A recent six-month infiltration campaign by North Korean hackers at Drift has sent shockwaves through the crypto industry, prompting questions about the regime's motivations and tactics. According to security experts, North Korea's reliance on crypto is driven by its need for a revenue stream to stay afloat, given the comprehensive international sanctions imposed on the country. Unlike other state-backed hacking operations, North Korea's approach is distinct in that it carries out large-scale, traceable heists on public blockchains, rather than using crypto to quietly evade sanctions. This is due to the country's lack of a functioning economy, which makes it reliant on direct revenue from crypto theft.
Security experts, including Dave Schwed and Alexander Urbelis, note that North Korea's targets are primarily exchanges, wallet providers, DeFi protocols, and individual engineers and founders with access to infrastructure. This focus on crypto as a target, rather than a means to broader geopolitical ends, sets North Korea apart from other state-backed hackers.
The crypto industry's unique architecture, which lacks the safeguards and friction present in traditional finance, makes it an attractive hunting ground for North Korean operatives. The finality of crypto transactions means that stopping an attack before it happens is essentially the only option, making it a challenging operational security problem for the industry to solve.