A six-month infiltration campaign by North Korean hackers at Drift has sent shockwaves through the crypto industry, which is still reeling from massive exploits. However, a more pressing question has emerged: why does North Korea persist in targeting crypto, and what makes its approach distinct from other state-sponsored hacking operations? According to security experts, the answer lies in the fact that crypto provides the regime with a vital revenue stream.

North Korea is under severe international sanctions and requires hard currency to fund its weapons programs, including nuclear and ballistic missile development. The UN and multiple intelligence agencies have confirmed that crypto theft is a primary funding mechanism for these programs. This urgency explains why North Korean hackers carry out large-scale, traceable heists on public blockchains instead of using crypto to quietly evade sanctions like other state actors. The reason, according to Dave Schwed, is structural: Russia and Iran have functioning economies with oil, gas, and commodity exports, as well as trading partners willing to use workarounds.

In contrast, North Korea has almost nothing left to sell, with its exports largely sanctioned. As a result, North Korea needs direct revenue, and crypto theft provides immediate access to liquid value globally without requiring a counterparty willing to do business with them. This distinction - crypto as infrastructure versus crypto as a target - sets North Korea apart from Russia and Iran. While Russia and Iran use crypto to route money around sanctions and fund proxy networks, North Korea is running a state-sponsored heist operation targeting exchanges, wallet providers, DeFi protocols, and individual engineers and founders with signing authority or infrastructure access.

The targets are whoever holds the keys or access to the infrastructure that holds the keys. In contrast, Russia and Iran treat crypto as incidental, a means to broader geopolitical ends, targeting elections, energy infrastructure, and government systems, or dissidents and regional adversaries. North Korea's singular focus has led its operatives to adopt tactics more commonly associated with intelligence agencies than criminal hackers, including months-long relationship building, fabricated identities, and supply chain infiltration. The Drift campaign is just the latest example.

Crypto's architecture makes it a uniquely attractive hunting ground, with no safeguards like compliance checks, correspondent bank checks, or settlement delays. Once a transaction is signed and confirmed, it's final, making it essential to stop attacks before they happen. The industry's emphasis on speed and innovation over governance and controls creates an environment where even sophisticated teams can be vulnerable to long-term infiltration tactics. This is the hardest operational security problem in crypto right now, and the industry has yet to find a solution.