A six-month infiltration campaign by North Korea at Drift sent shockwaves through the crypto industry, which was already reeling from billion-dollar hacks. However, a more pressing question emerged: why does North Korea persist in targeting crypto, and what makes its approach distinct from other state-sponsored hacking operations?

According to security experts, the answer lies in crypto's ability to provide the regime with a vital revenue stream. North Korea lacks the luxury of patience due to comprehensive international sanctions, necessitating hard currency to fund its weapons programs.

The UN and multiple intelligence agencies have confirmed that crypto theft is a primary funding mechanism for the regime's nuclear and ballistic missile development. This urgency explains why North Korean hackers execute large-scale, traceable heists on public blockchains instead of discreetly using crypto to evade sanctions like other state actors.

The reason, as explained by Dave Schwed, is structural: unlike Russia and Iran, which have functioning economies and use crypto as a payment rail, North Korea has almost nothing to sell due to heavily sanctioned exports. Consequently, the regime requires direct revenue, which crypto theft provides through immediate access to liquid value globally without needing a willing counterparty. This distinction - crypto as infrastructure versus crypto as a target - sets North Korea apart from Russia and Iran. While Russia and Iran use crypto to work around sanctions and fund proxy networks, North Korea operates a state-sponsored heist operation, targeting exchanges, wallet providers, DeFi protocols, and individual engineers with signing authority or infrastructure access.

In contrast, Russia and Iran treat crypto as incidental, a means to broader geopolitical ends, targeting elections, energy infrastructure, and government systems. North Korea's singular focus has driven its operatives to adopt tactics akin to those of intelligence agencies, including months-long relationship building, fabricated identities, and supply chain infiltration. The Drift campaign exemplifies this approach. The crypto ecosystem's architecture makes it an attractive hunting ground, as it lacks the safeguards present in traditional finance, such as compliance checks and settlement delays.

Once a crypto transaction is signed and confirmed, it is final, making it challenging to defend against attacks. The finality of crypto transactions fundamentally alters the security calculus, necessitating a focus on prevention rather than response. While banks operate under decades of regulatory guidance, many crypto projects prioritize speed and innovation over governance and controls, creating an environment where even sophisticated teams can be vulnerable to infiltration tactics. This operational security problem remains unresolved, posing a significant challenge to the crypto industry.