A six-month infiltration campaign by North Korean hackers at Drift has left the crypto industry reeling, raising questions about the regime's motives and methods. According to security experts, North Korea relies on crypto to generate revenue and stay afloat due to comprehensive international sanctions.
The regime's approach differs from other state-backed hacking operations, as it carries out large-scale, traceable heists on public blockchains to obtain hard currency for its nuclear and ballistic missile development programs. This urgency drives North Korean hackers to target exchanges, wallet providers, and DeFi protocols, using tactics such as months-long relationship building, fabricated identities, and supply chain infiltration. The crypto industry's lack of safeguards and regulatory guidance creates an environment where even sophisticated teams can be vulnerable to these tactics, making it essential to prioritize security and vetting against sophisticated fake identities and third-party intermediaries.