A six-month infiltration campaign by North Korean hackers at Drift has left the crypto industry reeling, prompting a deeper examination of the regime's reliance on crypto to sustain its economy and nuclear program. According to security experts, North Korea's approach differs significantly from other state-backed hacking operations due to its urgent need for hard currency to fund weapons programs.
The regime's hackers carry out large-scale, traceable heists on public blockchains to gain immediate access to liquid value globally, without requiring a counterparty willing to do business with them. This distinction sets North Korea apart from Russia and Iran, which use crypto as a means to work around sanctions or fund proxy networks. North Korea's focus on crypto as a target has led to the adoption of tactics more commonly associated with intelligence agencies, including months-long relationship building, fabricated identities, and supply chain infiltration. The Drift campaign is a recent example of this approach, which has pushed the crypto industry to reevaluate its security measures.
The lack of safeguards in crypto, such as compliance checks and settlement delays, makes it an attractive target for North Korean hackers. The finality of crypto transactions also changes the security calculus, making it essential to stop attacks before they happen.
The gap in regulatory guidance and audit requirements between traditional banking and crypto creates an environment where even sophisticated teams can be vulnerable to long-term infiltration tactics.