PodBrowser
Unchained

I Went Undercover to Interview a North Korean Crypto Hacker

Thursday, 13 August 2026 · 3 min read · Listen to the episode ↗

Security researcher Taylor Monahan estimates North Korean elite hackers have stolen over $6 billion in crypto, including $1.5 billion from the Bybit hack alone, and that every major crypto company since at least 2020 has unknowingly employed at least one North Korean IT worker.

Taylor Monahan, a security researcher, estimates North Korea's elite hackers have stolen over $6 billion in crypto for the regime, with the Bybit hack alone accounting for $1.5 billion of that total. Monahan also asserts that every crypto company of significant size dating back to at least 2020 has employed at least one North Korean IT worker, with many having hired around ten. The FBI and DOJ have identified cases including Consensus, and CoinDesk reported in 2024 that Cosmos Hub, Phantom, Sushi, and URIN Finance unknowingly hired North Korean state-sponsored hackers.

Researcher Nick Bax identified the interview subject by tracing alleged transaction links between the subject's crypto wallets at various employers and known North Korean wallets. Bax also alleged the subject stole approximately $2.7 million from MetaPlay in 2022. The subject's internet profiles suggested he was based in Vladivostok, Russia, though he claimed a Long Beach, California address and the name Justin Lim, both considered likely false. North Koreans are not permitted to live abroad or travel domestically without a permit, making apparent foreign residency a marker of elite state privilege.

The journalist conducted the undercover interview using the recruiter persona Sofi Wang, an email account set up by Bax, and a video conferencing platform chosen specifically to avoid requiring a VPN. The subject demonstrated genuine technical competence throughout, including resolving an indexing speed problem on the VELAS network by forking VELAS and optimizing the graph repository, performing real-time analysis of the Seaport protocol and OpenSea documentation, and suggesting multi-sig wallet ownership and re-entrancy attack prevention as smart contract security measures. Bax designed the security questions deliberately, because DPRK workers appeared to be stealing from projects by first learning how those projects secured their funds.

When the Bybit hack was mentioned during the interview, the subject produced a faint smile, described as his only smile during the entire conversation. He also claimed he could travel to ETH Denver or ETH CC for in-person meetings after a few months of remote work, a claim consistent with the operational flexibility North Korean state-sponsored workers sometimes project to appear credible to employers.

The most decisive moment came when the interviewer, deliberately using the word dictatorship to describe North Korea, asked the subject to say something negative about Kim Jong-un. The subject immediately dropped from the Zoom call. Nine minutes later he reappeared via the Sofi Wang account asking about Solidity developer compensation at UMP Labs. When pressed a second time, he responded only that it was a quite special situation and one he had never faced with other teams. According to Liberty in North Korea, even minor criticism of Kim Jong-un can result in entire families being sent to political prison camps for life, which researchers cite as the reason compliance with the question is effectively impossible for DPRK workers.

The Sofi Wang account stopped functioning shortly after the exchange, leaving no screenshots. The interviewer's real-time texts to Bax and Monahan during the call served as the only surviving record of the conversation. The interviewer concluded that asking candidates to criticize Kim Jong-un is a reliable screening method, and argued that widespread adoption of the question by crypto hiring teams could materially reduce North Korea's ability to steal crypto and fund its nuclear weapons program.

This summary was generated from the episode transcript and can contain mistakes.