A recent six-month infiltration campaign by North Korean hackers at Drift has raised concerns about the crypto industry's vulnerability to state-sponsored attacks. Unlike other nations, North Korea relies heavily on crypto to generate revenue due to its isolated economy and stringent international sanctions.
According to Dave Schwed, chief operating officer at SVRN, North Korea's hackers are forced to carry out large-scale, traceable heists on public blockchains to access liquid value quickly. This approach differs from that of Russia and Iran, which use crypto to evade sanctions and fund proxy networks.
North Korea's targets include exchanges, wallet providers, DeFi protocols, and individual engineers with access to infrastructure. The nation's operatives have adopted tactics commonly associated with intelligence agencies, such as months-long relationship building and supply chain infiltration.
The crypto industry's lack of safeguards, such as compliance checks and settlement delays, makes it an attractive target for North Korean hackers. The finality of crypto transactions means that stopping an attack before it happens is essential, and the industry's emphasis on speed and innovation over governance and controls creates an environment where even sophisticated teams can be vulnerable to long-term infiltration tactics.