Reporter posing as recruiter says suspected North Korean crypto developer left call after question about Kim Jong Un

Reporter posing as recruiter says suspected North Korean crypto developer left call after question about Kim Jong Un

N
News Editor
2026-08-14 01:16:53
TechFlowPost, citing a translated report from Unchained Crypto, described an undercover interview with a suspected North Korean crypto developer who had applied to Ump Labs. The interview was arranged with help from North Korea-focused security researcher Taylor Monahan and Nick Bax of SEAL Alliance and Ump Labs. According to the report, the candidate presented himself as a blockchain engineer with prior experience at projects including GameSwap, MetaPlay, and Cook Protocol, while investigators had also collected GitHub accounts, email-linked profiles, wallet activity, and other online traces they believed tied him to North Korean operations. During the call, the applicant said he lived in Long Beach, California, said he was from Singapore, and named Disney’s "Frozen" as his favorite film. He also answered technical questions on blockchain development, discussed The Graph and the Velas network, admitted gaps in his knowledge around Seaport and Uniswap v4, and pulled up documentation live to respond. The interview ended when the reporter asked him to make a negative comment about Kim Jong Un as part of what she described as a basic screening check. He left the Zoom call, later moved the conversation to Telegram, and still did not comply. The report also cited TRM Labs’ estimate that North Korean hackers have stolen more than $6 billion in crypto over the years.

A Korean American reporter posing as a recruiter said a suspected North Korean crypto developer abruptly ended a video interview after being asked to say something negative about Kim Jong Un.

Reporter posing as recruiter says suspected North Korean crypto developer left call after question about Kim Jong Un 2

The account was published by Unchained Crypto and translated by TechFlowPost. In the story, North Korea security researcher Taylor Monahan and Nick Bax of SEAL Alliance and Ump Labs asked the reporter to interview a developer who had applied for a job at Ump Labs and was suspected of being tied to North Korean operations.

How the candidate was identified

The report cited TRM Labs as estimating that North Korean hackers have stolen more than $6 billion in crypto over the years. It also said even established firms such as Consensys had at one point unknowingly hired people described by the FBI and the U.S. Department of Justice as North Korean “IT workers.”

The story also pointed to CoinDesk’s 2024 reporting on how widespread the problem had become across the industry, naming Cosmos Hub, Fantom, Sushi, and Yearn Finance among projects that had unknowingly hired North Korean state-linked hackers. Monahan was quoted from a recent Uneasy Money podcast appearance saying, “Every crypto company with any size, since at least 2020, has had North Korean IT worker infiltration. Many have had ten at the same time.”

Monahan and Bax showed the reporter a document listing the worker’s GitHub account, online accounts linked to his email, work history at crypto projects including GameSwap, MetaPlay, and Cook Protocol, and onchain links between wallets tied to his employers and other North Korean transactions. The file also included a screenshot from a notice posted by a team that had allegedly been hacked by him, along with a profile photo.

While those claims remained allegations, the report said the pieces fit together closely. After joining the video call, the reporter said she confirmed that the man on camera matched the person in the image from the hack notice, which in turn matched the related email addresses, profiles, and wallet addresses.

The article said much of the identity information appeared accurate and verifiable, while noting that North Korean IT workers sometimes operate shared GitHub accounts. Two elements did not line up, however. The candidate claimed to live in Long Beach, California, and used the English name Justin Lim. He had also used another alias, Jikun Liao, which the report suggested may have been fabricated or borrowed.

A privileged but restricted profile

The reporter argued that the man’s online footprint alone set him apart from most North Koreans, who, according to the article, are barred from using the internet and often cannot even access the country’s domestic intranet. The piece said even state-issued smartphones do not allow free browsing of internal networks, and that contact with outside media can lead to death, forced labor, or public punishment.

Another unusual detail was that some of his online traces suggested he may have been based in Vladivostok, Russia. The article contrasted that with the reality faced by ordinary North Koreans, who are not allowed to live abroad freely and often need permits even for domestic travel.

The story framed those privileges as consistent with his suspected role as a state-level hacker, a class that would sit far above the average North Korean citizen.

Setting up the interview

Bax and Monahan also told the reporter that the same person was allegedly involved in the theft of about $2.7 million from MetaPlay in 2022. That, the article said, raised concern that he might detect the recruiter cover story or even try to compromise the reporter’s systems.

Bax prepared interview questions, explained what would count as a plausible range of answers, and worked through follow-up strategy. They also discussed which video platform would be safest without using a VPN. The recruiter identity used for the call was given the name Sophie Wang.

Nick Bax then set up a Ump Labs work email account for her and scheduled the Zoom call for 2 p.m. on Friday Eastern Time, which would have been 4 a.m. Saturday in Vladivostok. The article described the timing as odd on its face, but not impossible if the work resembled coercive labor.

