我面试了一个朝鲜加密黑客:喜欢《冰雪奇缘》,说不出金正恩一句坏话
- 核心观点:一名韩裔美国记者伪装招聘人员,视频面试了一名疑似朝鲜国家级黑客,通过要求其批评金正恩的关键测试,确认其身份并揭示朝鲜黑客大规模渗透全球加密企业的严重问题。
- 关键要素:
- 据TRM Labs估算,朝鲜黑客累计窃取加密货币超60亿美元,且自2020年起几乎所有规模化加密公司均遭受过朝鲜IT工人渗透。
- 该开发者在面试中技术能力扎实,能实时阅读文档解答问题,但多轮测试暴露其编造身份(声称居住加州长滩、来自新加坡,却带韩国口音)。
- 当被要求说一句金正恩负面评价时,该开发者以“网络不稳定”为由退出通话,后续通过Telegram回复“了解不多”并回避问题,最终拉黑账号。
- 其网络资料显示常驻俄罗斯海参崴,且涉及2022年MetaPlay约270万美元被盗事件,链上交易与朝鲜相关钱包存在关联。
- 在面试中,该开发者确认最爱的迪士尼电影是《冰雪奇缘》,这一偏好与朝鲜开发者常见回答一致,成为身份佐证。
- 报道提出简单防御措施:加密公司应在招聘中要求应聘者批评金正恩,该方法可有效筛选并阻止朝鲜渗透。
Original Author: Unchained Crypto
Original Translation: TechFlow
Editor's Note: A Korean-American journalist, posing as a recruiter, conducted a video interview with a suspected North Korean state-sponsored hacker. The candidate was technically proficient, able to read developer documentation in real-time and improvise answers, claimed to be from Singapore but spoke with a Korean accent, and whose favorite Disney movie was *Frozen*. When the interview reached its final question — "Please say something bad about Kim Jong-un" — he paused for a moment and then left the Zoom call.
As a Korean-American, my ancestors had to flee Pyongyang. For me, North Korea has always been a place of complex fascination.
So, when North Korea security expert Taylor Monahan and Nick Bax of SEAL Alliance and Ump Labs asked if I wanted to personally interview a North Korean crypto developer who was applying for a job at Ump Labs, I didn't hesitate.
North Korea's top hackers have been stealing cryptocurrency for the regime for years, with TRM Labs estimating the total amount at over $6 billion. Even established companies like Consensys have accidentally hired "IT workers" that the FBI and the U.S. Department of Justice identify as North Korean.
In 2024, CoinDesk was the first to report on how rampant this problem is in the industry — well-known projects like Cosmos Hub, Fantom, Sushi, and Yearn Finance have all unknowingly employed North Korean state-sponsored hackers.
As Monahan said on a recent episode of the Uneasy Money podcast: "Every crypto company of any size has had North Korean IT worker infiltration since at least 2020. Many companies have even had ten at once."
When I took on this task, my top goal was: get the developer to say something derogatory about North Korea's dictator, Kim Jong-un. This is the acknowledged "Kryptonite" for North Koreans — the vast majority of DPRK developers will immediately terminate an interview if asked to do this.
To an American who can publicly tell the U.S. President to "go to hell" on Twitter, the fact that North Koreans cannot even meet such a simple request seems almost absurd. But this is how the dictatorship maintains power — through brainwashing to control people's thoughts, isolating them from all outside information, and enforcing discipline with cruel physical punishment. According to the international NGO Liberty in North Korea, "Even the slightest criticism of Kim Jong-un can result in an entire family spending the rest of their lives in political prison camps."
Although I have known about this for over a decade, I still wanted to witness it firsthand.
Background
Monahan and Bax showed me a document listing this IT worker's GitHub account, various online accounts linked to his email, his work experience on multiple crypto projects like GameSwap, MetaPlay, and Cook Protocol, and on-chain links between his crypto wallets at various employers and other North Korean transactions. The document also included a screenshot — an announcement from a team he allegedly hacked, featuring his profile photo.
While these are allegations, the clues connect tightly. Later, when I got on the video call, I confirmed that he was indeed the person in the hacker announcement photo, which was linked to those email addresses, profiles, and crypto wallet addresses.
