The recent six-month infiltration campaign at Drift sent shockwaves through the crypto industry, which was already reeling from billion-dollar exploits. However, a more pressing question has emerged: why does North Korea persist in targeting the crypto space, and what makes its approach distinct from other state-sponsored hacking operations?
According to security experts, the answer lies in the fact that crypto provides the regime with a vital revenue stream. North Korea is under comprehensive international sanctions and requires hard currency to fund its weapons programs. The UN and multiple intelligence agencies have confirmed that crypto theft is a primary funding mechanism for the regime's nuclear and ballistic missile development.
This urgency explains why North Korean hackers carry out large-scale, traceable heists on public blockchains instead of quietly using crypto to evade sanctions like other state actors. The reason, according to Dave Schwed, chief operating officer at SVRN, is structural. Unlike Russia and Iran, which have functioning economies and use crypto as a payment rail, North Korea has almost nothing left to sell due to sanctions. As a result, the regime relies on crypto theft to gain immediate access to liquid value globally without needing a willing counterparty.
This distinction - crypto as infrastructure versus crypto as a target - is what separates North Korea from other state-backed hackers. While Russia and Iran use crypto to work around sanctions and fund proxy networks, North Korea is running a state-sponsored heist operation, targeting exchanges, wallet providers, DeFi protocols, and individual engineers and founders with signing authority or infrastructure access. The regime's singular focus has led to the adoption of tactics more commonly associated with intelligence agencies, including months-long relationship building, fabricated identities, and supply chain infiltration. The Drift campaign is a recent example of this approach.
The crypto industry's own architecture makes it a uniquely attractive target, with a lack of safeguards such as compliance checks, correspondent bank checks, and settlement delays. Once a transaction is signed and confirmed, it's final, making it essential to stop attacks before they happen. The industry's emphasis on speed and innovation over governance and controls creates an environment where even sophisticated teams can be vulnerable to long-term infiltration tactics.