On-camera impressions

When the call began, the reporter said the man did not look like the image she had formed in her head of a hardened thief. Instead, she described a quiet, introverted young man with a baby face, wearing a headset, sitting under fluorescent lights with a buzzing microphone and looking more like a call-center employee. She estimated he was about 22 years old.

She opened with small talk designed to test his claim that he lived in Long Beach. She asked about the weather there, what was happening lately in Los Angeles, and whether he had visited Disney. She also pretended not to remember whether the California park was called Disneyland or Disney World, hoping he would correct her, but he did not take the bait.

Asked what he liked to do in daily life, he answered, “window shopping.” The reporter wrote that the reply was odd but not enough to expose him. More broadly, he came across as emotionally flat, to the point that she briefly wondered whether he was reading from a script. One of the few personal details he offered was that he liked playing Dota 2.

Bax and Monahan had told her in advance that “Frozen” seemed to be a common answer from North Korean developers when asked about favorite Disney movies. During the interview, Lim said “Frozen” was his favorite.

He also told the reporter that he was from Singapore. She wrote that the claim sounded dubious because the way he said “window shopping” carried a Korean accent, though she chose not to challenge him at that stage.

Technical answers and live documentation checks

Once the conversation shifted into a standard hiring flow, the reporter concluded that he may in fact have been a capable blockchain engineer.

She said he spoke with apparent pride about solving a problem in which The Graph could not index the Velas network as fast as blocks were being processed. According to his answer, he forked the Velas network to make it compatible with The Graph.

What stood out more was his handling of topics he did not know well. When asked about OpenSea’s Seaport protocol, he openly said he was unfamiliar with it, then pulled up the developer documentation on the spot and analyzed it in real time before answering. He gave a similar response on Uniswap v4, saying he knew v2 and v3 and volunteering to check the v4 documentation.

The article said he appeared eager to get the job. On questions tied to Ump Labs’ work on a physical-goods trading platform, he improvised several answers the reporter described as creative. She added that it was possible he was using AI to help craft some responses, but outside a few questions, most of what he said seemed spontaneous.

Security questions and a reaction to Bybit

The interview later turned to security, an area Bax had specifically structured because, according to the report, North Korean operatives may learn how projects protect funds and then use that knowledge to steal them.

Lim said a smart contract owner should use a multisig wallet and then offered other ideas for improving contract security, including guarding against reentrancy attacks.

At one point, the reporter said, “You probably know the crypto industry suffered a major attack. North Korea stole $1.5 billion from Bybit.” Although the recording setup failed to capture it clearly, she said she saw a brief smile cross his face, the only notable expression she observed during the entire conversation.

The final question

Bax and the reporter saved the most difficult questions for the end so they could gather as much information as possible before he left. She first asked whether he could travel in person to ETH Denver. He said yes, but wanted to work remotely for a few months first.

Then came what she described as the key question. She told him that because the crypto industry had been heavily infiltrated by North Koreans representing a dictatorship, the company had to perform a basic screening check. She asked whether he could say something negative about Kim Jong Un.

According to the article, he fell silent. Then he said something very faint, either “I think it’s not…” or “I think it’s enough,” and disappeared from the Zoom call.

The reporter then emailed him, pretending he had simply dropped offline, and asked whether he could rejoin. Nine minutes later, he replied: “Hi Sophie, my network is very unstable today, and I’m unable to continue the video call for now. If you can share your Discord or Telegram, we can talk there. Thanks.”

Telegram follow-up

Bax, Monahan, and the reporter quickly created a new Telegram account for Sophie Wang and reconnected with him there. The report said his Telegram username was Zero Bit.

He first asked what the compensation was for a Solidity developer at Ump Labs. After she answered, the reporter again asked him to make a negative comment about Kim Jong Un. He replied, “I don’t know much.”

She responded that no special knowledge was needed, and that he only had to say something negative. After several minutes of silence, he wrote, “It’s quite special question, and never faced with other teams before.” The reporter said the line looked likely to have been AI-generated.

The article said he still tried to avoid the request. She did not respond again. Some time later, she found that the Telegram account created for Sophie Wang no longer worked, which meant she could not preserve screenshots, though she said she had been messaging Bax and Monahan throughout with real-time updates.

The author’s conclusion

The reporter wrote that she agreed to the undercover interview out of a near-obsessive curiosity about whether he truly could not say a single bad word about Kim Jong Un. Once the answer became clear, she said the feeling left behind was sadness rather than satisfaction.

She also said the experience convinced her that if crypto companies consistently ask this one question during hiring, they should no longer end up hiring North Korean developers. In her view, that simple check could reduce the risk of infiltration used to gather internal intelligence and later steal crypto assets.

The story ended with a direct appeal for crypto companies around the world to use the question in recruitment calls so that, in the author’s words, North Korea’s nuclear weapons program would not receive even one more cent from crypto.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
70

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.