A recent six-month infiltration campaign by North Korean hackers at Drift has raised concerns in the crypto industry, which is already reeling from billion-dollar exploits. The question on everyone's mind is: why does North Korea keep targeting crypto, and what makes its approach different from other state-backed hacking operations? According to security experts, the answer lies in the fact that crypto provides the regime with a much-needed revenue stream.

North Korea is under comprehensive international sanctions, and it needs hard currency to fund its weapons programs, including its nuclear and ballistic missile development. The UN and multiple intelligence agencies have confirmed that crypto theft is a primary funding mechanism for these programs. Unlike other state actors, such as Russia and Iran, North Korea lacks a functioning economy and relies heavily on crypto to generate revenue.

While Russia and Iran use crypto to evade sanctions, North Korea uses it as a means to obtain direct revenue. This distinction is what sets North Korea apart from other state-backed hackers.

The regime's targets are primarily exchanges, wallet providers, DeFi protocols, and individual engineers and founders with signing authority or infrastructure access. North Korean operatives have adopted tactics commonly associated with intelligence agencies, including months-long relationship building, fabricated identities, and supply chain infiltration. The crypto industry's own architecture makes it an attractive target, with a lack of safeguards such as compliance checks and settlement delays.

This makes it difficult for the industry to defend against sophisticated attacks, and security experts warn that the industry has not yet solved the operational security problem of vetting against fake identities and third-party intermediaries.