BTC
ETH
HTX
SOL
BNB
View Market
简中
繁中
English
日本語
한국어
ภาษาไทย
Tiếng Việt

I interviewed a North Korean crypto hacker: loves *Frozen*, won't say a bad word about Kim Jong-un

深潮TechFlow
特邀专栏作者
2026-08-14 03:30
This article is about 4850 words, reading the full article takes about 7 minutes
A quiet, baby-faced introvert working under fluorescent lights, resembling a call center employee.
AI Summary
Expand
  • Core insight: A Korean-American journalist posed as a recruiter and conducted a video interview with a suspected North Korean state-sponsored hacker. By using a key test that required the interviewee to criticize Kim Jong-un, the journalist confirmed his identity, revealing the severe issue of large-scale North Korean hacker infiltration into global crypto companies.
  • Key elements:
    1. According to TRM Labs estimates, North Korean hackers have stolen over $6 billion in cryptocurrency cumulatively, and since 2020, almost all scaled crypto companies have experienced infiltration by North Korean IT workers.
    2. During the interview, the developer demonstrated solid technical skills and could read documents in real-time to answer questions. However, multiple rounds of testing exposed his fabricated identity (claiming to live in Long Beach, California, and hailing from Singapore, yet speaking with a Korean accent).
    3. When asked to say something negative about Kim Jong-un, the developer exited the call citing "unstable internet," later replying via Telegram that he "doesn't know much" and dodging the question, ultimately blocking the account.
    4. His online profile indicated he resides in Vladivostok, Russia, and is linked to the theft of approximately $2.7 million from MetaPlay in 2022, with on-chain transactions connected to North Korea-associated wallets.
    5. During the interview, the developer confirmed his favorite Disney movie was *Frozen*, a preference consistent with common answers from North Korean developers, serving as corroborating evidence of his identity.
    6. The report proposes a simple defense measure: crypto companies should require candidates to criticize Kim Jong-un during recruitment, a method that can effectively screen out and deter North Korean infiltration.

Original Author: Unchained Crypto

Original Translation: TechFlow

TechFlow Overview: A Korean-American journalist posed as a recruiter and conducted a video interview with a suspected North Korean state-sponsored hacker. The candidate was technically skilled, able to read developer documentation in real-time and answer impromptu questions. He claimed to be from Singapore but spoke with a Korean accent, and his favorite Disney movie was Frozen. When the interview reached its final question — "Please say something negative about Kim Jong Un" — he paused for a moment, then left the Zoom call.

As a Korean-American, my ancestors had to flee Pyongyang back in the day. For me, North Korea has always been a place of complex fascination.

So when North Korea security expert Taylor Monahan and Nick Bax of SEAL Alliance and Ump Labs asked if I wanted to personally interview a North Korean crypto developer who was applying for a job at Ump Labs, I didn't hesitate to say yes.

North Korea's top hackers have been stealing cryptocurrency for the authoritarian regime for years, with TRM Labs estimating the cumulative amount to exceed $6 billion. Even established companies like Consensys have accidentally hired what the FBI and the U.S. Department of Justice call North Korean "IT workers."

In 2024, CoinDesk was the first to report on how rampant this problem was within the industry — well-known projects like Cosmos Hub, Fantom, Sushi, and Yearn Finance had all unknowingly hired North Korean state-sponsored hackers.

As Monahan said on a recent episode of the Uneasy Money podcast: "Every crypto company of any significant size, at least since 2020, has had North Korean IT worker infiltration. Many companies have had as many as ten at the same time."

When I took on this assignment, my number one goal was: get the developer to say something derogatory about North Korean dictator Kim Jong Un to his face. This is widely recognized as the "Kryptonite" for North Koreans — the vast majority of North Korean developers will immediately terminate the interview when asked to do so.

To an American who can publicly tell the President of the United States to "go to hell" on Twitter, it seems almost absurd that North Koreans can't even meet such a simple requirement. But this is how dictatorships maintain power — through brainwashing to control people's thoughts, isolating them from all outside information, and then enforcing discipline with brutal physical punishment. According to Liberty in North Korea, an international NGO, "even the slightest criticism of Kim Jong Un can result in an entire family spending the rest of their lives in political prison camps."

Even though I've known all this for over a decade, I still wanted to witness it happen firsthand.

Background

Monahan and Bax showed me a document listing the IT worker's GitHub account, various online accounts linked to his email, his work history across multiple crypto projects like GameSwap, MetaPlay, and Cook Protocol, as well as on-chain links between his crypto wallets at various employers and other North Korean transactions. The file also included a screenshot — an announcement posted by a team he allegedly hacked, featuring his profile photo.

