A video job interview arranged by a journalist posing as a recruiter ended abruptly after a developer using the name Justin Lim was asked to criticize North Korean leader Kim Jong Un, adding a personal test to a screening process already built around alleged links to cryptocurrency theft and North Korea-connected IT-worker networks.
The journalist scheduled the call after security researchers Taylor Monahan and Nick Bax shared a dossier that they said connected the applicant’s online identities, employment history and wallet activity to previous crypto incidents. Bax told the journalist that the individual was linked in the researchers’ materials to the 2022 theft of roughly $2.7 million from MetaPlay.
Lim initially presented himself as a Long Beach, California-based developer from Singapore. During the interview, he spoke English with what the journalist described as a Korean accent, and the person on the call appeared to match an image included in a hack-related notice contained in the dossier.
The encounter offers a close view of a risk that crypto employers have struggled to contain: technically capable remote applicants using false identities to secure access to codebases, internal systems or privileged wallet infrastructure. Monahan said that since 2020, crypto companies of meaningful scale have faced recruitment and infiltration attempts by North Korean IT workers, with some organizations unknowingly hosting as many as 10 such workers simultaneously.
A technical interview before the political test
The interview was designed to resemble an ordinary hiring conversation for a Solidity and blockchain-development role. It began with questions about prior work, software architecture and decentralized-finance protocols, while Bax helped prepare the question list and created a work email account for the recruiter identity.
Lim provided technically detailed answers in several areas. He described dealing with an indexing bottleneck involving The Graph, a protocol used by applications to organize blockchain data, on the Velas network. His proposed solution involved forking Velas to improve compatibility, according to the interview account.
When asked about OpenSea’s Seaport protocol, Lim initially said he did not know it. He then opened the protocol’s documentation during the call and worked through follow-up questions in real time. That response illustrated a challenge for hiring teams: a candidate can demonstrate enough familiarity with industry tools and documentation to appear credible even without immediate knowledge of every protocol.
Lim also said he knew Uniswap v2 and v3 and offered to review documentation for Uniswap v4. In the security section, he recommended multi-signature ownership for smart contracts, a setup requiring several approvals before administrative actions can be executed. He also discussed standard defenses against reentrancy, an attack in which a malicious contract repeatedly calls a target function before the initial transaction is fully completed.
Those answers did not independently establish the candidate’s identity or intent. They did show why technical interviews alone may offer limited protection when a suspicious applicant has genuine programming skills or can quickly navigate public documentation.
Time-zone clues and wallet allegations
The call was set for 2 p.m. U.S. Eastern time, equivalent to 4 a.m. in Vladivostok, Russia. Monahan and Bax said online traces connected to the applicant suggested Vladivostok as a possible location, despite his claimed California residence.
The researchers’ dossier cited a work history involving multiple crypto projects and alleged that wallet flows associated with the candidate connected to addresses linked with North Korea-related activity. Bax said the same individual was tied to the MetaPlay theft, which the researchers valued at approximately $2.7 million.
Public blockchain records can reveal transfers between addresses, but attribution remains more difficult than following the transactions themselves. Researchers typically combine wallet patterns with accounts, infrastructure, social-media profiles, employment records and victim reports to develop an identification case. In this instance, Monahan and Bax said their dossier assembled those different elements before the interview took place.
The journalist also referenced the roughly $1.5 billion theft from Bybit in early 2025 while moving into questions about security practices. The incident was used as a bridge to discuss the risks posed by malicious insiders and compromised access, rather than as a claim about Lim’s involvement.
The question that ended the call
Late in the session, the recruiter raised concerns about North Korea-linked infiltration of crypto companies and asked Lim to say something negative about Kim as a basic background check.
Lim paused, began a response with “I think it’s not…,” then left the Zoom call. Nine minutes later, he sent an email saying his internet connection was unstable and asked to continue the conversation through Discord or Telegram.
The exchange continued on Telegram, where Lim asked about the salary range for the Solidity developer role. When pressed again to criticize Kim, he replied, “I don’t know much,” and later wrote: “It’s quite special question, and never faced with other teams before.”
The journalist later reported that the Telegram account used for the follow-up became unavailable, consistent with the account holder blocking the journalist or the account being reported. Monahan and Bax said the sequence resembled a pattern they associate with North Korea-linked hiring fraud, in which an applicant’s reluctance to criticize the country’s leader can serve as a practical warning sign.
A refusal to answer a political question would not, by itself, prove someone’s nationality, affiliations or involvement in criminal activity. In this case, the researchers treated it as one element alongside the alleged wallet connections, identity inconsistencies, location clues and historical hack allegations contained in their dossier.
A costly threat for crypto employers
North Korea-linked actors have stolen more than $6 billion in cryptocurrency overall, according to TRM Labs. In an August 2026 assessment, TRM Labs said state-linked actors accounted for 76% of digital assets stolen during the year to date, including $577 million taken in two attacks during April.
The alleged use of remote workers gives such operations a route that differs from conventional external hacking. Rather than immediately targeting a protocol or exchange from outside, an operator can seek a legitimate-looking engineering position and attempt to obtain trusted access over time. Access to private repositories, deployment systems, cloud tools, signing processes or administrative credentials can be more valuable than a short-term contract payment.
The interview also points to the limits of relying on a single hiring control. Technical tests can assess competence but not identity. Government-issued identity checks may confirm documents while failing to uncover a person operating through borrowed, fabricated or coerced credentials. Background screening, verification of prior employment, device and access controls, and restrictions on individual authority over wallets or contract upgrades each address different parts of the risk.
For crypto projects handling treasury funds or smart-contract administration, multi-signature arrangements and segmented permissions can reduce the damage a single compromised employee could cause. They do not prevent infiltration, but they can keep one developer from unilaterally moving funds or changing critical code.
The episode involving “Justin Lim” ultimately shows how recruitment has become part of the security perimeter for crypto firms. The strongest warning signs emerged not from one unusual answer, but from the combination of a disputed identity, location inconsistencies, alleged on-chain links and an exit triggered by a basic question about political loyalty.
Worried about infiltration and hacks? Strengthen your defenses with actionable crypto safety standards every serious trader should follow.
Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.
