A six-month-long covert operation by North Korean hackers at Drift has sent shockwaves through the crypto industry, which is still reeling from a string of billion-dollar exploits. However, a more pressing question has emerged: what drives North Korea's relentless pursuit of crypto, and how does its approach differ from other state-sponsored hacking operations? According to security experts, the answer lies in the regime's desperate need for a revenue stream to stay afloat. 'North Korea is under comprehensive international sanctions and requires hard currency to fund its weapons programs,' explained Dave Schwed, chief operating officer at SVRN.
'Crypto theft has been confirmed by the UN and multiple intelligence agencies as a primary funding mechanism for their nuclear and ballistic missile development.' This sense of urgency explains why North Korean hackers opt for large-scale, traceable heists on public blockchains, rather than quietly using crypto to evade sanctions like other state actors. The reason, Schwed argues, is structural: Russia and Iran have functioning economies with oil, gas, and commodity exports, as well as trading partners willing to use workarounds. In contrast, North Korea has almost nothing left to sell, with its exports largely sanctioned. As a result, the regime relies on crypto theft to gain immediate access to liquid value globally, without needing a willing counterparty.
This distinction – crypto as a target rather than infrastructure – sets North Korea apart from Russia and Iran. While Russia uses crypto to work around sanctions and Iran employs it to fund proxy networks, North Korea operates a state-sponsored heist operation, targeting exchanges, wallet providers, DeFi protocols, and individual engineers with signing authority or infrastructure access. Alexander Urbelis, chief information security officer at ENS Labs, noted that North Korea's targets are 'whoever holds the keys or access to the infrastructure that holds the keys.' In contrast, Russia and Iran treat crypto as incidental, a means to broader geopolitical ends, targeting elections, energy infrastructure, and government systems. North Korea's singular focus has led its operatives to adopt tactics more commonly associated with intelligence agencies, including months-long relationship building, fabricated identities, and supply chain infiltration.
The Drift campaign is just the latest example. 'You're not defending against a random scammer, but someone who spent six months building a relationship to compromise one person with the necessary access,' Urbelis said. The architecture of crypto itself makes it an attractive hunting ground, with no safeguards like compliance checks, correspondent bank checks, or settlement delays.
Once a transaction is signed and confirmed, it's final, making it essential to stop attacks before they happen. While banks operate under decades of regulatory guidance, many crypto projects are still improvising, prioritizing speed and innovation over governance and controls.
This gap creates an environment where even sophisticated teams can be vulnerable to North Korea's refined infiltration tactics. 'This is the hardest operational security problem in crypto right now,' Urbelis said. 'I don't think the industry has solved it.'