A recent six-month infiltration campaign by North Korean hackers at Drift has raised concerns about the crypto industry's vulnerability to state-sponsored attacks. According to security experts, North Korea's approach differs from other state-backed hacking operations due to its desperate need for revenue.

The regime relies heavily on crypto theft to generate hard currency, which is used to fund its nuclear and ballistic missile development programs. This is in contrast to other countries like Russia and Iran, which use crypto as a means to circumvent sanctions, but do not rely on it as a primary source of revenue.

North Korea's hackers have adopted tactics commonly associated with intelligence agencies, including months-long relationship building and supply chain infiltration. The crypto industry's lack of traditional safeguards, such as compliance checks and settlement delays, makes it an attractive target for these hackers. The finality of crypto transactions also changes the security calculus, making it essential to prevent attacks before they happen. The industry's improvisational approach to governance and controls creates an environment where even sophisticated teams can be vulnerable to long-term infiltration tactics.