A recent six-month infiltration campaign by North Korean hackers at Drift has sent shockwaves through the crypto industry, already reeling from massive exploits. But a more pressing question has emerged: why does North Korea continue to target crypto, and what sets its approach apart from other state-backed hacking operations? According to security experts, crypto provides the regime with a vital revenue stream, enabling it to stay afloat despite comprehensive international sanctions.
'North Korea lacks the luxury of patience,' said Dave Schwed, chief operating officer at SVRN. 'They require hard currency to fund their weapons programs, and crypto theft is a primary mechanism for their nuclear and ballistic missile development.' This urgency explains why North Korean hackers carry out large-scale, traceable heists on public blockchains, rather than using crypto to quietly evade sanctions like other state actors. The answer lies in the structural differences between North Korea and other sanctioned nations. While Russia and Iran have functioning economies and use crypto as a payment rail, North Korea has almost nothing to sell, with its exports largely sanctioned.
'Their economy needs direct revenue, and crypto theft provides immediate access to liquid value globally, without requiring a counterparty willing to do business with them,' Schwed explained. This distinction – crypto as a target rather than infrastructure – sets North Korea apart from Russia and Iran.
North Korean hackers target exchanges, wallet providers, DeFi protocols, and individual engineers and founders with signing authority or infrastructure access. In contrast, Russia and Iran use crypto to further broader geopolitical goals, such as targeting elections, energy infrastructure, and government systems.
The unique focus of North Korean operatives has led them to adopt tactics more commonly associated with intelligence agencies, including months-long relationship building, fabricated identities, and supply chain infiltration. The Drift campaign is a recent example of this approach. 'You're not defending against a random scammer, but someone who spent six months building a relationship to compromise one person with the necessary access,' said Alexander Urbelis, chief information security officer at ENS Labs. The architecture of crypto itself makes it an attractive hunting ground for North Korean hackers.
In traditional finance, successful hacks are often slowed by compliance checks, correspondent bank checks, and settlement delays, allowing for the possibility of reversing fraudulent transfers. In crypto, these safeguards do not exist at the protocol level, making it a high-risk environment.
'Once a transaction is signed and confirmed, it's final,' Urbelis said. The speed and scale of crypto transactions, such as the $1.5 billion Bybit exploit, would be nearly impossible in the traditional banking system. This finality fundamentally changes the security calculus, making it essential to stop attacks before they happen.
While banks operate under decades of regulatory guidance and audit requirements, many crypto projects are still improvising, often prioritizing speed and innovation over governance and controls. This gap creates an environment where even sophisticated teams can be vulnerable to long-term infiltration tactics. 'This is the hardest operational security problem in crypto right now,' Urbelis said.
'I don't think the industry has solved it.'