NewsCryptoLaura Shin Goes Undercover as a Recruiter to Interview Suspected North Korean Crypto Hacker on Unchained

Laura Shin Goes Undercover as a Recruiter to Interview Suspected North Korean Crypto Hacker on Unchained

Author: CryptoBriefing·

Key Takeaways

  • Journalist Laura Shin posed as a recruiter named Sophie Wang to conduct a video interview with a suspected North Korean state-sponsored hacker, aired on the Unchained podcast on August 14, 2026.
  • The interviewee, who called himself Justin Lim, answered technical blockchain screening questions fluently but became evasive and would not offer even mild criticism of Kim Jong Un.
  • Investigators linked Lim to a 2022 theft of $2.7 million from the MetaPlay project, connecting his identity to known North Korean hacking patterns.
  • North Korean operatives are estimated to have stolen over $6 billion from crypto enterprises in recent years, with the proceeds reportedly supporting the country's nuclear and ballistic missile programs.
  • The episode highlights that a project's team vetting now matters as much as its code audits, since a single insider with commit access can drain a treasury from within.
Laura Shin Goes Undercover as a Recruiter to Interview Suspected North Korean Crypto Hacker on Unchained

Crypto journalist Laura Shin — a former Forbes editor and the author of the 2022 book The Cryptopians — set out to see what would happen when a suspected North Korean state-sponsored hacker is put on camera. Posing as a recruiter named Sophie Wang, she arranged a video interview and let the man calling himself Justin Lim talk his way through a blockchain engineering screening. He nailed the technical questions — and stumbled, conspicuously, on the political ones.

The resulting episode of the Unchained podcast, which aired on August 14, 2026, stands as one of the most unusual pieces of crypto journalism in recent memory: part sting operation, part job interview, and part case study in how the Democratic People's Republic of Korea has turned remote developer work into a funding pipeline for its weapons programs.

The interview that wasn't really a job interview

Lim presented himself as a remote developer based in Long Beach, California, and on paper his resume checked a lot of boxes. He demonstrated fluency in smart contract security, discussed indexing protocols such as The Graph across multiple networks, and showed familiarity with projects including Uniswap and Velas.

The cracks appeared when Shin, still in character as Sophie Wang, steered the conversation toward North Korea's leadership. Lim's responses became evasive and vague, and he was conspicuously unwilling to offer even mild criticism of Kim Jong Un. For anyone familiar with how North Korean operatives behave under questioning, that kind of reflexive loyalty is a telltale marker.

A $2.7 million trail

Lim was not just a theoretical threat. Investigators subsequently linked him to a 2022 theft of $2.7 million from the MetaPlay project, connecting his identity to known North Korean hacking patterns.

North Korean operatives are estimated to have stolen over $6 billion from crypto enterprises in recent years. Much of that activity has been attributed by US authorities to units such as the Lazarus Group, which the Treasury Department tied to the roughly $600 million Ronin Bridge theft of 2022 and which the FBI blamed for the approximately $1.5 billion Bybit hack in February 2025. Unlike ransomware gangs or lone-wolf hackers, these operatives function as employees of the state. The stolen funds reportedly flow back to support North Korea's nuclear and ballistic missile programs, making every compromised DeFi protocol or drained project wallet a matter of international security — a linkage the United Nations Panel of Experts has documented for years, and one the FBI, State Department, and Treasury have flagged in joint advisories on North Korean IT workers beginning in 2022 and updated several times since.

The infiltration model is deceptively simple. North Korean operatives create convincing online identities, often claiming to be based in the US, Canada, or Southeast Asia. They build GitHub profiles, contribute to open-source projects, and cultivate the kind of digital footprint that a busy hiring manager might glance at and approve. That playbook is now well documented: Microsoft publicly warned in 2025 that North Korean IT workers were using open-source contributions to build convincing portfolios, and the US Department of Justice has indicted North Korean IT workers it says generated tens of millions of dollars in fraudulent wages. The exposure extends beyond crypto — security training firm KnowBe4 disclosed in 2024 that it had unknowingly hired a North Korean worker using a stolen US identity and an AI-altered profile photo. Once inside a project, they have access to the exact systems they need to exploit.

Why crypto is uniquely vulnerable

The crypto industry's hiring culture was practically designed for this kind of infiltration. Remote-first teams, pseudonymous contributors, a general tolerance for unconventional backgrounds, and the sheer velocity of hiring in bull markets all create openings that state-sponsored actors are trained to exploit.

Implications for projects and investors

The episode underscores a shifting security calculus for the industry. Any project that has hired remote developers without rigorous identity verification now has reason to audit its own team, not just its code. A single compromised insider can drain a treasury, and the $2.7 million MetaPlay loss is modest by the standards of recent crypto exploits.

For investors, the security posture of a project's team matters as much as the quality of its code. A protocol can pass every smart contract audit and still be gutted from the inside if the wrong person has commit access. The reporting points to a broader shift in due diligence around token investments, extending to how projects vet their contributors rather than only how they secure their contracts.