Close Menu
Altcoinvest
    What's Hot

    Ethereum Foundation-Backed Program Exposes 100 Nort Korea Operatives Infiltrating Crypto Firms

    April 19, 2026

    SEC Gives Some Self-Custody Crypto Apps 5 Years to Sort Out Broker Licensing

    April 19, 2026

    Warren Accuses SEC’s Paul Atkins of Misleading Congress

    April 19, 2026
    Facebook X (Twitter) Instagram
    Altcoinvest
    • Bitcoin
    • Altcoins
    • Exchanges
    • Youtube
    • Crypto Wallets
    • Learn Crypto
    • bitcoinBitcoin(BTC)$75,624.00-2.12%
    • ethereumEthereum(ETH)$2,346.76-3.03%
    • tetherTether(USDT)$1.000.00%
    • rippleXRP(XRP)$1.43-2.93%
    • binancecoinBNB(BNB)$627.75-2.68%
    • usd-coinUSDC(USDC)$1.000.01%
    • solanaSolana(SOL)$85.75-3.52%
    • tronTRON(TRX)$0.3277850.11%
    • Figure HelocFigure Heloc(FIGR_HELOC)$1.041.31%
    • dogecoinDogecoin(DOGE)$0.094938-4.31%
    Altcoinvest
    Home»Altcoins»Why North Korea hacks crypto instead of evading sanctions like Russia and Iran
    Why North Korea hacks crypto instead of evading sanctions like Russia and Iran
    Altcoins

    Why North Korea hacks crypto instead of evading sanctions like Russia and Iran

    April 12, 2026
    Share
    Facebook Twitter LinkedIn Pinterest Email

    North Korea’s six-month infiltration campaign at Drift rattled a crypto industry already reeling from billion-dollar exploits.

    But as the news settled, a bigger question came into focus: why does North Korea keep coming back to crypto in the first place, and why does its approach look so different from every other state-backed hacking operation on the planet?

    The short answer, according to security experts, is that crypto helps give the regime a revenue stream and keep them afloat.

    “North Korea doesn’t have the luxury of patience,” said Dave Schwed, chief operating officer at SVRN and the founder of the cybersecurity masters program at Yeshiva University. “They’re under comprehensive international sanctions and they need hard currency to fund weapons programs. The UN and multiple intelligence agencies have confirmed that crypto theft is a primary funding mechanism for their nuclear and ballistic missile development.”

    That urgency explains a dynamic that has long puzzled investigators: why North Korean hackers carry out large-scale, traceable heists on public blockchains instead of quietly using crypto to evade sanctions the way other state actors do.

    The answer, Schwed argues, is structural. Russia still has an economy: oil, gas, commodity exports, and trading partners willing to use workarounds. It needs crypto as a payment rail, but not for much else. Iran, too, has goods to move — sanctioned oil, proxy financing networks, willing intermediaries across the Middle East. North Korea has almost nothing left to sell.

    “Their exports are almost entirely sanctioned. They don’t have a functioning economy that needs a payment rail. They need direct revenue,” Schwed said. “Crypto theft gives them immediate access to liquid value, globally, without needing a counterparty willing to do business with them.”

    That distinction — crypto as infrastructure versus crypto as a target — is what separates North Korea not just from Russia, but from Iran as well. While Russia routes money through crypto to work around sanctions, and Iran uses it to fund proxy networks across the Middle East, North Korea is running something closer to a state-sponsored heist operation.

    “Their targets are exchanges, wallet providers, DeFi protocols and the individual engineers and founders who have signing authority or infrastructure access,” said Alexander Urbelis, chief information security officer at ENS Labs and a professor of cybersecurity at King’s College London. “The victim is whoever holds the keys or access to the infrastructure that holds the keys.”

    Russia and Iran, by comparison, treat crypto as incidental, a means to broader geopolitical ends.

    “Russia targets elections, energy infrastructure and government systems. Iran goes after dissidents and regional adversaries,” Urbelis said. “When either of them touches crypto, it’s to move money, not to steal it from the ecosystem.”

