A case of a remote developer interview suspected to be linked to North Korea has once again highlighted the hiring verification issues in the cryptocurrency industry. Hacking can begin not only from code vulnerabilities but also from the processes of selecting and granting authority to individuals.
TechFlow reported on the 14th that an interviewee introduced himself as a developer but abruptly ended his response after being asked to criticize Kim Jong-un, the North Korean leader. It is said that this interviewee claimed to like the movie "Frozen." The alias, nationality, and residence of the person mentioned in the article have not been independently verified.
The crux of this case lies more in the method than in the identity of a single applicant. The U.S. Treasury and FBI have warned since 2022 that North Korean IT personnel are attempting to disguise themselves as non-North Korean nationals to gain employment in foreign companies. They aim to pass hiring procedures by using forged documents, stolen identities, fake personal information, remote access tools, and local accomplices.
The FBI stated in a notice in January 2025 that North Korean IT personnel could exploit access to company networks to extract sensitive data and source code or use it for extortion. They recommended repeatedly verifying identities during the interview and onboarding stages and checking whether the same resume phrases or contact details are reused by multiple applicants.
In March 2026, the U.S. Treasury imposed sanctions on six accomplices and two corporations related to North Korean IT fraud. The Treasury noted that this method had generated nearly $800 million (approximately 11.344 trillion KRW) in revenue for North Korea in 2024 alone.
Scott Bessent, the U.S. Treasury Secretary, stated in the materials at that time, "The North Korean regime targets U.S. companies with deceptive methods using overseas IT personnel." Sanctioning authorities view North Korea's remote employment fraud not merely as a hiring issue but as part of foreign currency procurement and cyber operations.
TRM Labs reported that the total amount lost to cryptocurrency hacking in the first half of 2026 was $972 million (approximately 13.783 trillion KRW). Of this, losses attributed to North Korean-linked activities were about $643 million (approximately 9.118 trillion KRW), accounting for 66%. TRM Labs estimated that the amount stolen by North Korea in 2025 was $1.92 billion (approximately 27.226 trillion KRW).
The losses were concentrated in a few major incidents. TRM Labs reported that as of April 2026, approximately $577 million (about 8.182 trillion KRW) was stolen in two attacks on Drift and KelpDAO. The losses from Drift were reported to be $285 million (approximately 4.041 trillion KRW), while KelpDAO's losses were $292 million (approximately 4.141 trillion KRW).
In the same report, TRM Labs stated that since 2017, North Korea's cumulative cryptocurrency theft has exceeded $6 billion (approximately 85.08 trillion KRW). As of April 2026, North Korean-linked hacking accounted for 76% of the cryptocurrency hacking losses recorded for that year up to that point. Depending on the timing and criteria of the tally, the figures for the first half of the year and the cumulative annual proportion were presented differently.
Remote hiring is a particularly sensitive procedure for cryptocurrency companies. Developers can access code repositories, wallet infrastructure, signing procedures, and internal documents. If disguised personnel pass the hiring process, attacks could begin not from technical vulnerabilities but from work authorizations.
This structure is also connected to previous security incidents. Earlier, it was reported that malicious software targeting Web3 professionals had been detected. Attackers were found to have attempted to extract wallet and browser-related information by inducing the installation of fake AI meeting tools.
The issue of North Korea's overseas IT personnel cannot be viewed as a single incident. The multilateral sanctions monitoring team has stated that North Korea's cryptocurrency theft and the profits from overseas IT workers are used for weapons of mass destruction and ballistic missile programs. This is why the hiring process for overseas IT personnel is handled within the framework of money laundering and information theft response systems.
However, responding solely to the "Kim Jong-un criticism question" is not the end of the matter. Mark Karpelès, former CEO of Mt. Gox, stated on X that this method is "actually an effective filter." It can be used as a question that allows for immediate verification of responses in the field.
There are counterarguments as well. Discussions on Hacker News pointed out that such questions could lead to profiling controversies and could be undermined in the long term by scripts or deepfakes. There are concerns that relying on a single question for hiring security could narrow the verification process.
The recommendations from the FBI and the U.S. Treasury emphasize procedural verification over a single question. They state that identity verification, location validation, access IP and device checks, remote access tool detection, and monitoring for unusual signs after hiring should all be applied together. The remote hiring procedures of cryptocurrency companies have entered a phase where they need to reassess internal authorization criteria alongside evaluating development capabilities.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.















Today’s WEEX TradFi Daily Brief covers cooling inflation data, the broader market reaching new highs, and collective strength in the storage sector, helping you quickly capture stock-token trading opportunities.














