A recent six-month infiltration campaign by North Korea at Drift has left the crypto industry reeling, but a more pressing question has emerged: why does North Korea continue to target crypto, and what makes its approach distinct from other state-backed hacking operations? According to security experts, crypto provides the regime with a vital revenue stream. 'North Korea lacks the luxury of patience due to comprehensive international sanctions, and it requires hard currency to fund its weapons programs,' explained Dave Schwed, Chief Operating Officer at SVRN. The UN and multiple intelligence agencies have confirmed that crypto theft is a primary funding mechanism for North Korea's nuclear and ballistic missile development.
This urgency explains why North Korean hackers carry out large-scale, traceable heists on public blockchains instead of using crypto to evade sanctions quietly. The answer lies in the structural differences between North Korea and other state actors. Unlike Russia and Iran, which have functioning economies and use crypto as a payment rail, North Korea has almost nothing to sell due to sanctions. 'Their exports are almost entirely sanctioned, and they don't have a functioning economy that needs a payment rail.
They need direct revenue,' Schwed said. Crypto theft gives North Korea immediate access to liquid value globally without needing a counterparty willing to do business with them.
This distinction – crypto as infrastructure versus crypto as a target – separates North Korea from Russia and Iran. While Russia and Iran use crypto to work around sanctions and fund proxy networks, North Korea is running a state-sponsored heist operation. 'Their targets are exchanges, wallet providers, DeFi protocols, and individual engineers and founders who have signing authority or infrastructure access,' said Alexander Urbelis, Chief Information Security Officer at ENS Labs.
The victim is whoever holds the keys or access to the infrastructure that holds the keys. Russia and Iran, by comparison, treat crypto as incidental to their broader geopolitical goals.
'Russia targets elections, energy infrastructure, and government systems. Iran goes after dissidents and regional adversaries,' Urbelis said.
'When either of them touches crypto, it's to move money, not to steal it from the ecosystem.' North Korea's singular focus has pushed its operatives to adopt tactics more commonly associated with intelligence agencies than criminal hackers, including months-long relationship building, fabricated identities, and supply chain infiltration. The Drift campaign is just the latest example.
'You're not defending against a phishing email from a random scammer; you're defending against someone who spent six months building a relationship specifically to compromise one person who has the access you need to protect,' Urbelis said. Crypto's architecture makes it an attractive hunting ground, with none of the traditional finance safeguards, such as compliance checks, correspondent bank checks, settlement delays, or the possibility of reversing fraudulent transfers. 'Once a transaction is signed and confirmed, it's final,' Urbelis said. The Bybit exploit earlier last year moved $1.5 billion in roughly 30 minutes, a pace and scale that would be nearly impossible in the traditional banking system.
This finality fundamentally changes the security calculus, making stopping an attack before it happens the only viable option. While banks operate under decades of regulatory guidance and audit requirements, many crypto projects are still improvising, often prioritizing speed and innovation over governance and controls. This gap creates an environment where even sophisticated teams can be vulnerable to long-term infiltration tactics.
'This is the hardest operational security problem in crypto right now,' Urbelis said. 'I don't think the industry has solved it.'