A six-month infiltration campaign by North Korean hackers at Drift has raised concerns about the crypto industry's vulnerability to state-sponsored attacks. The campaign has prompted questions about why North Korea is targeting crypto and what sets its approach apart from other state-backed hacking operations.

According to security experts, North Korea's crypto heists are driven by the regime's need for hard currency to fund its nuclear and ballistic missile development programs, which are under comprehensive international sanctions. The experts note that North Korea's economy is severely limited, with almost no exports or trading partners, making crypto theft a primary funding mechanism. Unlike Russia and Iran, which use crypto to evade sanctions or fund proxy networks, North Korea is running a state-sponsored heist operation, targeting exchanges, wallet providers, and individual engineers with access to infrastructure.

The regime's operatives have adopted tactics commonly associated with intelligence agencies, including months-long relationship building and supply chain infiltration. The crypto industry's own architecture makes it an attractive target, with a lack of safeguards such as compliance checks and settlement delays, allowing for rapid and irreversible transactions.

This has created an environment where even sophisticated teams can be vulnerable to long-term infiltration tactics, and security experts warn that the industry has not yet solved the operational security problem of vetting against sophisticated fake identities and third-party intermediaries.