A recent six-month infiltration campaign by North Korean hackers at Drift has sent shockwaves through the crypto industry, which is still reeling from massive exploits. But a more pressing question has emerged: why does North Korea persist in targeting crypto, and what makes its approach distinct from other state-backed hacking operations? According to security experts, crypto provides the regime with a vital revenue stream, enabling it to stay afloat. 'North Korea lacks the luxury of patience,' explained Dave Schwed, Chief Operating Officer at SVRN and founder of the cybersecurity masters program at Yeshiva University.

'Under comprehensive international sanctions, they require hard currency to fund their weapons programs.' The UN and multiple intelligence agencies have confirmed that crypto theft is a primary funding mechanism for North Korea's nuclear and ballistic missile development. This urgency explains why North Korean hackers carry out large-scale, traceable heists on public blockchains instead of quietly using crypto to evade sanctions like other state actors. The answer, Schwed argues, lies in the structural differences between North Korea and other sanctioned nations like Russia and Iran.

While Russia and Iran have functioning economies and use crypto as a payment rail to work around sanctions, North Korea has almost nothing to sell due to stringent sanctions on its exports. 'Their exports are almost entirely sanctioned, and they don't have a functioning economy that needs a payment rail,' Schwed said. 'They need direct revenue, and crypto theft provides them with immediate access to liquid value globally without requiring a counterparty willing to do business with them.' This distinction - crypto as infrastructure versus crypto as a target - sets North Korea apart from Russia and Iran. While Russia and Iran use crypto to fund broader geopolitical objectives, North Korea operates a state-sponsored heist operation, targeting exchanges, wallet providers, DeFi protocols, and individual engineers and founders with signing authority or infrastructure access.

'Their targets are those who hold the keys or have access to the infrastructure that holds the keys,' said Alexander Urbelis, Chief Information Security Officer at ENS Labs and a professor of cybersecurity at King's College London. In contrast, Russia and Iran view crypto as incidental, a means to achieve broader geopolitical ends.

'Russia targets elections, energy infrastructure, and government systems, while Iran goes after dissidents and regional adversaries,' Urbelis said. 'When either of them touches crypto, it's to move money, not to steal it from the ecosystem.' North Korea's singular focus has driven its operatives to adopt tactics more commonly associated with intelligence agencies than criminal hackers, including months-long relationship building, fabricated identities, and supply chain infiltration. The Drift campaign is a recent example of this approach.

'You're not defending against a phishing email from a random scammer,' Urbelis said. 'You're defending against someone who spent six months building a relationship specifically to compromise one person who has the access you need to protect.' Crypto's architecture makes it a uniquely attractive hunting ground for North Korean hackers.

In traditional finance, successful hacks often encounter friction in the form of compliance checks, correspondent bank checks, settlement delays, and the possibility of reversing fraudulent transfers. In crypto, these safeguards do not exist at the protocol level.

'Once a transaction is signed and confirmed, it's final,' Urbelis said. The Bybit exploit earlier last year moved $1.5 billion in roughly 30 minutes, a pace and scale that would be nearly impossible in the traditional banking system.

This finality fundamentally changes the security calculus, making it essential to stop attacks before they happen. While banks operate under decades of regulatory guidance and audit requirements, many crypto projects are still improvising, often prioritizing speed and innovation over governance and controls.

This gap creates an environment where even sophisticated teams can be vulnerable, particularly to the kind of long-term infiltration tactics North Korea has been refining. 'This is the hardest operational security problem in crypto right now,' Urbelis said of the challenge of vetting against sophisticated fake identities and third-party intermediaries. 'I don't think the industry has solved it.'