A recent six-month infiltration campaign by North Korean hackers at Drift has raised concerns in the crypto industry, already reeling from massive exploits. But a more pressing question has emerged: why does North Korea continue to target crypto, and what makes its approach different from other state-backed hacking operations? According to security experts, crypto provides the regime with a vital revenue stream. 'North Korea lacks the luxury of patience due to comprehensive international sanctions and requires hard currency to fund its weapons programs,' said Dave Schwed, chief operating officer at SVRN.

The UN and multiple intelligence agencies have confirmed that crypto theft is a primary funding mechanism for North Korea's nuclear and ballistic missile development. This urgency explains why North Korean hackers carry out large-scale, traceable heists on public blockchains instead of quietly using crypto to evade sanctions.

The answer, Schwed argues, lies in the structural differences between North Korea and other state actors. Unlike Russia and Iran, which have functioning economies and use crypto as a payment rail, North Korea has almost nothing to sell due to sanctions.

'Their exports are almost entirely sanctioned, and they don't have a functioning economy that needs a payment rail. They need direct revenue,' Schwed said. Crypto theft gives North Korea immediate access to liquid value globally without needing a willing counterparty. This distinction - crypto as infrastructure versus crypto as a target - separates North Korea from Russia and Iran.

While Russia and Iran use crypto to route money around sanctions and fund proxy networks, North Korea is running a state-sponsored heist operation. 'Their targets are exchanges, wallet providers, DeFi protocols, and individual engineers and founders who have signing authority or infrastructure access,' said Alexander Urbelis, chief information security officer at ENS Labs. Russia and Iran, by comparison, treat crypto as incidental to broader geopolitical ends.

North Korean operatives have adopted tactics more commonly associated with intelligence agencies, including months-long relationship building, fabricated identities, and supply chain infiltration. The Drift campaign is a recent example. Crypto's architecture makes it a uniquely attractive hunting ground, with no safeguards like compliance checks or settlement delays. 'Once a transaction is signed and confirmed, it's final,' Urbelis said.

This finality changes the security calculus, making it essential to stop attacks before they happen. The crypto industry's regulatory gap and prioritization of speed over governance create an environment where even sophisticated teams can be vulnerable to long-term infiltration tactics. 'This is the hardest operational security problem in crypto right now,' Urbelis said. 'I don't think the industry has solved it.'