A recent six-month infiltration campaign by North Korean hackers at Drift has highlighted the growing threat to the crypto industry, with security experts warning that the regime's tactics are unique and more dangerous than those of other state-backed hackers. The reason for this, according to experts, is that North Korea relies heavily on crypto to generate revenue and keep its economy afloat, due to the country's limited exports and comprehensive international sanctions. Unlike other state actors, such as Russia and Iran, which use crypto as a means to evade sanctions or fund proxy networks, North Korea is running a state-sponsored heist operation, targeting exchanges, wallet providers, DeFi protocols, and individual engineers and founders.

The regime's operatives have adopted tactics more commonly associated with intelligence agencies, including months-long relationship building, fabricated identities, and supply chain infiltration. The crypto industry's own architecture makes it a uniquely attractive target, with a lack of safeguards at the protocol level and a focus on speed and innovation over governance and controls. This creates an environment where even sophisticated teams can be vulnerable to long-term infiltration tactics, and security experts warn that the industry has not yet solved the operational security problem of vetting against sophisticated fake identities and third-party intermediaries.