A recent six-month infiltration campaign by North Korean hackers at Drift has raised concerns about the crypto industry's vulnerability to state-sponsored attacks. According to security experts, North Korea's reliance on crypto theft is driven by its need for hard currency to fund its nuclear and ballistic missile programs, due to comprehensive international sanctions.

Unlike other state-backed hackers, North Korea's approach is distinct in that it targets crypto directly, rather than using it as a means to evade sanctions. This is because North Korea's economy is severely limited, with almost no exports or trading partners, making crypto theft a primary source of revenue. The regime's hackers have adopted sophisticated tactics, including months-long relationship building and supply chain infiltration, to target exchanges, wallet providers, and DeFi protocols.

The crypto industry's lack of traditional financial safeguards, such as compliance checks and settlement delays, makes it an attractive target for North Korean hackers. The finality of crypto transactions means that stopping an attack before it happens is essentially the only option, and the industry's emphasis on speed and innovation over governance and controls creates an environment where even sophisticated teams can be vulnerable to long-term infiltration tactics.