A recent six-month infiltration campaign by North Korean hackers at Drift has sent shockwaves through the crypto industry, already reeling from massive exploits. But a more pressing question has emerged: why does North Korea consistently target crypto, and what makes its approach distinct from other state-sponsored hacking operations? According to experts, the answer lies in the regime's desperate need for a revenue stream to stay afloat.
North Korea is under stringent international sanctions and requires hard currency to fund its weapons programs, including nuclear and ballistic missile development. The UN and multiple intelligence agencies have confirmed that crypto theft is a primary funding mechanism for these programs. This urgency drives North Korean hackers to carry out large-scale, traceable heists on public blockchains, rather than using crypto to evade sanctions like other state actors. The reason, according to Dave Schwed, Chief Operating Officer at SVRN, is structural.
Unlike Russia and Iran, which have functioning economies and use crypto as a payment rail, North Korea has almost nothing to sell and no functioning economy. Its exports are heavily sanctioned, and it lacks a payment rail. As a result, crypto theft provides the regime with immediate access to liquid value globally, without needing a willing counterparty.
This distinction - crypto as a target rather than infrastructure - sets North Korea apart from Russia and Iran. While Russia and Iran use crypto to route money and fund proxy networks, North Korea operates a state-sponsored heist operation, targeting exchanges, wallet providers, DeFi protocols, and individual engineers and founders with signing authority or infrastructure access. The regime's singular focus has led to the adoption of tactics more commonly associated with intelligence agencies, including months-long relationship building, fabricated identities, and supply chain infiltration. The Drift campaign is just one example.
The crypto industry's architecture makes it a uniquely attractive target, with no safeguards like compliance checks or settlement delays to slow down hacks. Once a transaction is signed and confirmed, it's final, making it essential to stop attacks before they happen.
However, many crypto projects prioritize speed and innovation over governance and controls, creating an environment where even sophisticated teams can be vulnerable to long-term infiltration tactics.