A recent six-month infiltration campaign by North Korea at Drift has sent shockwaves through the crypto industry, which is still reeling from massive exploits. As the news settles, a pressing question emerges: what drives North Korea's persistent pursuit of crypto, and why does its approach differ from other state-backed hacking operations? According to security experts, crypto provides the regime with a vital revenue stream, enabling it to stay afloat. 'North Korea lacks the luxury of patience,' notes Dave Schwed, chief operating officer at SVRN.
'Under comprehensive international sanctions, they require hard currency to fund their weapons programs, with crypto theft serving as a primary funding mechanism for their nuclear and ballistic missile development.' This urgency explains why North Korean hackers execute large-scale, traceable heists on public blockchains, rather than quietly using crypto to evade sanctions like other state actors. The answer lies in the structural differences between North Korea and other nations. Unlike Russia and Iran, which have functioning economies and use crypto as a payment rail, North Korea has almost nothing to sell, with its exports largely sanctioned. 'Their exports are almost entirely sanctioned, and they don't have a functioning economy that needs a payment rail,' Schwed explains.
'They need direct revenue, and crypto theft gives them immediate access to liquid value globally, without requiring a counterparty willing to do business with them.' This distinction – crypto as infrastructure versus crypto as a target – sets North Korea apart from Russia and Iran. While Russia and Iran use crypto to work around sanctions and fund proxy networks, North Korea operates a state-sponsored heist operation, targeting exchanges, wallet providers, DeFi protocols, and individual engineers and founders with signing authority or infrastructure access.
'The victim is whoever holds the keys or access to the infrastructure that holds the keys,' says Alexander Urbelis, chief information security officer at ENS Labs. Russia and Iran, by contrast, view crypto as incidental to their broader geopolitical goals, targeting elections, energy infrastructure, and government systems, rather than the crypto ecosystem itself. North Korea's singular focus has led its operatives to adopt tactics more commonly associated with intelligence agencies, including months-long relationship building, fabricated identities, and supply chain infiltration. The Drift campaign is a recent example of this approach.
'You're not defending against a phishing email from a random scammer,' Urbelis notes. 'You're defending against someone who spent six months building a relationship specifically to compromise one person who has the access you need to protect.' The architecture of crypto itself makes it an attractive hunting ground for North Korea. In traditional finance, successful hacks encounter friction in the form of compliance checks and settlement delays, allowing for the reversal of fraudulent transfers. In crypto, these safeguards do not exist at the protocol level, making it a uniquely attractive target.
'Once a transaction is signed and confirmed, it's final,' Urbelis says. The speed and scale of crypto transactions – such as the $1.5 billion Bybit exploit, which occurred in just 30 minutes – would be nearly impossible in the traditional banking system. This finality fundamentally changes the security calculus, as stopping an attack before it happens is essentially the only option.
While banks operate under decades of regulatory guidance and audit requirements, many crypto projects are still improvising, prioritizing speed and innovation over governance and controls. This gap creates an environment where even sophisticated teams can be vulnerable to North Korea's refined infiltration tactics. 'This is the hardest operational security problem in crypto right now,' Urbelis says. 'I don't think the industry has solved it.'