A recent six-month infiltration campaign by North Korean hackers at Drift has highlighted the crypto industry's vulnerability to state-sponsored attacks. Unlike other countries, North Korea relies heavily on crypto to fund its economy and nuclear program due to comprehensive international sanctions.

According to experts, this urgency drives North Korean hackers to carry out large-scale, traceable heists on public blockchains. The regime's approach is distinct from other state-backed hackers, such as Russia and Iran, which use crypto as a means to work around sanctions or fund proxy networks.

North Korea's focus on crypto as a target, rather than a means to an end, has led to the adoption of tactics more commonly associated with intelligence agencies. The crypto industry's lack of traditional financial safeguards, such as compliance checks and settlement delays, makes it an attractive hunting ground for North Korean hackers. The finality of crypto transactions means that stopping an attack before it happens is essential, and the industry's improvisational approach to governance and controls creates an environment where even sophisticated teams can be vulnerable to long-term infiltration tactics.