A recent six-month infiltration campaign by North Korean hackers at Drift has sent shockwaves through the crypto industry, which is still reeling from billion-dollar exploits. The question on everyone's mind is: why does North Korea keep targeting crypto, and what sets its approach apart from other state-backed hacking operations? According to security experts, the answer lies in the regime's desperate need for revenue to fund its nuclear and ballistic missile programs.

North Korea is under strict international sanctions, and crypto provides a vital revenue stream. The regime's hackers carry out large-scale, traceable heists on public blockchains, rather than quietly using crypto to evade sanctions like other state actors.

This is because North Korea lacks a functioning economy and needs direct revenue, which crypto theft provides. The regime's targets include exchanges, wallet providers, DeFi protocols, and individual engineers and founders with signing authority or infrastructure access. Russia and Iran, on the other hand, use crypto as a means to broader geopolitical ends, such as routing money around sanctions or funding proxy networks. North Korea's singular focus on crypto has led to the adoption of tactics more commonly associated with intelligence agencies, including months-long relationship building, fabricated identities, and supply chain infiltration.

The Drift campaign is just the latest example. Crypto's architecture makes it a uniquely attractive target, with a lack of safeguards such as compliance checks and settlement delays. Once a transaction is signed and confirmed, it's final, making it essential to stop attacks before they happen. The crypto industry's emphasis on speed and innovation over governance and controls creates a vulnerability to sophisticated infiltration tactics.

This is the hardest operational security problem in crypto right now, and one that the industry has yet to solve.