A recent six-month infiltration campaign by North Korean hackers at Drift has sent shockwaves through the crypto industry, which is still reeling from billion-dollar exploits. However, a more pressing question has emerged: why does North Korea continue to target crypto, and what makes its approach distinct from other state-backed hacking operations?

According to security experts, the answer lies in crypto's ability to provide the regime with a vital revenue stream. North Korea is under stringent international sanctions and requires hard currency to fund its weapons programs, including nuclear and ballistic missile development. The UN and multiple intelligence agencies have confirmed that crypto theft is a primary funding mechanism for these initiatives. This urgency explains why North Korean hackers carry out large-scale, traceable heists on public blockchains instead of using crypto to quietly evade sanctions like other state actors.

The reason, according to Dave Schwed, Chief Operating Officer at SVRN, is structural. Unlike Russia and Iran, which have functioning economies and use crypto as a payment rail to work around sanctions, North Korea has almost nothing left to sell due to comprehensive sanctions on its exports. As a result, North Korea needs direct revenue, which crypto theft provides through immediate access to liquid value globally without requiring a willing counterparty.

This distinction - crypto as infrastructure versus crypto as a target - sets North Korea apart from Russia and Iran. While Russia and Iran use crypto to fund broader geopolitical goals, North Korea operates a state-sponsored heist operation, targeting exchanges, wallet providers, DeFi protocols, and individual engineers and founders with signing authority or infrastructure access. The crypto industry's unique architecture makes it an attractive hunting ground, with none of the traditional financial safeguards such as compliance checks, correspondent bank checks, or settlement delays.

Once a transaction is signed and confirmed, it's final, making it essential to stop attacks before they happen. The industry's emphasis on speed and innovation over governance and controls creates an environment where even sophisticated teams can be vulnerable to long-term infiltration tactics like those employed by North Korea.