A recent six-month infiltration campaign by North Korean hackers at Drift has sent shockwaves through the crypto industry, still reeling from billion-dollar exploits. However, a more pressing question has emerged: why does North Korea consistently target crypto, and what makes its approach distinct from other state-backed hacking operations? According to security experts, crypto provides the regime with a vital revenue stream.

'North Korea lacks the luxury of patience due to comprehensive international sanctions and requires hard currency to fund its weapons programs,' explained Dave Schwed, Chief Operating Officer at SVRN and founder of the cybersecurity masters program at Yeshiva University. The UN and multiple intelligence agencies have confirmed that crypto theft is a primary funding mechanism for North Korea's nuclear and ballistic missile development. This urgency explains why North Korean hackers carry out large-scale, traceable heists on public blockchains instead of quietly using crypto to evade sanctions like other state actors. The answer lies in the structural differences between North Korea and other sanctioned nations like Russia and Iran.

While Russia and Iran have economies that can utilize crypto as a payment rail, North Korea's exports are almost entirely sanctioned, and it lacks a functioning economy. As a result, North Korea needs direct revenue, which crypto theft provides in the form of immediate access to liquid value globally without requiring a counterparty willing to do business with them.

This distinction is what separates North Korea from Russia and Iran, which use crypto to route money around sanctions or fund proxy networks. In contrast, North Korea operates a state-sponsored heist operation, targeting exchanges, wallet providers, DeFi protocols, and individual engineers and founders with signing authority or infrastructure access. Alexander Urbelis, Chief Information Security Officer at ENS Labs and a professor of cybersecurity at King's College London, noted that 'their targets are whoever holds the keys or access to the infrastructure that holds the keys.' Russia and Iran, on the other hand, treat crypto as incidental to their broader geopolitical goals.

North Korea's singular focus on crypto has led its operatives to adopt tactics more commonly associated with intelligence agencies, including months-long relationship building, fabricated identities, and supply chain infiltration. The Drift campaign is a recent example of this approach. 'You're not defending against a phishing email from a random scammer; you're defending against someone who spent six months building a relationship specifically to compromise one person with the access you need to protect,' Urbelis said.

Crypto's architecture makes it an attractive hunting ground due to the lack of safeguards like compliance checks, correspondent bank checks, settlement delays, and the possibility of reversing fraudulent transfers. In traditional finance, even successful hacks encounter friction, but in crypto, once a transaction is signed and confirmed, it's final. This finality changes the security calculus, making it essential to stop attacks before they happen.

The gap in regulatory guidance and audit requirements between traditional banking and crypto creates an environment where sophisticated teams can be vulnerable to long-term infiltration tactics. 'This is the hardest operational security problem in crypto right now,' Urbelis said, emphasizing that the industry has yet to solve it.