A recent six-month infiltration campaign by North Korean hackers at Drift has sent shockwaves through the crypto industry, which is still reeling from billion-dollar exploits. The question on everyone's mind is: why does North Korea keep targeting crypto, and what makes its approach different from other state-backed hacking operations? According to security experts, the answer lies in the regime's desperate need for a revenue stream to stay afloat. 'North Korea is under comprehensive international sanctions and requires hard currency to fund its weapons programs,' explained Dave Schwed, Chief Operating Officer at SVRN.
'Crypto theft is a primary funding mechanism for their nuclear and ballistic missile development.' This urgency drives North Korean hackers to carry out large-scale, traceable heists on public blockchains, unlike other state actors who use crypto to quietly evade sanctions. The reason, Schwed argues, is structural: while countries like Russia and Iran have functioning economies and use crypto as a payment rail, North Korea has almost nothing to sell due to sanctions. 'Their exports are almost entirely sanctioned, and they don't have a functioning economy that needs a payment rail. They need direct revenue,' Schwed said.
'Crypto theft provides them with immediate access to liquid value, globally, without requiring a counterparty willing to do business with them.' This distinction - crypto as infrastructure versus crypto as a target - sets North Korea apart from Russia and Iran. While Russia and Iran use crypto to route money around sanctions and fund proxy networks, North Korea is running a state-sponsored heist operation. 'Their targets are exchanges, wallet providers, DeFi protocols, and individual engineers and founders with signing authority or infrastructure access,' said Alexander Urbelis, Chief Information Security Officer at ENS Labs. 'The victim is whoever holds the keys or access to the infrastructure that holds the keys.' Russia and Iran, by comparison, treat crypto as incidental, a means to broader geopolitical ends.
'Russia targets elections, energy infrastructure, and government systems. Iran goes after dissidents and regional adversaries,' Urbelis said. 'When either of them touches crypto, it's to move money, not to steal it from the ecosystem.' North Korea's singular focus has led its operatives to adopt tactics more commonly associated with intelligence agencies than criminal hackers: months-long relationship building, fabricated identities, and supply chain infiltration. The Drift campaign is just the latest example.
'You're not defending against a phishing email from a random scammer,' Urbelis said. 'You're defending against someone who spent six months building a relationship specifically to compromise one person who has the access you need to protect.' Crypto's architecture makes it a uniquely attractive hunting ground. In traditional finance, even successful hacks encounter friction in the form of compliance checks, correspondent bank checks, settlement delays, and the possibility of reversing fraudulent transfers.
In crypto, none of these safeguards exist at the protocol level. 'Once a transaction is signed and confirmed, it's final,' Urbelis said.
The Bybit exploit earlier last year moved $1.5 billion in roughly 30 minutes, a pace and scale that would be nearly impossible in the traditional banking system. This finality fundamentally changes the security calculus. In banking, a reasonable defense can be built across prevention, detection, and response, because there's always a window to freeze funds or reverse a wire.
In crypto, that window barely exists, which means stopping an attack before it happens isn't just preferable - it's essentially the only option. While banks operate under decades of regulatory guidance and audit requirements, many crypto projects are still improvising, often prioritizing speed and innovation over governance and controls.
This gap creates an environment where even sophisticated teams can be vulnerable, particularly to the kind of long-term infiltration tactics North Korea has been refining. 'This is the hardest operational security problem in crypto right now,' Urbelis said of the challenge of vetting against sophisticated fake identities and third-party intermediaries. 'I don't think the industry has solved it.'