The recent six-month infiltration campaign targeting Drift has sent shockwaves through the crypto community, still reeling from massive billion-dollar exploits. However, a more pressing question has emerged: what drives North Korea's persistent focus on crypto, and why does its approach differ from other state-backed hacking operations? According to security experts, crypto provides the regime with a vital revenue stream, enabling it to stay afloat.
North Korea's urgent need for hard currency to fund its weapons programs, due to comprehensive international sanctions, makes crypto theft a primary funding mechanism for its nuclear and ballistic missile development. This urgency explains why North Korean hackers carry out large-scale, traceable heists on public blockchains instead of quietly using crypto to evade sanctions. The answer lies in the structural differences between North Korea and other state actors. Unlike Russia and Iran, which have functioning economies and use crypto as a payment rail to work around sanctions, North Korea has almost nothing to sell and needs direct revenue.
Crypto theft gives North Korea immediate access to liquid value globally without requiring a counterparty willing to do business with them. This distinction - crypto as infrastructure versus crypto as a target - sets North Korea apart from Russia and Iran. While Russia and Iran use crypto to fund broader geopolitical goals, North Korea operates a state-sponsored heist operation, targeting exchanges, wallet providers, DeFi protocols, and individual engineers and founders with signing authority or infrastructure access.
The victim is whoever holds the keys or access to the infrastructure that holds the keys. Russia and Iran, by comparison, treat crypto as incidental to their broader objectives, targeting elections, energy infrastructure, government systems, dissidents, and regional adversaries. North Korea's singular focus on crypto has led to the adoption of tactics more commonly associated with intelligence agencies, including months-long relationship building, fabricated identities, and supply chain infiltration.
The Drift campaign is a recent example. Crypto's architecture makes it an attractive hunting ground, with no safeguards like compliance checks, correspondent bank checks, settlement delays, or the possibility of reversing fraudulent transfers.
Once a transaction is signed and confirmed, it's final, making it essential to stop attacks before they happen. The gap in regulatory guidance and audit requirements between traditional banking and crypto creates an environment where even sophisticated teams can be vulnerable to long-term infiltration tactics. This is the hardest operational security problem in crypto right now, and the industry has yet to find a solution.