A recent six-month infiltration campaign by North Korean hackers at Drift has raised concerns about the crypto industry's vulnerability to state-sponsored attacks. According to security experts, North Korea's desperation for hard currency to fund its nuclear and ballistic missile development programs drives its focus on crypto. Unlike other state-backed hackers, North Korea's approach is characterized by large-scale, traceable heists on public blockchains, rather than using crypto to quietly evade sanctions.

This is due to the country's severely limited economy, which lacks the luxury of patience and relies on crypto theft as a primary funding mechanism. North Korean hackers target exchanges, wallet providers, DeFi protocols, and individual engineers and founders with signing authority or infrastructure access, using tactics such as months-long relationship building, fabricated identities, and supply chain infiltration. The crypto industry's lack of traditional financial safeguards, such as compliance checks and settlement delays, makes it an attractive target for these hackers. The finality of crypto transactions means that stopping an attack before it happens is essentially the only option, and the industry's prioritization of speed and innovation over governance and controls creates an environment vulnerable to sophisticated infiltration tactics.