Scallop founder Kris Lai said a blockchain engineer who approached him on Telegram and asked to join the team blocked him within hours after he was asked to record a FaceTime clip saying 「Kim Jong-un is an ugly pig」, a test Lai used because he suspected the applicant could be tied to North Korean IT worker activity.
A Telegram applicant claimed deep familiarity with Scallop’s stack
Lai said the exchange began in the early hours of Aug. 19, when a Telegram account named Yuto Kazuma sent him a direct message and introduced himself as a blockchain engineer from Tokyo.
Based on screenshots shared by Lai, the applicant said he had researched Scallop and spent time reading its GitHub repositories. He specifically mentioned the Sui lending protocol, Sui Kit, the Scallop SDK, and a newer AI Skill integration.
The person described himself as an engineer focused on blockchain and AI, with experience in blockchain infrastructure, backend systems, automation, and distributed services. He also claimed work experience in production blockchain backends, Solana RPC and WebSocket infrastructure, transaction pipelines, smart contracts, and AI agents.
He told Lai he was particularly interested in Scallop’s infrastructure, wanted to learn more about what the team was building, and asked whether there was any way he could help.
Lai skipped the normal interview route
Rather than moving into an ordinary hiring process, Lai replied with a short instruction: 「record a facetime telling me ‘Kim Jong-un is an ugly pig.’」
Lai said that a few hours later, he found that the account had blocked him.
The request looked absurd on its face, but Lai’s reaction tracked a risk that has become a recurring concern across tech and crypto: remote North Korean IT workers using false identities to pursue overseas engineering jobs. In this case, Lai appeared to use a political taboo as a fast identity screen, betting that a North Korean operative would be unwilling to insult the country’s top leader on camera.
Another detail that raised concern for him was the number of crypto industry groups he shared with the Telegram account, suggesting the profile may already have entered Web3 developer and project communities.
Lai later disclosed the applicant’s GitHub, personal website, Telegram, Discord, email, and the projects and work history the person claimed as his own. He described it sarcastically as a portfolio for people to inspect.
A wider pattern already flagged by U.S. authorities
The incident lines up with a larger security issue that U.S. authorities have warned about for years: North Korean IT workers applying for remote engineering roles overseas under stolen or fabricated identities, collecting salaries, and in some cases obtaining access to corporate systems.
According to an earlier report cited in the article, North Korea generated an estimated $2.8 billion over the past two years by using remote IT workers to infiltrate companies in the United States and Europe.
A United Nations multilateral sanctions monitoring body estimated that this IT worker network brings in roughly $250 million to $600 million a year for North Korea, with some of the money believed to support its nuclear and weapons programs.
In April this year, a related U.S. Department of Justice case ended in heavy prison sentences. Two New Jersey residents, Kejia Wang and Zhenxing Wang, were sentenced to nine years and about seven years and eight months, respectively.
The two helped run infrastructure commonly described as a laptop farm, which allowed North Korean IT workers located overseas to remotely control company computers placed inside the United States. The core of the setup was to make the engineers appear as if they were actually living and working in the U.S.
Under that model, North Korean workers use stolen or forged identities to land remote jobs. Once hired, company-issued laptops are not shipped to the real worker but to U.S.-based accomplices running the laptop farm. Those local helpers receive and set up the machines, then let overseas operators connect through tools such as RDP and AnyDesk.
As a result, the device footprint, IP address, and working time zone seen by the employer may all appear to be in the United States, while the actual coder is elsewhere. The case involved at least 80 U.S. citizens whose identities were stolen and more than 100 victim companies, including Fortune 500 firms, and brought in more than $5 million for North Korea.
Scallop said it raised $3 million in 2024
Scallop is a DeFi lending protocol in the Sui ecosystem. It is built as a money market on Sui Move and offers asset supply, collateral, and borrowing functions. The project also provides development tools including the Scallop SDK and Sui Kit.
In 2024, Scallop said it had raised a cumulative $3 million. Using the rough exchange range cited in the report of NT$31 to NT$32 per U.S. dollar, that works out to about NT$93 million to NT$96 million.
The round was co-led by CMS Holdings and 6th Man Ventures. Other investors named in the report included KuCoin Labs, UOB Venture Management, Mysten Labs, Blockchain Founders Fund, Signum Capital, Cypher Capital, LBank Labs, ViaBTC, and Cetus Protocol.
With remote work and AI-assisted development becoming more common, the article argues that for DeFi teams responsible for significant on-chain assets, the question of who is actually writing the code is becoming as important as the security of the code itself.

