A recent six-month infiltration campaign by North Korean hackers has raised concerns about the crypto industry's vulnerability to state-sponsored attacks. According to security experts, North Korea's approach to hacking is distinct from other state-backed operations, as it relies heavily on crypto to generate revenue. The regime's economic isolation and lack of traditional exports have made crypto a crucial source of funding for its nuclear and ballistic missile development. Unlike Russia and Iran, which use crypto to evade sanctions and fund proxy networks, North Korea is focused on carrying out large-scale, traceable heists on public blockchains to gain direct access to liquid value.

This approach has led to the adoption of tactics more commonly associated with intelligence agencies, such as months-long relationship building and supply chain infiltration. The crypto industry's lack of traditional safeguards, such as compliance checks and settlement delays, makes it an attractive target for North Korean hackers.

The finality of crypto transactions means that stopping an attack before it happens is essential, and the industry's emphasis on speed and innovation over governance and controls creates an environment where even sophisticated teams can be vulnerable to infiltration tactics.