A recent six-month infiltration campaign by North Korea at Drift has left the crypto industry on high alert, prompting a deeper examination of the regime's motivations and tactics. According to security experts, North Korea's reliance on crypto stems from its need for a revenue stream to stay afloat under comprehensive international sanctions. "North Korea lacks the luxury of patience," notes Dave Schwed, COO at SVRN and founder of Yeshiva University's cybersecurity masters program.

"They require hard currency to fund their weapons programs, and crypto theft has been confirmed by the UN and multiple intelligence agencies as a primary funding mechanism for their nuclear and ballistic missile development." This sense of urgency explains why North Korean hackers opt for large-scale, traceable heists on public blockchains, rather than using crypto to quietly evade sanctions like other state actors. The reason, Schwed argues, lies in the structural differences between North Korea and other sanctioned nations like Russia and Iran. While Russia and Iran have economies that can utilize crypto as a payment rail, North Korea's exports are heavily sanctioned, leaving it with almost nothing to sell.

"Their economy is non-functional, and they need direct revenue," Schwed explains. "Crypto theft provides them with immediate access to liquid value globally, without requiring a willing counterparty." This distinction – crypto as a means to an end versus crypto as the primary target – sets North Korea apart from Russia and Iran. Unlike Russia, which uses crypto to work around sanctions, and Iran, which uses it to fund proxy networks, North Korea operates a state-sponsored heist operation. "Their targets include exchanges, wallet providers, DeFi protocols, and individual engineers and founders with signing authority or infrastructure access," says Alexander Urbelis, CISO at ENS Labs and a professor of cybersecurity at King’s College London.

"The victim is whoever holds the keys or access to the infrastructure that holds the keys." In contrast, Russia and Iran view crypto as a secondary means to broader geopolitical ends. "Russia targets elections, energy infrastructure, and government systems, while Iran goes after dissidents and regional adversaries," Urbelis notes. "When either of them touches crypto, it's to move money, not to steal it from the ecosystem." North Korea's singular focus has led its operatives to adopt tactics reminiscent of intelligence agencies, including months-long relationship building, fabricated identities, and supply chain infiltration.

The Drift campaign is a prime example of this approach. "You're not defending against a random phishing email, but against someone who spent six months building a relationship to compromise one person with the necessary access," Urbelis warns.

The inherent architecture of crypto makes it an attractive hunting ground for North Korea. Unlike traditional finance, where successful hacks encounter friction in the form of compliance checks and settlement delays, crypto lacks these safeguards at the protocol level. "Once a transaction is signed and confirmed, it's final," Urbelis emphasizes.

The speed and scale of crypto transactions, such as the $1.5 billion Bybit exploit, would be nearly impossible in the traditional banking system. This finality fundamentally alters the security calculus, making it essential to stop attacks before they happen. While banks operate under decades of regulatory guidance and audit requirements, many crypto projects are still improvising, often prioritizing speed and innovation over governance and controls.

The resulting gap creates an environment where even sophisticated teams can be vulnerable to North Korea's refined infiltration tactics. "This is the hardest operational security problem in crypto right now," Urbelis acknowledges. "I don't think the industry has solved it." As the crypto community rethinks its security measures in response to North Korea's 6-month secret espionage program, one thing is clear: the regime's billion-dollar crypto heists are a symptom of a larger problem that requires a fundamental shift in the industry's approach to security.