A recent six-month infiltration campaign by North Korean hackers at Drift has sent shockwaves through the crypto industry, already reeling from massive exploits. But a bigger question remains: why does North Korea continue to target crypto, and what makes its approach different from other state-backed hacking operations? According to security experts, crypto provides the regime with a vital revenue stream, enabling it to stay afloat.
North Korea's economy is severely limited by international sanctions, and it desperately needs hard currency to fund its weapons programs. The UN and multiple intelligence agencies have confirmed that crypto theft is a primary funding mechanism for the regime's nuclear and ballistic missile development. This sense of urgency explains why North Korean hackers carry out large-scale, traceable heists on public blockchains, rather than using crypto to quietly evade sanctions like other state actors.
The answer lies in the structural differences between North Korea and other sanctioned nations. Russia and Iran, for example, have functioning economies and can use crypto as a payment rail to work around sanctions.
In contrast, North Korea has almost nothing to sell, and its exports are heavily sanctioned. As a result, the regime needs direct revenue, which crypto theft provides. This distinction - crypto as a target rather than infrastructure - sets North Korea apart from other state-backed hackers. While Russia and Iran use crypto to fund broader geopolitical goals, North Korea is running a state-sponsored heist operation, targeting exchanges, wallet providers, DeFi protocols, and individual engineers and founders with signing authority or infrastructure access.
The regime's operatives have adopted tactics more commonly associated with intelligence agencies, including months-long relationship building, fabricated identities, and supply chain infiltration. The Drift campaign is just the latest example. The crypto industry's own architecture makes it a uniquely attractive hunting ground for North Korean hackers.
In traditional finance, even successful hacks encounter friction in the form of compliance checks and settlement delays. In crypto, however, transactions are final and irreversible once confirmed. This lack of safeguards creates a challenging security environment, where stopping an attack before it happens is essentially the only option.
Many crypto projects are still improvising, prioritizing speed and innovation over governance and controls, which creates an environment where even sophisticated teams can be vulnerable to long-term infiltration tactics. The challenge of vetting against sophisticated fake identities and third-party intermediaries is the hardest operational security problem in crypto right now, and the industry has yet to find a solution.