A six-month infiltration campaign by North Korean hackers at Drift sent shockwaves through the crypto industry, which was already reeling from massive exploits. However, as the news unfolded, a more significant question emerged: why does North Korea persistently target crypto, and what sets its approach apart from other state-backed hacking operations? According to security experts, the answer lies in crypto's ability to provide the regime with a vital revenue stream. 'North Korea lacks the luxury of patience,' explained Dave Schwed, Chief Operating Officer at SVRN and founder of the cybersecurity masters program at Yeshiva University.
'Under comprehensive international sanctions, they require hard currency to fund their weapons programs. The UN and multiple intelligence agencies have confirmed that crypto theft is a primary funding mechanism for their nuclear and ballistic missile development.' This sense of urgency explains why North Korean hackers carry out large-scale, traceable heists on public blockchains instead of quietly using crypto to evade sanctions like other state actors. The reason, Schwed argues, is structural. Unlike Russia and Iran, which have functioning economies and use crypto as a payment rail to circumvent sanctions, North Korea has almost nothing to sell due to nearly comprehensive sanctions on its exports.
'Their exports are almost entirely sanctioned. They don't have a functioning economy that needs a payment rail.
They need direct revenue,' Schwed noted. 'Crypto theft gives them immediate access to liquid value, globally, without needing a counterparty willing to do business with them.' This distinction - crypto as infrastructure versus crypto as a target - is what separates North Korea from Russia and Iran. While Russia and Iran use crypto to route money around sanctions and fund proxy networks, North Korea operates a state-sponsored heist operation. 'Their targets are exchanges, wallet providers, DeFi protocols, and the individual engineers and founders who have signing authority or infrastructure access,' said Alexander Urbelis, Chief Information Security Officer at ENS Labs and a professor of cybersecurity at King’s College London.
'The victim is whoever holds the keys or access to the infrastructure that holds the keys.' In contrast, Russia and Iran treat crypto as incidental to their broader geopolitical objectives. 'Russia targets elections, energy infrastructure, and government systems. Iran goes after dissidents and regional adversaries,' Urbelis said.
'When either of them touches crypto, it's to move money, not to steal it from the ecosystem.' North Korea's singular focus on crypto has led its operatives to adopt tactics more commonly associated with intelligence agencies than criminal hackers, including months-long relationship building, fabricated identities, and supply chain infiltration. The Drift campaign is a recent example. 'You're not defending against a phishing email from a random scammer,' Urbelis said. 'You're defending against someone who spent six months building a relationship specifically to compromise one person who has the access you need to protect.' The architecture of crypto itself makes it an attractive hunting ground.
Unlike traditional finance, where successful hacks encounter friction in the form of compliance checks and settlement delays, crypto lacks these safeguards at the protocol level. 'Once a transaction is signed and confirmed, it's final,' Urbelis said. The speed and finality of crypto transactions fundamentally change the security calculus, making it essential to stop attacks before they happen. While banks operate under decades of regulatory guidance and audit requirements, many crypto projects prioritize speed and innovation over governance and controls, creating an environment where even sophisticated teams can be vulnerable to long-term infiltration tactics.
'This is the hardest operational security problem in crypto right now,' Urbelis said. 'I don't think the industry has solved it.'