While these were all allegations, the pieces of evidence lined up tightly. Later, when I got on the video call, I confirmed he was the same person in the hacker announcement photo, which was in turn linked to those email addresses, profiles, and crypto wallet addresses.

These identity details appeared accurate and verifiable (though it's worth noting that North Korean IT workers sometimes maintain specific GitHub accounts as a team), but there were two parts that didn't add up. First, he claimed to live in Long Beach, California. Second, his English name was Justin Lim. (He had also used another alias, Jikun Liao — a surname that appears Chinese, and is likely fabricated or stolen.) His claimed location was a thread I could pull on to try to expose him.

Both Privileged and Unfree

The fact that he had any kind of online presence at all already set him apart from the vast majority of his fellow North Koreans — who are not only banned from using the internet, but most don't even have access to the country's domestic intranet. Even the smartphones officially issued by the North Korean government don't allow free browsing of the internal network. In this "Hermit Kingdom," ordinary North Koreans can face the death penalty, forced labor, or public denunciation for accessing any foreign media.

Another thing that set him apart: some of his online profiles suggested he was likely based in Vladivostok, Russia. His compatriots are not only forbidden from living abroad, but even traveling domestically requires permits.

But on reflection, the fact that he possessed these privileges makes sense — he's a North Korean state-sponsored hacker, a "honor" reserved only for the elite class.

Two Koreans Pretending to Be Chinese

Bax and Monahan also revealed another detail: this person allegedly stole approximately $2.7 million from MetaPlay in 2022. So he clearly had real skills. I was somewhat worried he might see through me — that I wasn't actually a recruiter but a journalist — and might even hack into my system to find out who I was.

Bax helped me draft the interview questions and told me what constituted appropriate answer ranges, so I could react and follow up reasonably. We also discussed which video conferencing platform would keep me safe without using a VPN, and I came up with a name for my recruiter persona: Sophie Wang.

It's amusing to think about — me and him, two Koreans, each disguising our identities with fake Chinese surnames.

I was both excited and nervous to come face-to-face (at least through a screen) with "my" hacker. Nick set up a Ump Labs work email for me and scheduled the Zoom meeting for Friday at 2 PM Eastern Time, which was 4 AM Saturday for him (Vladivostok time). The timing was odd, but given that his work was essentially forced labor, it seemed to make sense. After a rehearsal run-through with Bax, I was ready.

Cold-Blooded Criminal or Emotionless Worker?

The moment had arrived. I was finally face-to-face virtually with someone I had imagined as a ruthless con man and thief — a North Korean "IT worker."

Yet my first impression was: a quiet, baby-faced introverted young man, wearing a headset with a buzzing microphone, working under fluorescent lights, looking like a call center employee. He appeared to be around 22 years old.

I started with some casual probing questions that Bax and I had prepared in advance, hoping to find holes in his claimed Long Beach residence. But I found it difficult to press hard on these questions because they were essentially small talk — I didn't want to start off with an interrogation-style demeanor, which would expose my identity.

For example, I asked him what the weather was like in Long Beach, what had been happening recently in Los Angeles, and whether he'd ever been to Disneyland. Then I pretended to be unsure whether the California Disney park was called Disney Land or Disney World, to see if he'd correct me. He answered in single words throughout, and he completely ignored the Disney name question.

When I asked what he liked to do in his free time, he replied, "window shopping." While the answer was a bit odd, it wasn't something I could immediately debunk on the spot.

He seemed more like a detached, even emotionless tech geek. At one point I even wondered if he was reading from a script. The only piece of information that seemed remotely personal was his saying he enjoyed playing Dota 2. But then again, could that just be something made up to make himself look like an ordinary programmer? Either way, my overall feeling was: he was just trying to survive, or even just doing his "job" — getting hired and sending money back to the North Korean dictatorship.

Bax and Monahan were looking forward to me asking about his favorite Disney movie and had told me in advance that Frozen seemed to be the most common answer among North Korean developers. Sure enough, Lim confirmed that his favorite Disney movie was indeed Frozen.

He told me he was from Singapore. That was amusing, because the way he said "window shopping" had an unmistakable Korean accent, but I wasn't going to call it out just yet. I was still waiting for the climax.

