The recent six-month infiltration campaign by North Korea at Drift has raised concerns in the crypto industry, which is still reeling from billion-dollar exploits. But a more pressing question has emerged: why does North Korea continue to target crypto, and what makes its approach distinct from other state-backed hacking operations? According to security experts, the answer lies in the fact that crypto provides the regime with a vital revenue stream. North Korea is under comprehensive international sanctions and requires hard currency to fund its weapons programs.

The UN and multiple intelligence agencies have confirmed that crypto theft is a primary funding mechanism for its nuclear and ballistic missile development. This urgency explains why North Korean hackers carry out large-scale, traceable heists on public blockchains, rather than using crypto to quietly evade sanctions like other state actors. The reason, according to Dave Schwed, chief operating officer at SVRN, is structural. Unlike Russia and Iran, which have functioning economies and use crypto as a payment rail, North Korea has almost nothing to sell.

Its exports are largely sanctioned, and it lacks a functioning economy that needs a payment rail. Instead, it requires direct revenue, which crypto theft provides. This distinction – crypto as infrastructure versus crypto as a target – sets North Korea apart from other state-backed hackers.

While Russia and Iran use crypto to work around sanctions and fund proxy networks, North Korea is running a state-sponsored heist operation, targeting exchanges, wallet providers, DeFi protocols, and individual engineers and founders. The crypto industry's architecture makes it an attractive hunting ground, with its lack of safeguards, such as compliance checks and settlement delays, making it easier for hackers to carry out large-scale heists.

The finality of crypto transactions also changes the security calculus, making it essential to stop attacks before they happen. The industry's regulatory gaps and prioritization of speed and innovation over governance and controls create an environment where even sophisticated teams can be vulnerable to long-term infiltration tactics. As Alexander Urbelis, chief information security officer at ENS Labs, notes, this is the hardest operational security problem in crypto right now, and the industry has yet to solve it.