A recent six-month infiltration campaign by North Korean hackers at Drift has sent shockwaves through the crypto industry, still reeling from billion-dollar exploits. This has raised questions about why North Korea consistently targets crypto and what sets its approach apart from other state-backed hacking operations. According to security experts, crypto provides North Korea with a vital revenue stream, enabling the regime to stay afloat.
Dave Schwed, COO at SVRN, notes that North Korea lacks patience due to comprehensive international sanctions and requires hard currency to fund its weapons programs. The UN and multiple intelligence agencies have confirmed that crypto theft is a primary funding mechanism for North Korea's nuclear and ballistic missile development.
This urgency explains why North Korean hackers carry out large-scale, traceable heists on public blockchains instead of quietly using crypto to evade sanctions. Unlike Russia and Iran, which have functioning economies and use crypto as a payment rail, North Korea has almost nothing to sell and needs direct revenue.
Crypto theft gives North Korea immediate access to liquid value globally without needing a counterparty willing to do business with them. This distinction separates North Korea from other state-backed hackers, with its targets being exchanges, wallet providers, DeFi protocols, and individual engineers and founders with signing authority or infrastructure access. North Korean operatives have adopted tactics more commonly associated with intelligence agencies, including months-long relationship building, fabricated identities, and supply chain infiltration. The Drift campaign is a recent example, with hackers spending six months building a relationship to compromise one person with access.
Crypto's architecture makes it an attractive hunting ground, with no safeguards like compliance checks or settlement delays. Once a transaction is signed and confirmed, it's final, making it essential to stop attacks before they happen.
The crypto industry's improvisational approach to security, prioritizing speed and innovation over governance and controls, creates an environment where even sophisticated teams can be vulnerable to long-term infiltration tactics. This is the hardest operational security problem in crypto, with the industry yet to solve it.