No Wonder These North Korean Developers Get Hired

Next, I went through the full process of pretending to recruit for Ump Labs. My conclusion was: he might genuinely be a fairly capable blockchain engineer. He seemed proud to describe how he solved a problem where The Graph's indexing speed on the Velas network couldn't keep up with block processing, so he forked the Velas network to make it compatible with The Graph.

What impressed me wasn't just that he seemed to know the answers to my questions, but also that when I asked about OpenSea's Seaport protocol, he candidly admitted he didn't know it, then pulled up the developer documentation on the spot, analyzed it in real-time, and answered my question.

He clearly wanted this job badly. Another question he admitted he didn't know was about Uniswap v4 — he said he was familiar with v2 and v3, then proactively offered to go look up the v4 documentation.

Still a Skilled Hacker?

He was also flexible in his improvisation. Because Ump Labs was building a physical goods trading platform, he offered some quite creative off-the-cuff responses.

Of course, there's also the possibility that he was simply very good at using AI-assisted answers. But aside from those few questions, most of his answers seemed to come naturally.

Then came the security-related questions. These were designed by Bax, because North Korean operatives seem to carry out thefts by understanding how projects protect their funds. Lim responded that smart contract owners should use multi-sig wallets, then began offering various ideas for protecting smart contract security, such as preventing reentrancy attacks.

At that point, I said: "You should know that the crypto industry suffered a major attack. North Korea stole $1.5 billion from Bybit." Although my recording setup had issues and I didn't catch it on camera, I saw a slight smile flash across his face — the only one in the entire conversation.

The Moment I'd Been Waiting For

Bax and I had saved all the potentially uncomfortable questions for the end, so we could extract as much information as possible before he might leave.

First, I asked if he could fly to ETH Denver in person. He said yes, but wanted to work remotely for a few months first.

Then came my "holy grail" question. I chose my words very carefully. As a descendant of ancestors who concluded that communism doesn't work and fled from today's North Korea to a democratic society, and as an American journalist who believes freedom of speech is one of democracy's most important pillars, I deliberately chose the word used to describe the North Korean government: dictatorship. This was my way of trying to open a door in his mind — a door that might one day lead him to question the cruel, barbaric, inhumane system he was born into.

So, on what I believed might be the final question, I said: "As I mentioned earlier, the crypto industry has been heavily infiltrated by North Koreans representing the dictatorship, so we have to do a basic verification. Can you say something negative about Kim Jong Un?"

Silence. Then, in an extremely faint voice, he said something like, "I think it's not..." or "I think it's enough." Then he was gone.

I emailed him, pretending he had been disconnected, and asked if he could rejoin the Zoom call. Nine minutes later, he replied to "me" (Sophie Wang): "Hi Sophie, my network is very unstable today and I can't do a video call right now. If you can share your Discord or Telegram, we can chat there. Thanks."

Bax, Monahan, and I scrambled to set up a new Telegram account for Sophie. Once that was done, I reconnected with Lim — his username was Zero Bit — and he asked what Ump Labs paid Solidity developers. After I answered, I again asked him to say something negative about Kim Jong Un. He replied: "I don't know much."

I explained that this didn't require any knowledge — he just needed to say something negative about Kim Jong Un. After a few minutes of silence, he wrote: "It's quite special question, and never faced with other teams before." This looked very much like an AI-generated response.

Regardless, he was still trying to dodge the requirement. I didn't reply, and afterward, he may have reported or blocked me. After a while, I noticed that the Telegram account created for Sophie Wang was no longer usable, so I wasn't able to take screenshots to save the conversation. (Luckily, I had been messaging Bax and Monahan throughout to keep them updated on every detail.)

A Heavy Ending

I agreed to do this "undercover" work out of a nearly morbid curiosity — could he really not say one bad thing about Kim Jong Un? When that curiosity was satisfied, what remained was a somber, dazed feeling. At the same time, I felt immense gratitude toward my ancestors — especially my grandfather, for his foresight — and for the freedom of speech we Americans enjoy.

This experience also reinforced my conviction: as long as every crypto company ensures they ask this one question during recruitment, no more North Korean developers should be hired. These people will genuinely abandon all efforts.

If that's achieved, the North Korean regime will no longer be able to steal crypto assets through internal infiltration. It's a basic check, yet it could save the entire industry and the whole world a tremendous amount of trouble. I hope crypto companies around the world use this question in their hiring calls, so that North Korea's nuclear weapons program never receives a single cent from cryptocurrency.

As for Justin Lim, or whatever your real name is, I hope that one day, you and your compatriots will be freed from the Kim family's barbaric tyranny.

Safety
technology
Welcome to Join Odaily Official Community