PodBrowser
Unchained

I Interviewed a North Korean Hacker Posing as a Crypto Dev

Thursday, 13 August 2026 · 3 min read · Listen to the episode ↗

Taylor Monahan, a security researcher who estimates North Korean hackers have stolen over $6 billion in crypto for the regime, joins a live sting operation targeting a suspected DPRK IT worker operating under the name Justin Lim. Researcher Nick Bax traces on-chain links connecting the worker to roughly $2.7 million stolen from MetaPlay in 2022, and the interview ends abruptly the moment the candidate is asked to say something negative about Kim Jong-un.

Taylor Monahan, a security researcher, estimates North Korea's elite hackers have stolen over $6 billion in crypto for the regime, with a separate $1.5 billion taken from Bybit in a recent hack. She also claims that every significant crypto company dating back to at least 2020 has had at least one North Korean IT worker on payroll, with many having around ten, and that even established firms like Consensus have accidentally hired DPRK workers as identified by the FBI and DOJ.

In 2024, CoinDesk reported that well-known projects including Cosmos Hub, Phantom, Sushi, and URIN Finance had unknowingly hired North Korean state-sponsored hackers. The specific IT worker investigated in this episode had worked at GameSwap, MetaPlay, and Cook Protocol. Researcher Nick Bax identified on-chain links between the worker's wallets at those employers and other known North Korean transactions, and Bax and Monahan allege the worker stole approximately $2.7 million from MetaPlay in 2022.

The worker used the English name Justin Lim and an alias G. Can Lee Al, claimed a US address in Long Beach, California, and stated he was from Singapore. His internet profiles suggested he was most likely based in Vladivostok, Russia, and his pronunciation of the phrase window shopping was described as a dead ringer for a Korean accent. North Koreans are not permitted to live abroad or travel domestically without a permit, making the Singapore and California claims implausible on their face.

Nick Bax created a fake UMP Labs email account and scheduled a Zoom interview for Friday at 2 p.m. ET, which was 4 a.m. Saturday in Vladivostok. The candidate demonstrated functional technical knowledge during the call, fixing a Graph indexing speed issue on the VELAS network by forking VELAS and optimizing the Graph repository, discussing re-entrancy attack prevention and multi-sig wallet ownership, and pulling up Seaport protocol documentation in real time when he admitted unfamiliarity with it. The interviewers noted the candidate's only visible smile came when the Bybit hack was mentioned. The candidate also claimed he could attend ETH Denver or ETH CC in person after a few months of remote work, which would be inconsistent with his actual location.

The interviewers deliberately saved sensitive questions for the end to extract as much technical information as possible before the candidate was likely to disengage. When asked to say something negative about Kim Jong-un, the candidate immediately dropped from the Zoom call. He later messaged that it was a quite special situation he had never faced with other teams before. The interviewer then stopped responding, after which the account used for the interview appeared to be blocked or reported.

Monahan and the interviewer argue that routinely asking candidates to criticize Kim Jong-un during crypto hiring could serve as a reliable and low-cost screening method. Their reasoning is that North Korean developers will not comply with the request under any circumstances, making it a practical filter. The broader implication they draw is that failing to screen for DPRK workers means crypto companies are directly funding a regime that uses stolen proceeds to finance nuclear weapons programs.

This summary was generated from the episode transcript and can contain mistakes.