A recent six-month infiltration campaign by North Korean hackers at Drift has raised concerns about the crypto industry's vulnerability to state-sponsored attacks. According to security experts, North Korea's approach differs significantly from other state-backed hacking operations, as it relies heavily on crypto to generate revenue and stay afloat. Dave Schwed, chief operating officer at SVRN, explains that North Korea's urgency stems from its lack of patience due to comprehensive international sanctions, which necessitates the need for hard currency to fund weapons programs. The UN and multiple intelligence agencies have confirmed that crypto theft is a primary funding mechanism for North Korea's nuclear and ballistic missile development.

North Korean hackers' large-scale, traceable heists on public blockchains have puzzled investigators, but Schwed argues that the answer lies in the structural differences between North Korea and other state actors. Unlike Russia and Iran, which have functioning economies and use crypto as a payment rail, North Korea has almost nothing to sell and needs direct revenue. Crypto theft provides North Korea with immediate access to liquid value globally, without requiring a counterparty willing to do business with them. Alexander Urbelis, chief information security officer at ENS Labs, notes that North Korea's targets are exchanges, wallet providers, DeFi protocols, and individual engineers and founders with signing authority or infrastructure access.

In contrast, Russia and Iran use crypto incidentally, as a means to broader geopolitical ends, targeting elections, energy infrastructure, and government systems. North Korean operatives have adopted tactics more commonly associated with intelligence agencies, including months-long relationship building, fabricated identities, and supply chain infiltration.

The Drift campaign is a recent example of this approach. The crypto ecosystem's architecture makes it an attractive hunting ground for North Korean hackers, as it lacks the safeguards present in traditional finance, such as compliance checks and settlement delays.

Once a transaction is signed and confirmed in crypto, it's final, making it challenging to reverse fraudulent transfers. The finality of crypto transactions fundamentally changes the security calculus, requiring a focus on prevention rather than detection and response.

While banks operate under decades of regulatory guidance, many crypto projects are still improvising, prioritizing speed and innovation over governance and controls. This gap creates an environment where even sophisticated teams can be vulnerable to long-term infiltration tactics, making it the hardest operational security problem in crypto right now, according to Urbelis.