A recent six-month infiltration campaign by North Korea at Drift has left the crypto industry reeling, prompting questions about the regime's motivations and methods. According to security experts, North Korea's reliance on crypto stems from its need for a revenue stream to fund its weapons programs, given the comprehensive international sanctions it faces. Unlike other state-backed hackers, North Korea's approach is distinct in that it uses crypto as a direct source of revenue, rather than as a means to evade sanctions or facilitate other illicit activities. This difference in approach is what makes North Korea a unique and formidable threat to the crypto ecosystem.
The regime's operatives have adopted sophisticated tactics, including months-long relationship building, fabricated identities, and supply chain infiltration, to target exchanges, wallet providers, DeFi protocols, and individual engineers and founders. The crypto industry's lack of traditional safeguards, such as compliance checks and settlement delays, makes it an attractive target for North Korea's hackers. The finality of crypto transactions also changes the security calculus, making it essential to stop attacks before they happen. The challenge of vetting against sophisticated fake identities and third-party intermediaries is a significant operational security problem in crypto, one that the industry has yet to solve.