A recent six-month infiltration campaign by North Korean hackers at Drift has left the crypto industry reeling, but a more pressing question has emerged: what drives North Korea's relentless pursuit of crypto, and how does its approach differ from other state-backed hacking operations? Security experts argue that crypto provides the regime with a vital revenue stream, enabling it to stay afloat amidst comprehensive international sanctions. 'North Korea lacks the luxury of patience,' explained Dave Schwed, chief operating officer at SVRN.

'It requires hard currency to fund its weapons programs, and crypto theft has been confirmed by the UN and multiple intelligence agencies as a primary funding mechanism for its nuclear and ballistic missile development.' This urgency explains why North Korean hackers opt for large-scale, traceable heists on public blockchains instead of using crypto to evade sanctions quietly. According to Schwed, the reason lies in the structural differences between North Korea and other state actors. Unlike Russia and Iran, which have functioning economies and use crypto as a payment rail, North Korea has almost nothing to sell, with its exports largely sanctioned. As a result, it relies on crypto theft to access liquid value globally without needing a willing counterparty.

This distinction – crypto as a target rather than infrastructure – sets North Korea apart from other state-backed hackers. While Russia and Iran use crypto to route money and fund proxy networks, North Korea is running a state-sponsored heist operation, targeting exchanges, wallet providers, DeFi protocols, and individual engineers with signing authority or infrastructure access. The regime's singular focus on crypto has led to the adoption of tactics typically associated with intelligence agencies, including months-long relationship building, fabricated identities, and supply chain infiltration. The Drift campaign is just the latest example.

'You're not defending against a random scammer,' said Alexander Urbelis, chief information security officer at ENS Labs. 'You're defending against someone who spent six months building a relationship to compromise one person with the necessary access.' Crypto's architecture makes it an attractive hunting ground, with none of the safeguards present in traditional finance, such as compliance checks and settlement delays.

Once a transaction is signed and confirmed, it's final, which fundamentally changes the security calculus. In crypto, stopping an attack before it happens is the only viable option, as the window to freeze funds or reverse a transaction is virtually non-existent.

The gap in regulatory guidance and audit requirements between traditional banking and crypto creates an environment where even sophisticated teams can be vulnerable to long-term infiltration tactics. 'This is the hardest operational security problem in crypto right now,' Urbelis said. 'I don't think the industry has solved it.'