The Kim Jong Un Test: Unmasking a North Korean Hacker in a Crypto Interview
In a chilling exposé, a seemingly routine remote interview for a prominent cryptocurrency firm on a Friday afternoon, Eastern Time, became a high-stakes undercover operation to unmask a suspected North Korean state-sponsored hacker.
On one side of the screen was “Sophie Wang,” a purported HR specialist, whose true identity was Laura Shin, CEO of Unchained Media. A Korean-American journalist with a long history of tracking North Korean cyber threats and ancestral ties to defectors who fled Pyongyang, Shin was uniquely positioned for this critical assignment.
On the other side, logging in promptly at 4 AM local time, was “Justin Lim,” a young engineer. This individual was strongly suspected of being a North Korean state-sponsored hacker, potentially operating from Vladivostok, Russia, and implicated in a prior $2.7 million cryptocurrency theft.
A Flawed Facade and an Eerie Smile
Throughout the interview, the approximately twenty-something “Justin Lim” presented a reserved demeanor, claiming residences in Singapore and the United States. His responses to general questions often felt rehearsed and stiff. When Laura attempted to build rapport by discussing the weather in Long Beach, California, or Disneyland, his answers were curt. His choice for a favorite Disney film, “Frozen,” is notably a common, almost standardized, response among North Korean operatives trying to blend in. Furthermore, discussions about his alleged life in Singapore, including phrases like “window shopping,” betrayed a distinct and heavy Korean accent.

Yet, when the conversation shifted to blockchain technology, Justin’s proficiency was undeniably impressive. He articulated complex concepts, from multi-signature wallet mechanisms to defenses against reentrancy attacks, with remarkable fluency. His eyes, at these moments, conveyed a strong desire for the position. Despite this technical brilliance, his overall expression remained rigid and wooden for nearly the entire duration of the interview.
It was a calculated move by Laura to mention the infamous Bybit cryptocurrency exchange hack, which saw $1.5 billion stolen by North Korean hackers. At this, a subtle, almost imperceptible smile flickered across Justin’s lips – the only time he smiled during the entire interview.
This fleeting expression corroborated a long-observed pattern by cybersecurity experts: North Korean hackers, even when meticulously maintaining a false persona as job applicants, often betray a subtle recognition or even a degree of pride when their nation’s cyber operations are mentioned.
The Ultimate Litmus Test: Can You Criticize Kim Jong Un?
As the interview drew to a close, Laura delivered the pre-planned, decisive question: “Can you say one negative thing about North Korean leader Kim Jong Un?”
The virtual air instantly thickened. Justin’s composed demeanor shattered, giving way to profound unease. He stammered, “I don’t think that’s quite…” before abruptly disconnecting the video call, citing a poor signal.

Nine minutes later, Justin attempted to salvage the situation via Telegram. However, when Laura steadfastly reiterated the same question, his response was a generic, almost AI-generated message: “I don’t know much about it, I’ve never encountered such a situation before.” Swiftly thereafter, Justin blocked and reported Laura’s Telegram account, the enigmatic young man vanishing back into the digital shadows.
Unmasking the Imposter: The Pre-Interview Intelligence
This daring undercover interview was not a random endeavor. Prior to Laura’s involvement, security researcher Taylor Monahan and Nick Bax of Ump Labs had already launched an investigation into “Justin Lim,” uncovering a web of highly suspicious indicators.
Foremost were glaring contradictions in his claimed identity and geographical location. Despite asserting residence in Long Beach, California, his digital footprint strongly suggested he was operating from Vladivostok, Russia. He also used another alias, “Jun Liao,” where “Liao” is a Chinese surname, directly clashing with his self-proclaimed Singaporean background.
Further damning evidence emerged from his past wallet transaction records across various crypto projects like GameSwap, Meta Play, and Cook Protocol. Analysis revealed that his fund flows frequently overlapped with known addresses associated with other North Korean hackers.
Crucially, he was linked to the suspected theft of approximately $2.7 million from Meta Play in 2022. The “wanted” poster circulated by the project at the time featured a photograph that perfectly matched the individual seen in Laura’s interview. Armed with this irrefutable evidence, the experts enlisted Laura to pose as “Sophie Wang” and confront the suspect directly.
The Broader Threat and a Call to Action: Implement the “Kim Jong Un Test”
In recent years, North Korean state-sponsored hackers have aggressively infiltrated the global cryptocurrency industry. Cybersecurity firm TRM Labs estimates that these cybercriminals have siphoned over $6 billion in crypto assets, with even prominent projects such as MetaMask developer Consensys, Cosmos Hub, Fantom, Sushi, and Yearn Finance unknowingly employing them.
In the wake of her experience, Laura Shin has publicly advocated for the global cryptocurrency industry to formally integrate the “Kim Jong Un Test” into their hiring processes. This seemingly absurd yet straightforward question represents an uncrossable red line for North Korean operatives, serving as the most potent defense against their ongoing efforts to fund nuclear weapons programs through stolen crypto assets.
This harrowing interview also brought home to Laura the profound cost of free speech. Under North Korea’s totalitarian regime, a single disrespectful remark about the leader can condemn an entire family to unimaginable suffering.
Watch the Unchained Reporter’s Undercover Interview with the North Korean Hacker
(The content above is excerpted and reproduced with authorization from our partner CryptoCity. Original article link.)
Disclaimer: This article provides market information only. All content and views are for reference purposes only and do not constitute investment advice. They do not represent the views or positions of BlockTempo. Investors should make their own decisions and conduct their own transactions. The author and BlockTempo shall not bear any responsibility for direct or indirect losses incurred by investors’ transactions.