A six-month infiltration campaign by North Korean hackers at Drift sent shockwaves through the crypto industry, which was already reeling from billion-dollar exploits. However, as the dust settled, a more pressing question emerged: why does North Korea persist in targeting crypto, and what makes its approach distinct from other state-backed hacking operations? According to security experts, the answer lies in the fact that crypto provides the regime with a vital revenue stream. 'North Korea lacks the luxury of patience,' explained Dave Schwed, Chief Operating Officer at SVRN and founder of the cybersecurity masters program at Yeshiva University.

'Under comprehensive international sanctions, they require hard currency to fund their weapons programs, and the UN and multiple intelligence agencies have confirmed that crypto theft is a primary funding mechanism for their nuclear and ballistic missile development.' This sense of urgency explains why North Korean hackers opt for large-scale, traceable heists on public blockchains rather than quietly using crypto to evade sanctions like other state actors. The reason, Schwed argues, is structural: countries like Russia and Iran have functioning economies and can utilize crypto as a payment rail, whereas North Korea has almost nothing to sell due to sanctions.

'Their exports are almost entirely sanctioned, and they don't have a functioning economy that needs a payment rail. They need direct revenue,' Schwed stated.

'Crypto theft gives them immediate access to liquid value globally, without requiring a counterparty willing to do business with them.' This distinction - crypto as infrastructure versus crypto as a target - is what separates North Korea from other nations. While Russia and Iran use crypto to work around sanctions and fund proxy networks, North Korea operates a state-sponsored heist operation, targeting exchanges, wallet providers, DeFi protocols, and individual engineers with signing authority or infrastructure access. 'The victim is whoever holds the keys or access to the infrastructure that holds the keys,' said Alexander Urbelis, Chief Information Security Officer at ENS Labs and a professor of cybersecurity at King's College London.

In contrast, Russia and Iran view crypto as a means to broader geopolitical ends, targeting elections, energy infrastructure, and government systems, or going after dissidents and regional adversaries. North Korea's singular focus on crypto has driven its operatives to adopt tactics more commonly associated with intelligence agencies, including months-long relationship building, fabricated identities, and supply chain infiltration.

The Drift campaign is a recent example of this approach. 'You're not defending against a phishing email from a random scammer,' Urbelis said. 'You're defending against someone who spent six months building a relationship specifically to compromise one person who has the access you need to protect.' The architecture of crypto itself makes it an attractive hunting ground, as it lacks the safeguards present in traditional finance, such as compliance checks and settlement delays.

'Once a transaction is signed and confirmed, it's final,' Urbelis said. The Bybit exploit, which moved $1.5 billion in roughly 30 minutes, demonstrates the pace and scale that would be nearly impossible in the traditional banking system. This finality fundamentally changes the security calculus, making it essential to stop attacks before they happen. While banks operate under decades of regulatory guidance and audit requirements, many crypto projects are still improvising, often prioritizing speed and innovation over governance and controls.

This gap creates an environment where even sophisticated teams can be vulnerable to long-term infiltration tactics. 'This is the hardest operational security problem in crypto right now,' Urbelis said.

'I don't think the industry has solved it.'