These identity details seemed accurate and verifiable (though it's worth noting that North Korean IT workers sometimes operate in teams maintaining specific GitHub accounts), but two parts didn't add up. First, he claimed to live in Long Beach, California; second, his English name was Justin Lim. (He also used another alias, Jikun Liao — given that this surname is Chinese, it's likely fabricated or stolen.) His claimed location was a thread I could pull on, trying to get him to slip up.
Privileged Yet Unfree
The very fact that he has any kind of online presence already sets him apart from the vast majority of his fellow North Koreans — who are not only banned from using the internet, but most don't even have access to North Korea's domestic intranet. Even the smartphones officially distributed by the North Korean government don't allow free browsing of the internal network. In this "Hermit Kingdom," ordinary North Koreans can face the death penalty, labor camps, or public denunciation for accessing any foreign media.
Another thing that makes him stand out: some of his online profiles suggest he is likely based in Vladivostok, Russia. His fellow citizens are not only forbidden from living overseas, but even traveling domestically requires permits.
But when you think about it, it makes sense that he has these privileges — he is a North Korean state-sponsored hacker, an "honor" reserved only for the elite class.
Two Koreans Pretending to Be Chinese
Bax and Monahan also revealed a detail: this person allegedly stole approximately $2.7 million from MetaPlay in 2022. So he clearly has real skills. I was somewhat worried he might see through me as a journalist rather than a real recruiter, or even hack into my system to find out who I was.
Bax helped me draft the interview questions, telling me what constituted appropriate answers so I could react and follow up reasonably. We also discussed which video conferencing platform would keep me safe without using a VPN, and I came up with a name for my recruiter persona: Sophie Wang.
It's interesting to think about — me and him, two Koreans, each disguising ourselves with fake Chinese surnames.
I was both excited and nervous to come face-to-face with "my" hacker (at least through a screen). Nick set me up with a Ump Labs work email and scheduled the Zoom meeting for Friday at 2 PM Eastern Time, which was 4 AM Saturday for him (Vladivostok time). That was an odd time, but given that his work is essentially forced labor, it seemed to make sense. After a rehearsal with Bax, I was ready.
Cold-Hearted Criminal or Expressionless Worker?
The moment arrived. I finally came face-to-face — virtually — with someone I had imagined as a ruthless con artist and thief, a North Korean "IT worker."
However, my first impression was: a quiet, baby-faced introvert, wearing a headset, microphone buzzing, working under fluorescent lights, looking like a call center employee. He seemed around 22 years old.

I started with some casual probing questions that Bax and I had prepared, trying to find holes in his claimed Long Beach residence. But I found it hard to pressure him on these questions, because they were essentially small talk. I didn't want to start off with an interrogation vibe, which would blow my cover.
For example, I asked him about the weather in Long Beach, what had been happening in Los Angeles recently, and whether he had been to Disneyland. Then I pretended I wasn't sure if the California Disney was called Disney Land or Disney World, to see if he would correct me. Throughout, he answered in single words, and he didn't even take the bait on the Disney name.
When I asked what he liked to do in his free time, he answered: "Shopping." While the answer was a bit odd, it also wasn't something I could immediately call out as a slip.
He seemed more like an indifferent, even emotionless tech nerd. At one point, I even wondered if he was reading from a script. The only piece of information that seemed remotely personal was his saying he liked playing Dota 2. But then again, could that just be fabricated to look like a typical programmer? Either way, my overall feeling was: he was just trying to survive, or even just to do his "job" — get hired, then send money back to the North Korean regime.
Bax and Monahan were looking forward to me asking him his favorite Disney movie, and they had told me beforehand that *Frozen* seemed to be the most common answer among North Korean developers. Sure enough, Lim confirmed that his favorite Disney movie was indeed *Frozen*.
He told me he was from Singapore. That was amusing, because his accent when he said "window shopping" clearly sounded Korean, but I didn't plan to call that out just yet. I was still waiting for the climax.
No Wonder These North Korean Developers Get Hired
Next, I went through the process of pretending to recruit for Ump Labs. My conclusion was: he might indeed be a fairly capable blockchain engineer. He seemed proud to explain how he had solved a problem where The Graph's indexing speed on the Velas network couldn't keep up with block processing, so he forked the Velas network to make it compatible with The Graph.
