A recent six-month infiltration campaign by North Korean hackers at Drift has raised questions about the regime's motivations for targeting the crypto industry. According to security experts, the answer lies in the fact that crypto provides a vital revenue stream for the regime, which is under comprehensive international sanctions and needs hard currency to fund its nuclear and ballistic missile programs.
Unlike other state-backed hackers, North Korea's approach is distinct in that it carries out large-scale, traceable heists on public blockchains, rather than using crypto to evade sanctions. This is due to the regime's dire economic situation, with almost no exports left to sell, and a need for direct revenue. Crypto theft gives North Korea immediate access to liquid value globally, without requiring a counterparty willing to do business with them.
The regime's targets include exchanges, wallet providers, DeFi protocols, and individual engineers and founders with signing authority or infrastructure access. In contrast to Russia and Iran, which use crypto as a means to broader geopolitical ends, North Korea's focus is singularly on stealing crypto assets.
This has led to the adoption of tactics more commonly associated with intelligence agencies, such as months-long relationship building, fabricated identities, and supply chain infiltration. The Drift campaign is just one example of this approach. The unique architecture of crypto makes it an attractive hunting ground for North Korean hackers, with no safeguards like compliance checks or settlement delays to slow down transactions.
Once a transaction is signed and confirmed, it's final, making it essential to stop attacks before they happen. The crypto industry's improvisational approach to security, prioritizing speed and innovation over governance and controls, creates an environment where even sophisticated teams can be vulnerable to long-term infiltration tactics. This poses a significant challenge, with the industry yet to solve the problem of vetting against sophisticated fake identities and third-party intermediaries.