The recent six-month infiltration campaign at Drift has raised concerns about North Korea's intentions in the crypto industry. According to security experts, the regime's reliance on crypto is driven by its need for a revenue stream to fund its economy and nuclear program. Unlike other state-backed hackers, North Korea's approach is distinct in that it carries out large-scale, traceable heists on public blockchains.

This is due to the country's limited economic options, with almost all its exports being sanctioned. As a result, North Korea has turned to crypto theft as a means to access liquid value globally without needing a counterparty.

The country's targets include exchanges, wallet providers, DeFi protocols, and individual engineers and founders with signing authority or infrastructure access. In contrast to Russia and Iran, which use crypto as a means to work around sanctions or fund proxy networks, North Korea's focus is on stealing crypto from the ecosystem.

The crypto industry's unique architecture, lack of safeguards, and emphasis on speed and innovation over governance and controls create an environment where even sophisticated teams can be vulnerable to North Korea's long-term infiltration tactics.