A recent six-month infiltration campaign by North Korean hackers at Drift has raised concerns about the crypto industry's vulnerability to state-sponsored attacks. The campaign has prompted questions about why North Korea is so focused on crypto and why its approach differs from that of other state-backed hacking operations. According to security experts, the answer lies in North Korea's urgent need for revenue to fund its nuclear and ballistic missile programs. The country is under comprehensive international sanctions and lacks a functioning economy, making crypto a vital source of hard currency.
Unlike Russia and Iran, which use crypto to evade sanctions or fund proxy networks, North Korea relies on large-scale, traceable heists on public blockchains to generate direct revenue. This approach has led North Korean hackers to adopt sophisticated tactics, including months-long relationship building, fabricated identities, and supply chain infiltration. The Drift campaign is just one example of this approach, which has pushed the crypto industry to rethink its security measures. The lack of safeguards in crypto, combined with the finality of transactions, makes it an attractive target for North Korean hackers.
The industry's emphasis on speed and innovation over governance and controls has created an environment where even sophisticated teams can be vulnerable to long-term infiltration tactics. As a result, security experts warn that the crypto industry must prioritize security and develop effective measures to counter North Korea's state-sponsored hacking operations.