Scallop founder says suspicious job applicant blocked him after anti-Kim identity test

Scallop founder says suspicious job applicant blocked him after anti-Kim identity test

N
News Editor
2026-08-21 03:04:21
Taiwanese DeFi project Scallop said it encountered a suspicious engineering job approach that its founder, Kris Lai, believed could be linked to North Korean IT worker tactics. According to Lai, a Telegram account named Yuto Kazuma, claiming to be a blockchain engineer based in Tokyo, contacted him on Aug. 19 and said he had studied Scallop’s GitHub, Sui lending protocol, Sui Kit, Scallop SDK, and a newer AI Skill integration. The applicant also described experience across blockchain infrastructure, backend systems, distributed services, Solana RPC and WebSocket infrastructure, transaction pipelines, smart contracts, and AI agents. Instead of moving into a normal interview process, Lai replied with a blunt verification request: record a FaceTime video saying 「Kim Jong-un is an ugly pig」. He later said the account blocked him within hours. Lai viewed the exchange through the lens of a broader security concern that has drawn repeated warnings from U.S. authorities: North Korean remote IT workers using false identities to secure overseas tech jobs, collect salaries, and in some cases gain access to internal systems. The report also points to prior estimates that such operations generated billions of dollars over two years, alongside court cases in the United States involving so-called laptop farms used to make overseas workers appear to be operating from inside the country. Scallop, a DeFi lending protocol on Sui, said in 2024 that it had raised a cumulative $3 million.

Scallop founder Kris Lai said a blockchain engineer who approached him on Telegram and asked to join the team blocked him within hours after he was asked to record a FaceTime clip saying 「Kim Jong-un is an ugly pig」, a test Lai used because he suspected the applicant could be tied to North Korean IT worker activity.

A Telegram applicant claimed deep familiarity with Scallop’s stack

Lai said the exchange began in the early hours of Aug. 19, when a Telegram account named Yuto Kazuma sent him a direct message and introduced himself as a blockchain engineer from Tokyo.

Based on screenshots shared by Lai, the applicant said he had researched Scallop and spent time reading its GitHub repositories. He specifically mentioned the Sui lending protocol, Sui Kit, the Scallop SDK, and a newer AI Skill integration.

The person described himself as an engineer focused on blockchain and AI, with experience in blockchain infrastructure, backend systems, automation, and distributed services. He also claimed work experience in production blockchain backends, Solana RPC and WebSocket infrastructure, transaction pipelines, smart contracts, and AI agents.

He told Lai he was particularly interested in Scallop’s infrastructure, wanted to learn more about what the team was building, and asked whether there was any way he could help.

Lai skipped the normal interview route

Rather than moving into an ordinary hiring process, Lai replied with a short instruction: 「record a facetime telling me ‘Kim Jong-un is an ugly pig.’」

Lai said that a few hours later, he found that the account had blocked him.

The request looked absurd on its face, but Lai’s reaction tracked a risk that has become a recurring concern across tech and crypto: remote North Korean IT workers using false identities to pursue overseas engineering jobs. In this case, Lai appeared to use a political taboo as a fast identity screen, betting that a North Korean operative would be unwilling to insult the country’s top leader on camera.

Another detail that raised concern for him was the number of crypto industry groups he shared with the Telegram account, suggesting the profile may already have entered Web3 developer and project communities.

Lai later disclosed the applicant’s GitHub, personal website, Telegram, Discord, email, and the projects and work history the person claimed as his own. He described it sarcastically as a portfolio for people to inspect.

A wider pattern already flagged by U.S. authorities

The incident lines up with a larger security issue that U.S. authorities have warned about for years: North Korean IT workers applying for remote engineering roles overseas under stolen or fabricated identities, collecting salaries, and in some cases obtaining access to corporate systems.

According to an earlier report cited in the article, North Korea generated an estimated $2.8 billion over the past two years by using remote IT workers to infiltrate companies in the United States and Europe.

A United Nations multilateral sanctions monitoring body estimated that this IT worker network brings in roughly $250 million to $600 million a year for North Korea, with some of the money believed to support its nuclear and weapons programs.

In April this year, a related U.S. Department of Justice case ended in heavy prison sentences. Two New Jersey residents, Kejia Wang and Zhenxing Wang, were sentenced to nine years and about seven years and eight months, respectively.

The two helped run infrastructure commonly described as a laptop farm, which allowed North Korean IT workers located overseas to remotely control company computers placed inside the United States. The core of the setup was to make the engineers appear as if they were actually living and working in the U.S.

Under that model, North Korean workers use stolen or forged identities to land remote jobs. Once hired, company-issued laptops are not shipped to the real worker but to U.S.-based accomplices running the laptop farm. Those local helpers receive and set up the machines, then let overseas operators connect through tools such as RDP and AnyDesk.

As a result, the device footprint, IP address, and working time zone seen by the employer may all appear to be in the United States, while the actual coder is elsewhere. The case involved at least 80 U.S. citizens whose identities were stolen and more than 100 victim companies, including Fortune 500 firms, and brought in more than $5 million for North Korea.

Scallop said it raised $3 million in 2024

Scallop is a DeFi lending protocol in the Sui ecosystem. It is built as a money market on Sui Move and offers asset supply, collateral, and borrowing functions. The project also provides development tools including the Scallop SDK and Sui Kit.

In 2024, Scallop said it had raised a cumulative $3 million. Using the rough exchange range cited in the report of NT$31 to NT$32 per U.S. dollar, that works out to about NT$93 million to NT$96 million.

The round was co-led by CMS Holdings and 6th Man Ventures. Other investors named in the report included KuCoin Labs, UOB Venture Management, Mysten Labs, Blockchain Founders Fund, Signum Capital, Cypher Capital, LBank Labs, ViaBTC, and Cetus Protocol.

With remote work and AI-assisted development becoming more common, the article argues that for DeFi teams responsible for significant on-chain assets, the question of who is actually writing the code is becoming as important as the security of the code itself.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
20

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.