A recent six-month infiltration campaign by North Korean hackers at Drift has sent shockwaves through the crypto industry, which is still reeling from massive exploits. The incident has raised questions about why North Korea continues to target crypto and what sets its approach apart from other state-backed hacking operations. According to security experts, crypto provides the regime with a vital revenue stream, enabling it to stay afloat. "North Korea lacks the luxury of patience," said Dave Schwed, Chief Operating Officer at SVRN.
"Under comprehensive international sanctions, they require hard currency to fund their weapons programs. Crypto theft is a primary funding mechanism for their nuclear and ballistic missile development." This urgency explains why North Korean hackers carry out large-scale, traceable heists on public blockchains instead of using crypto to quietly evade sanctions. The answer lies in the structural differences between North Korea and other state actors.
Unlike Russia and Iran, which have functioning economies and use crypto as a payment rail, North Korea has almost nothing to sell and relies on crypto theft for direct revenue. This distinction is what separates North Korea from other state-backed hackers. While Russia and Iran use crypto to route money and fund proxy networks, North Korea is running a state-sponsored heist operation, targeting exchanges, wallet providers, DeFi protocols, and individual engineers with signing authority or infrastructure access.
The victim is whoever holds the keys or access to the infrastructure that holds the keys. Russia and Iran, by comparison, treat crypto as incidental, targeting elections, energy infrastructure, and government systems. North Korean operatives have adopted tactics more commonly associated with intelligence agencies, including months-long relationship building, fabricated identities, and supply chain infiltration. The Drift campaign is just one example.
"You're not defending against a random scammer, but someone who spent six months building a relationship to compromise one person with access," said Alexander Urbelis, Chief Information Security Officer at ENS Labs. Crypto's architecture makes it a uniquely attractive target, with no safeguards like compliance checks, correspondent bank checks, or settlement delays. Once a transaction is signed and confirmed, it's final.
This finality changes the security calculus, making it essential to stop attacks before they happen. The gap in regulatory guidance and audit requirements between traditional banking and crypto creates an environment where even sophisticated teams can be vulnerable to long-term infiltration tactics.
"This is the hardest operational security problem in crypto right now," Urbelis said. "I don't think the industry has solved it."