    That singular focus has pushed North Korean operatives to adopt tactics more commonly associated with intelligence agencies than criminal hackers: months-long relationship building, fabricated identities and supply chain infiltration.

    The Drift campaign is only the most recent example.

    “You’re not defending against a phishing email from a random scammer,” Urbelis said. “You’re defending against someone who spent six months building a relationship specifically to compromise one person who has the access you need to protect.”

    Crypto’s own architecture makes it a uniquely attractive hunting ground. In traditional finance, even successful hacks run into friction in the form of compliance checks, correspondent bank checks, settlement delays and the possibility of reversing fraudulent transfers. When North Korea’s hackers pulled off the Bangladesh Bank robbery in 2016, the heist took days to process and most of the funds were eventually recovered or blocked. In crypto, none of those safeguards exist at the protocol level.

    “Once a transaction is signed and confirmed, it’s final,” Urbelis said. The Bybit exploit earlier last year moved $1.5 billion in roughly 30 minutes, a pace and scale that would be nearly impossible in the traditional banking system.

    That finality fundamentally changes the security calculus. In banking, a reasonable defense can be built across prevention, detection and response, because there’s always a window to freeze funds or reverse a wire. In crypto, that window barely exists, which means stopping an attack before it happens isn’t just preferable — it’s essentially the only option.

    And while banks operate under decades of regulatory guidance and audit requirements, many crypto projects are still improvising — often prioritizing speed and innovation over governance and controls.

    That gap creates an environment where even sophisticated teams can be vulnerable, particularly to the kind of long-term infiltration tactics North Korea has been refining.

    “This is the hardest operational security problem in crypto right now,” Urbelis said of the challenge of vetting against sophisticated fake identities and third-party intermediaries. “I don’t think the industry has solved it.”

    Read more: How North Korea’s 6-month long secret espionage program has crypto community rethinking security

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    Ethereum Foundation-Backed Program Exposes 100 Nort Korea Operatives Infiltrating Crypto Firms

    April 19, 2026

    GalaxyOne Head Wants Retail Investors to Stake More, Predict Less

    April 19, 2026

    50,640 People Affected After Hackers Hit Healthcare Firm, Stealing Personal, Financial and Medical Data

    April 18, 2026

    What Is The XLS-66 And What Does It Mean For XRP Holders?

    April 18, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Tweets by InfoAltcoinvest

    Top Posts

    Ethereum Foundation-Backed Program Exposes 100 Nort Korea Operatives Infiltrating Crypto Firms

    April 19, 2026

    GalaxyOne Head Wants Retail Investors to Stake More, Predict Less

    April 19, 2026

    50,640 People Affected After Hackers Hit Healthcare Firm, Stealing Personal, Financial and Medical Data

    April 18, 2026

    Pepe Coin Price Prediction 🐸 Pepe Heading For Huge End Of 2025 ?! 🎆 Pepecoin News Today 🐸

    December 26, 2025

    XRP Leads Crypto Institutional Revival with Massive Weekly Inflows Topping BTC, ETH ⋆ ZyCrypto

    April 10, 2026

    BREAKOUT: How High Can BTC Go On This Current Rally? [Will Alts Follow?]

    January 25, 2026

    Expert Outlines Reasons to be Bullish for Crypto Market in 2026‬ ⋆ ZyCrypto

    December 14, 2025

    Altcoinvest is a leading platform dedicated to providing the latest news and insights on the dynamic world of cryptocurrencies.

    We're social. Connect with us:

    Facebook X (Twitter)
    Top Insights

    Ethereum Foundation-Backed Program Exposes 100 Nort Korea Operatives Infiltrating Crypto Firms

    April 19, 2026

    SEC Gives Some Self-Custody Crypto Apps 5 Years to Sort Out Broker Licensing

    April 19, 2026

    Warren Accuses SEC’s Paul Atkins of Misleading Congress

    April 19, 2026
    Get Informed

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.


    Facebook X (Twitter)
    • Home
    • About us
    • Contact Us
    • Privacy Policy
    • Terms & Conditions
    © 2026 altcoinvest.com

    Type above and press Enter to search. Press Esc to cancel.