The recent six-month infiltration campaign targeting Drift has raised concerns within the crypto industry, highlighting the need to understand what sets North Korea apart from other state-backed hackers and the reasons behind its focus on crypto. According to security experts, crypto provides the regime with a vital revenue stream, enabling it to stay afloat amidst comprehensive international sanctions. North Korea's chief operating officer at SVRN, Dave Schwed, notes that the regime lacks the luxury of patience, requiring hard currency to fund its weapons programs.
The UN and multiple intelligence agencies have confirmed that crypto theft is a primary funding mechanism for North Korea's nuclear and ballistic missile development. This urgency explains why North Korean hackers carry out large-scale, traceable heists on public blockchains, rather than using crypto to quietly evade sanctions. Unlike Russia and Iran, which have functioning economies and use crypto as a payment rail, North Korea relies on crypto theft to access liquid value globally without needing a counterparty willing to do business with them.
This distinction separates North Korea from other state-backed hackers, with its targets including exchanges, wallet providers, DeFi protocols, and individual engineers and founders with signing authority or infrastructure access. The crypto industry's unique architecture, lacking traditional finance's safeguards such as compliance checks and settlement delays, makes it an attractive hunting ground for North Korean operatives. The finality of crypto transactions, once signed and confirmed, fundamentally changes the security calculus, requiring a proactive defense against attacks. The challenge of vetting against sophisticated fake identities and third-party intermediaries remains a significant operational security problem in crypto, with many projects still improvising and prioritizing speed and innovation over governance and controls.