What impressed me wasn't just that he seemed to know the answers to my questions, but also when I asked about OpenSea's Seaport protocol, he honestly said he didn't know it, then immediately pulled up the developer documentation and analyzed it in real-time to answer my question.
He clearly wanted this job. Another question he admitted not knowing was about Uniswap v4 — he said he was familiar with v2 and v3, and then volunteered to go look up the v4 documentation.
Still a Skilled Hacker?
He was also quick on his feet. Because Ump Labs was building a physical commodities trading platform, he gave some creative improvised responses.
Of course, there's also a possibility — he was just very good at using AI to assist his answers. But aside from those few questions, most of his answers seemed to come off the top of his head.
Then came the security-related questions. These were designed by Bax, because North Korean operatives seem to steal by understanding how projects protect their funds. Lim replied that the owner of a smart contract should use a multi-sig wallet, and then started throwing out various ideas for protecting smart contract security, such as preventing reentrancy attacks.
At that point, I said: "You should know that the crypto industry suffered a major attack. North Korea stole $1.5 billion from Bybit." Although my recording setup failed and didn't capture it, I saw a faint smile flash across his face — the only time during the entire conversation.
The Moment I Had Been Waiting For
Bax and I saved all the questions that might make him uncomfortable for the end, so we could get as much information as possible before he potentially left.
First, I asked if he could fly out to ETH Denver in person. He said he could, but wanted to work remotely for a few months first.
Then came my "holy grail" question. I chose my words very carefully. As a descendant of ancestors who determined communism wouldn't work and fled today's North Korea to a democratic society, and as an American journalist who believes freedom of speech is one of the most important pillars of democracy, I deliberately chose the word used to describe the North Korean government: dictatorship. This was my way of trying to open a door in his mind, so that perhaps one day he might question the cruel, barbaric, inhumane system he was born into.
So, in what I thought might be my final question, I said: "As I mentioned earlier, the crypto industry has been heavily infiltrated by North Koreans acting on behalf of a dictatorship, so we have to do a basic vetting check. Can you say something negative about Kim Jong-un?"
Silence. Then, extremely faintly, he said something like, "I think it's not…" or "I think it's enough." Then he was gone.
I emailed him, pretending he had dropped off, and asked if he could rejoin the Zoom. Nine minutes later, he replied to "me" (i.e., Sophie Wang): "Hi Sophie, my network is very unstable today, and I can't do video calls at the moment. If you can share your Discord or Telegram, we can chat there. Thanks."
Bax, Monahan, and I quickly scrambled to create a new Telegram account for Sophie. Once that was done, I reconnected with Lim — whose username was Zero Bit — and he asked what Ump Labs paid their Solidity developers. After I answered, I again asked him to say something negative about Kim Jong-un. He replied: "I don't know much."
I explained that this didn't require much knowledge — he just needed to say something negative about Kim Jong-un. After a few minutes of silence, he wrote: "It's quite special question, and never faced with other teams before." That seemed very likely to be an AI-generated response.
Either way, he was still trying to dodge the request. I didn't reply, and afterwards, perhaps he reported or blocked me. After a moment, I noticed the Telegram account created for Sophie Wang was no longer usable, so I couldn't even take a screenshot for the record. (Good thing I had been messaging Bax and Monahan throughout to log every detail.)
A Somber Ending
I took on this "undercover" work out of a morbid curiosity — could he really not say a single bad word about Kim Jong-un? When that curiosity was satisfied, what remained was a sad, dazed feeling. At the same time, I felt immense gratitude toward my ancestors — especially my grandfather, for his foresight — and for the freedom of speech we Americans enjoy.
This experience also reinforced my conviction: as long as every crypto company ensures they ask this one question during recruitment, no more North Korean developers should ever be hired. These people really will give up everything in their efforts.
If we achieve this, the North Korean regime will no longer be able to use insider infiltration to steal crypto assets. It's a basic check, yet it could save the entire industry and the whole world a massive headache. I hope crypto companies worldwide use this question on hiring calls, so that North Korea's nuclear weapons program never receives a single cent from cryptocurrency.
As for Justin Lim, or whatever your real name is, I hope that one day, you and your fellow citizens will be freed from the savage tyranny of the Kim family.


