A recent six-month infiltration campaign by North Korean hackers at Drift has sent shockwaves through the crypto industry, still reeling from massive exploits. But a more pressing question has emerged: what drives North Korea's persistent focus on crypto, and how does its approach differ from other state-backed hacking operations? According to security experts, the answer lies in the regime's desperate need for a revenue stream to stay afloat. 'North Korea lacks the luxury of patience,' said Dave Schwed, Chief Operating Officer at SVRN.
'Under comprehensive international sanctions, they require hard currency to fund their weapons programs, and crypto theft has been confirmed by the UN and multiple intelligence agencies as a primary funding mechanism for their nuclear and ballistic missile development.' This urgency explains why North Korean hackers carry out large-scale, traceable heists on public blockchains, rather than quietly using crypto to evade sanctions like other state actors. The reason, Schwed argues, is structural: Russia and Iran have functioning economies and use crypto as a payment rail, whereas North Korea has almost nothing to sell and needs direct revenue. 'Crypto theft provides them with immediate access to liquid value globally, without requiring a counterparty willing to do business with them,' Schwed explained.
This distinction - crypto as infrastructure versus crypto as a target - sets North Korea apart from Russia and Iran. While Russia and Iran use crypto to work around sanctions and fund proxy networks, North Korea is running a state-sponsored heist operation, targeting exchanges, wallet providers, DeFi protocols, and individual engineers and founders with signing authority or infrastructure access. 'The victim is whoever holds the keys or access to the infrastructure that holds the keys,' said Alexander Urbelis, Chief Information Security Officer at ENS Labs. Russia and Iran, in contrast, treat crypto as incidental to their broader geopolitical goals.
'Russia targets elections, energy infrastructure, and government systems, while Iran goes after dissidents and regional adversaries,' Urbelis said. 'When either of them touches crypto, it's to move money, not to steal it from the ecosystem.' North Korean operatives have adopted tactics more commonly associated with intelligence agencies, including months-long relationship building, fabricated identities, and supply chain infiltration.
The Drift campaign is just the latest example. 'You're not defending against a phishing email from a random scammer,' Urbelis said. 'You're defending against someone who spent six months building a relationship specifically to compromise one person who has the access you need to protect.' Crypto's architecture makes it a uniquely attractive hunting ground, with no safeguards like compliance checks, correspondent bank checks, or settlement delays.
'Once a transaction is signed and confirmed, it's final,' Urbelis said. The Bybit exploit earlier last year moved $1.5 billion in roughly 30 minutes, a pace and scale that would be nearly impossible in the traditional banking system. This finality fundamentally changes the security calculus, making stopping an attack before it happens the only viable option.
While banks operate under decades of regulatory guidance and audit requirements, many crypto projects are still improvising, prioritizing speed and innovation over governance and controls. This gap creates an environment where even sophisticated teams can be vulnerable to long-term infiltration tactics. 'This is the hardest operational security problem in crypto right now,' Urbelis said.
'I don't think the industry has solved it.'