A recent six-month infiltration campaign by North Korean hackers at Drift has sent shockwaves through the crypto industry, which is still reeling from billion-dollar exploits. The question on everyone's mind is: why does North Korea keep targeting crypto, and what sets its approach apart from other state-backed hacking operations?

According to security experts, the answer lies in the regime's desperate need for a revenue stream to fund its nuclear and ballistic missile development programs. North Korea is under comprehensive international sanctions, and crypto theft has become a primary funding mechanism. Unlike other state actors, such as Russia and Iran, which use crypto to evade sanctions or fund proxy networks, North Korea relies on large-scale, traceable heists on public blockchains to generate direct revenue. This is because the regime has almost no other exports to sell, and its economy is heavily sanctioned.

Crypto theft provides North Korea with immediate access to liquid value, globally, without the need for a counterparty willing to do business with them. This distinction - crypto as infrastructure versus crypto as a target - is what separates North Korea from other state-backed hackers. While Russia and Iran use crypto to move money and fund broader geopolitical ends, North Korea is running a state-sponsored heist operation, targeting exchanges, wallet providers, DeFi protocols, and individual engineers and founders with signing authority or infrastructure access. The regime's operatives have adopted tactics more commonly associated with intelligence agencies, including months-long relationship building, fabricated identities, and supply chain infiltration.

The Drift campaign is just the latest example. The crypto industry's own architecture makes it a uniquely attractive hunting ground for North Korean hackers, as it lacks the safeguards and compliance checks that exist in traditional finance. Once a transaction is signed and confirmed, it's final, and the possibility of reversing fraudulent transfers is slim. This finality fundamentally changes the security calculus, making it essential to stop attacks before they happen.

However, many crypto projects are still improvising, prioritizing speed and innovation over governance and controls, creating an environment where even sophisticated teams can be vulnerable to long-term infiltration tactics. The challenge of vetting against sophisticated fake identities and third-party intermediaries is the hardest operational security problem in crypto right now, and the industry has yet to find a solution.