A recent six-month infiltration campaign by North Korean hackers at Drift has raised concerns in the crypto industry, highlighting the regime's reliance on crypto to generate revenue. According to security experts, North Korea's approach differs significantly from other state-backed hacking operations, as it focuses on large-scale, traceable heists on public blockchains to obtain immediate access to liquid value.
This is in contrast to countries like Russia and Iran, which use crypto to evade sanctions and fund proxy networks. North Korea's targets include exchanges, wallet providers, DeFi protocols, and individual engineers and founders with signing authority or infrastructure access. The regime's operatives have adopted tactics commonly associated with intelligence agencies, such as months-long relationship building, fabricated identities, and supply chain infiltration.
The crypto industry's lack of traditional safeguards, such as compliance checks and settlement delays, makes it a uniquely attractive target for North Korean hackers. The finality of crypto transactions means that stopping an attack before it happens is essentially the only option, and the industry's improvisational approach to governance and controls creates an environment where even sophisticated teams can be vulnerable to long-term infiltration tactics.