Unchained CEO Laura Shin posed as a recruiter named "Sophie Wang" in a remote hiring interview with a software engineer using the name "Justin Lim," according to a Blockcast report republished from Crypto City. The man on the other side of the video call was described as a likely North Korean state-linked hacker who may have been in Vladivostok, Russia and had previously been suspected in the theft of $2.7 million.

Small talk produced early inconsistencies
The interview was framed as an ordinary crypto industry hiring call held on a Friday afternoon in U.S. Eastern time. Shin, a Korean American media executive who has long covered North Korean cyber threats, was identified in the report as someone whose ancestors had fled Pyongyang.
The applicant logged in on time even though it was said to be 4 a.m. in his local time zone. He claimed to live in both Singapore and the United States. Shin described him as appearing to be in his early 20s, reserved in demeanor, and often sounding as if he were reciting prepared answers.
When Shin tried to build rapport by talking about the weather in Long Beach, California and Disneyland, his responses were awkward. Asked about his favorite Disney movie, he named "Frozen," which the report said is considered one of the standard answers given by North Korean hacker applicants. In another exchange about his supposed life in Singapore, his pronunciation of phrases such as "window shopping" reportedly revealed a strong Korean accent.
Technical answers were solid, but one reference drew a reaction
For all the problems in casual conversation, the candidate handled blockchain topics comfortably. The report said he answered questions smoothly on multisignature wallet design and defenses against reentrancy attacks, and appeared eager to land the role.
At the same time, he kept an unusually rigid expression through nearly the entire meeting. That changed only once. Shin deliberately brought up the theft of $1.5 billion from crypto exchange Bybit in an attack attributed in the article to North Korean hackers. At that moment, she noticed a brief smile flash across his face. It was, according to the report, the only time he smiled during the interview.
The article said that detail matched a pattern long observed by security researchers: North Korean operatives posing as job candidates can show signs of familiarity with, or quiet approval of, hacking campaigns tied to their home country even while trying to maintain a fabricated identity.
A question about Kim Jong Un ended the call
Near the end of the interview, Shin asked what the report described as the decisive question: could he say something negative about North Korean leader Kim Jong Un.
The atmosphere changed immediately. The applicant, who had been restrained up to that point, appeared shaken and started to say, "I think that’s not really…" before cutting himself off. Seconds later, he blamed a bad connection and abruptly disconnected from the video call.
Nine minutes later, he contacted Shin on Telegram in an effort to recover the interview. When she repeated the same question, he sent back what the article described as an AI-like canned response: "I don’t know much about it; I’ve never encountered this situation before." He then blocked and reported Shin’s Telegram account.

Researchers had already been tracking the applicant
Before the undercover interview took place, security researcher Taylor Monahan and Nick Bax of startup Ump Labs had already been investigating the person using the name Justin Lim and had assembled several suspicious indicators.
One issue was the mismatch between identity claims and location data. He said he lived in Long Beach, California, but his online footprint suggested he was more likely in Vladivostok. The report also said he used another alias, "Jun Liao." Because "Liao" is a Chinese surname, that name did not fit cleanly with his claimed Singaporean background.
Researchers also examined wallet transaction records tied to his past work across crypto projects including GameSwap, Meta Play, and Cook Protocol. According to the report, those flows overlapped with addresses already associated with known North Korean hackers. He was also linked to the theft of roughly $2.7 million from Meta Play in 2022, and a wanted notice released by that project at the time reportedly showed a photo that matched the person seen in the interview.
Those findings led Monahan and Bax to ask Shin to take the role of recruiter and test him directly in a live call.
TRM Labs estimate tops $6 billion in stolen crypto
The report placed the interview in the context of a broader North Korean push into the crypto sector. Security firm TRM Labs was cited as estimating that North Korean hackers have stolen more than $6 billion in digital assets over the years.
It also said that organizations including MetaMask developer Consensys, Cosmos Hub, Fantom, Sushi, and Yearn Finance had unknowingly hired such operatives in the past.
After the interview, Shin called on the global crypto industry to add what she referred to as the "Kim Jong Un test" to hiring procedures. The article characterized the question as simple but impossible for North Korean operatives to answer, and as a line of defense against the use of stolen crypto assets to support North Korea’s nuclear weapons program.
The report ended by saying the experience left Shin with a sharper sense of what freedom of speech can cost under North Korea’s political system, where even a single disrespectful remark about the country’s leader can put an entire family at risk.

