A recent six-month infiltration campaign by North Korean hackers at Drift has sent shockwaves through the crypto industry, prompting questions about the regime's motivations and tactics. According to experts, North Korea's reliance on crypto is driven by its isolated economy and need for immediate access to liquid value. Unlike other state-backed hackers, North Korea's operatives carry out large-scale, traceable heists on public blockchains, seeking direct revenue rather than using crypto as a payment rail. This approach sets them apart from other state actors, such as Russia and Iran, which use crypto to work around sanctions or fund proxy networks.
North Korea's hackers have adopted tactics more commonly associated with intelligence agencies, including months-long relationship building, fabricated identities, and supply chain infiltration. The crypto industry's lack of traditional safeguards, such as compliance checks and settlement delays, makes it a uniquely attractive target. The finality of crypto transactions means that stopping an attack before it happens is the only viable option, and the industry's emphasis on speed and innovation over governance and controls creates an environment where even sophisticated teams can be vulnerable to infiltration.
Experts warn that the industry has yet to solve the operational security problem of vetting against sophisticated fake identities and third-party intermediaries.