A six-month infiltration campaign by North Korean hackers at Drift has sent shockwaves through the crypto industry, still reeling from billion-dollar exploits. The question on everyone's mind is: why does North Korea keep targeting crypto, and what makes its approach so different from other state-backed hacking operations? According to security experts, the answer lies in the fact that crypto provides the regime with a vital revenue stream. 'North Korea is under comprehensive international sanctions and needs hard currency to fund its weapons programs,' said Dave Schwed, chief operating officer at SVRN.
'The UN and multiple intelligence agencies have confirmed that crypto theft is a primary funding mechanism for their nuclear and ballistic missile development.' This sense of urgency explains why North Korean hackers carry out large-scale, traceable heists on public blockchains, rather than quietly using crypto to evade sanctions like other state actors. The reason, Schwed argues, is structural: Russia and Iran have functioning economies and use crypto as a payment rail, whereas North Korea has almost nothing to sell and needs direct revenue.
'Crypto theft gives them immediate access to liquid value, globally, without needing a counterparty willing to do business with them,' Schwed said. This distinction - crypto as infrastructure versus crypto as a target - is what separates North Korea from Russia and Iran. While Russia and Iran use crypto to work around sanctions and fund proxy networks, North Korea is running a state-sponsored heist operation, targeting exchanges, wallet providers, DeFi protocols, and individual engineers and founders.
'The victim is whoever holds the keys or access to the infrastructure that holds the keys,' said Alexander Urbelis, chief information security officer at ENS Labs. Russia and Iran, by comparison, treat crypto as incidental, a means to broader geopolitical ends.
North Korea's singular focus has pushed its operatives to adopt tactics more commonly associated with intelligence agencies than criminal hackers, including months-long relationship building, fabricated identities, and supply chain infiltration. The Drift campaign is just the latest example. 'You're not defending against a phishing email from a random scammer,' Urbelis said.
'You're defending against someone who spent six months building a relationship specifically to compromise one person who has the access you need to protect.' Crypto's architecture makes it a uniquely attractive hunting ground, with no safeguards like compliance checks or settlement delays to slow down hackers. 'Once a transaction is signed and confirmed, it's final,' Urbelis said. This finality fundamentally changes the security calculus, making it essential to stop attacks before they happen. The crypto industry's regulatory gap and prioritization of speed and innovation over governance and controls create an environment where even sophisticated teams can be vulnerable to North Korea's long-term infiltration tactics.
'This is the hardest operational security problem in crypto right now,' Urbelis said. 'I don't think the industry has solved it.'