions. "Their exports are almost entirely sanctioned, and they don't have a functioning economy that needs a payment rail.

They need direct revenue," Schwed said. Crypto theft gives North Korea immediate access to liquid value globally without requiring a counterparty willing to do business with them. This distinction – crypto as infrastructure versus crypto as a target – separates North Korea from Russia and Iran. While Russia and Iran use crypto to work around sanctions and fund proxy networks, North Korea operates a state-sponsored heist operation.

"Their targets are exchanges, wallet providers, DeFi protocols, and individual engineers and founders with signing authority or infrastructure access," said Alexander Urbelis, chief information security officer at ENS Labs. Russia and Iran, by comparison, view crypto as incidental to broader geopolitical objectives. "Russia targets elections, energy infrastructure, and government systems, while Iran goes after dissidents and regional adversaries," Urbelis said. "When either of them touches crypto, it's to move money, not to steal it from the ecosystem." North Korean operatives have adopted tactics akin to intelligence agencies, including months-long relationship building, fabricated identities, and supply chain infiltration.

The Drift campaign is a recent example. "You're not defending against a random scammer's phishing email, but against someone who spent six months building a relationship to compromise one person with the necessary access," Urbelis said. Crypto's architecture makes it a uniquely attractive target. Unlike traditional finance, where successful hacks encounter friction in the form of compliance checks and settlement delays, crypto lacks these safeguards at the protocol level.

"Once a transaction is signed and confirmed, it's final," Urbelis said. The Bybit exploit, which moved $1.5 billion in 30 minutes, demonstrates the pace and scale that would be nearly impossible in traditional banking. This finality changes the security calculus, making it essential to stop attacks before they happen. While banks operate under decades of regulatory guidance, many crypto projects prioritize speed and innovation over governance and controls, creating an environment where sophisticated teams can be vulnerable to long-term infiltration tactics.

"This is the hardest operational security problem in crypto right now," Urbelis said. "I don't think the industry has solved it."