Evidence has emerged that personnel linked to North Korea are exploiting the remote recruitment processes of crypto companies as a pathway for infiltration, highlighted by an interview-based report. It has been assessed that not only wallet hacking but also interviews, onboarding, equipment delivery, and remote access authorization have become the primary lines of security control.
Crypto Briefing reported on the 18th that Laura Shin, the host of Unchained, interviewed an individual who introduced himself as 'Justin Lim' under the guise of a job seeker named 'Sophie Wang'. This conversation was featured in an episode of the Unchained podcast released on the 14th.
In the report, Lim described himself as a remote developer. He answered questions related to smart contract security, Graph (GRT), Uniswap (UNI), and Velas, while reportedly responding evasively to questions about North Korean leaders.
Crypto Briefing noted that Lim is linked to a $2.7 million theft that occurred at MetaPlay in 2022. However, this connection is based on claims from the report and has not been confirmed by official investigation documents or agency announcements.
The FBI stated in a notice on May 16, 2024, that North Korean IT personnel are using accomplices within the U.S. to conceal their identities and gain access to corporate networks. The FBI identified key methods such as receiving equipment, remote desktop connections, opening financial accounts, creating job site accounts, attending virtual interviews as proxies, and establishing front companies based in the U.S.
The FBI's warning is significant as it views hacking not merely as a code vulnerability issue but as a problem within the hiring process. Companies are advised to repeatedly check location, equipment, and account usage patterns throughout the employment period, not just during pre-employment identity verification.
The U.S. Department of Justice also announced on June 30, 2025, that North Korean personnel obtained remote IT jobs using stolen or fake identities and were employed by over 100 U.S. companies. The same announcement mentioned searches of 29 suspected 'laptop farms' across 16 states, the seizure of 29 financial accounts, and the confiscation of 21 fraudulent websites.
A laptop farm is a physical base where third parties store work equipment sent by hiring companies, assisting foreign personnel in accessing it remotely. The Department of Justice stated that some North Korean IT personnel were employed by blockchain research and development companies and stole virtual assets worth over $900,000.
Chainalysis reported in a 2025 report that North Korean hackers stole $2.02 billion that year, with a cumulative theft amounting to $6.75 billion. Chainalysis explained that North Korean-linked entities embed IT personnel within crypto services to gain access rights or disguise themselves as hiring managers for Web3 and AI companies, targeting credential verification and source code access during technical interview processes.
Security firm Kudelski Security revealed in a study on June 30, 2026, that a North Korean-linked 'contagious interview' campaign is luring developers through LinkedIn, WhatsApp, and Discord. The structure was analyzed to involve executing repositories containing malicious code during fake technical interviews, extracting sensitive information such as execution environment variables and tokens.
Security training company KnowBe4 shared an experience on February 24, 2025, about interviewing a fake North Korean applicant. The applicant reportedly exhibited patterns of stalling by repeating questions and seemed to use search or AI responses. KnowBe4 explained that remote developer hiring companies are repeatedly receiving such applicants.
The crypto industry faces similar issues. Our previous reports highlighted that cases of remote developer interviews suspected to be linked to North Korea revealed problems in the hiring verification processes within the virtual asset industry. At that time, the aliases, nationalities, and residences of individuals mentioned in the article were not independently verified, and the key issue was the methods rather than specific individuals.
There have also been cases where security researchers set up fake DeFi companies to trace back disguised IT personnel identified as part of North Korea's Lazarus group. We previously reported that counterfeit identification, stolen social security numbers, and proxy accounts were used in the hiring process.
This matter targets the hiring structure within the crypto industry rather than the identity of specific interview subjects. To reduce infiltration aimed at internal access rights, hiring interviews, equipment delivery, remote access permissions, and authorization procedures must be managed within the same security framework.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.





























