A six-month infiltration campaign by North Korean hackers at Drift has sent shockwaves through the crypto industry, which is still reeling from billion-dollar exploits. However, a more pressing question has emerged: why does North Korea consistently target crypto, and what sets its approach apart from other state-backed hacking operations?

According to security experts, the answer lies in the fact that crypto provides the regime with a vital revenue stream, enabling it to stay afloat. North Korea is under comprehensive international sanctions and requires hard currency to fund its weapons programs, with the UN and multiple intelligence agencies confirming that crypto theft is a primary funding mechanism for its nuclear and ballistic missile development.

The urgency of North Korea's situation explains why its hackers carry out large-scale, traceable heists on public blockchains instead of using crypto to quietly evade sanctions like other state actors. The reason, according to Dave Schwed, chief operating officer at SVRN, is structural: unlike Russia and Iran, which have functioning economies and use crypto as a payment rail, North Korea has almost nothing left to sell and relies on direct revenue from crypto theft. This distinction is what separates North Korea from other state-backed hackers, with its targets including exchanges, wallet providers, DeFi protocols, and individual engineers and founders with signing authority or infrastructure access.

In contrast, Russia and Iran use crypto incidentally, as a means to broader geopolitical ends, targeting elections, energy infrastructure, government systems, dissidents, and regional adversaries. North Korea's singular focus on crypto has led its operatives to adopt tactics more commonly associated with intelligence agencies, including months-long relationship building, fabricated identities, and supply chain infiltration. The Drift campaign is just the latest example. The crypto industry's own architecture makes it a uniquely attractive target, with its lack of friction in the form of compliance checks, correspondent bank checks, settlement delays, and the possibility of reversing fraudulent transfers.

Once a transaction is signed and confirmed, it's final, making it essential to stop attacks before they happen. The industry's emphasis on speed and innovation over governance and controls creates an environment where even sophisticated teams can be vulnerable to long-term infiltration tactics. According to Alexander Urbelis, chief information security officer at ENS Labs, this is the hardest operational security problem in crypto right now, and one that the industry has yet to solve.