A recent six-month infiltration campaign targeting Drift has sent shockwaves through the crypto industry, which is still reeling from massive exploits. But a more pressing question has emerged: why does North Korea continue to target the crypto space, and what sets its approach apart from other state-sponsored hacking operations? According to security experts, the answer lies in the regime's desperate need for revenue to fund its nuclear and ballistic missile programs. 'North Korea is under intense international sanctions and requires hard currency to support its weapons programs,' explained Dave Schwed, chief operating officer at SVRN.

'Crypto theft has been confirmed by the UN and multiple intelligence agencies as a primary funding mechanism for their nuclear and missile development.' This urgency drives North Korea's hackers to carry out large-scale, traceable heists on public blockchains, rather than using crypto to quietly evade sanctions like other state actors. The reason, Schwed argues, is structural: Russia and Iran have functioning economies and use crypto as a payment rail, whereas North Korea has almost nothing to sell and needs direct revenue. 'Crypto theft provides them with immediate access to liquid value globally, without requiring a counterparty willing to do business with them,' Schwed said.

This distinction - crypto as a target rather than infrastructure - sets North Korea apart from Russia and Iran. While Russia and Iran use crypto to work around sanctions and fund proxy networks, North Korea operates a state-sponsored heist operation, targeting exchanges, wallet providers, DeFi protocols, and individual engineers with signing authority or infrastructure access. 'Their targets are those who hold the keys or have access to the infrastructure that holds the keys,' said Alexander Urbelis, chief information security officer at ENS Labs.

Russia and Iran, by contrast, view crypto as incidental to their broader geopolitical goals. 'Russia targets elections, energy infrastructure, and government systems, while Iran goes after dissidents and regional adversaries,' Urbelis said. 'When either of them touches crypto, it's to move money, not to steal it from the ecosystem.' North Korea's singular focus has led its operatives to adopt tactics more commonly associated with intelligence agencies, including months-long relationship building, fabricated identities, and supply chain infiltration.

The Drift campaign is just the latest example. 'You're not defending against a random phishing email, but against someone who has spent six months building a relationship to compromise one person with the necessary access,' Urbelis said.

Crypto's architecture makes it an attractive hunting ground, with no safeguards like compliance checks or settlement delays to slow down hacks. 'Once a transaction is signed and confirmed, it's final,' Urbelis said. The speed and scale of crypto hacks, such as the $1.5 billion Bybit exploit, would be impossible in traditional banking.

This finality changes the security calculus, making prevention the only viable option. While banks operate under decades of regulatory guidance, many crypto projects prioritize speed and innovation over governance and controls, creating an environment where even sophisticated teams can be vulnerable to long-term infiltration tactics.