A recent six-month infiltration campaign by North Korean hackers at Drift has raised concerns about the crypto industry's vulnerability to state-sponsored attacks. According to security experts, North Korea's approach to hacking is distinct from other state-backed operations, driven by its need for hard currency to fund its weapons programs.
The regime's hackers carry out large-scale, traceable heists on public blockchains, rather than using crypto to evade sanctions. This is because North Korea lacks a functioning economy and needs direct revenue, which crypto theft provides. In contrast to Russia and Iran, which use crypto as a payment rail to work around sanctions, North Korea is running a state-sponsored heist operation, targeting exchanges, wallet providers, and individual engineers and founders.
The crypto industry's lack of regulatory guidance and audit requirements creates an environment where even sophisticated teams can be vulnerable to long-term infiltration tactics. Experts warn that the industry has not yet solved the operational security problem of vetting against sophisticated fake identities and third-party intermediaries.