A recent six-month infiltration campaign by North Korean hackers at Drift has raised concerns in the crypto industry, prompting questions about the regime's motivations and tactics. According to security experts, North Korea's reliance on crypto is driven by its need for a revenue stream to fund its nuclear and ballistic missile programs, as the country is under comprehensive international sanctions. Unlike other state-backed hackers, such as Russia and Iran, North Korea's approach is distinct in that it treats crypto as a direct source of revenue, rather than using it as a means to evade sanctions or fund other activities. This has led North Korean hackers to adopt sophisticated tactics, including months-long relationship building, fabricated identities, and supply chain infiltration, to target crypto exchanges, wallet providers, and other infrastructure.

The crypto industry's lack of traditional safeguards, such as compliance checks and settlement delays, makes it a uniquely attractive target for these hackers. The finality of crypto transactions also means that stopping an attack before it happens is the only viable option, making it a significant operational security challenge for the industry.