Crypto Trust Crisis — The “Kim Jong‑Un Test” Is Exposing Secret North Korean Moles
Amidst yet one more large hack attributed to North Korea-linked operatives, some crypto builders have confessed they’re passing checks throughout interviews to builders to ensure they aren’t North Korean brokers.
The Fool-Proof “Kim Jong‑Un Test” For Crypto Developers
Once once more, the Democratic People’s Republic of Korea (DPRK) is accountable for some motion movie-sounding strikes.
Following the attribution of the April 1st $285 million attack on Drift Protocol to UNC4736, a North Korea–aligned, state‑sponsored hacking group, a number of crypto business actors have taken to the social community X to share their fears and strategies to fight what basically are DPRK secret brokers.
All particulars on the lengthy‑time period social engineering, pretend skilled personas, in‑particular person convention conferences and compromised tooling employed within the assault could be consulted on a yesterday’s article in our sister’s website Bitcoinist.
Unbelievable and hilarious as it might sound, probably the most easy technique a few of these builders have discovered is asking candidates to explicitly insult Kim Jong-Un, North Korea’s regime head, throughout interviews.
Crypto Builders Share Proof
Yesterday, Tanuki42, an unbiased blockchain safety investigator, shared an precise video of a “North Korean IT employee being stopped useless of their tracks upon being required to insult Kim Jong Un”.
In the video, “Taro Aikuchi” wasn’t simply unable to repeat after the interviewer that “Kim Jong-Un is a fats, ugly pig”: he was stunned and visibly nervous.
Here is a video of a North Korean IT employee being stopped useless of their tracks upon being required to insult Kim Jong Un.
It gained’t work perpetually, however proper now it’s genuinely an efficient filter. I’m but to come back throughout one who can say it. https://t.co/8FFVPxNm8X pic.twitter.com/KXI5efMo5L
— tanuki42 (@tanuki42_) April 6, 2026
In a distinct video shared by the safety investigator, “Taro” tells him amusingly that he “is aware of North Korea properly”, however then experiences very handy connection points when is requested to say “Fuck Kim Jong-Un”.
The clip I posted was really spherical 2. Here’s spherical 1 – I inform Taro I’m a North Korea safety researcher, he tells me he “is aware of North Korea properly”. Mysterious connection points once I say “Fuck Kim Jong Un”, which he apologises for on reconnecting.
pic.twitter.com/M89KDDmASW
— tanuki42 (@tanuki42_) April 6, 2026
Later on the thread, Tanuki42 confirmed the candidate modified his Telegram deal with, wiped their chat and blocked him after the interview.
@taroaikuchi simply modified his Telegram deal with @cryptotrading2150->@cryptodegen202 – he’d already wiped our chat and blocked me
pic.twitter.com/EcQedYyGG7
— tanuki42 (@tanuki42_) April 6, 2026
His X account and LinkedIn web page additionally disappeared.
Crypto investor and fund supervisor Jason Choi quoted Tanuki42’s thread to echo the message, claiming that numerous crypto founders have shared with him that this take a look at works.
Several founders in crypto have informed me they ran this take a look at and it genuinely labored https://t.co/DIZHoZDZ0l
— Jason Choi (@mrjasonchoi) April 6, 2026
Crypto founder and RWA‑centered builder Pav replied to Choi saying that he has been utilizing the tactic 2024, after he found out he was interviewing a DPRK agent for an engineering position in 2022.
have been utilizing this since 2024 and works like a attraction https://t.co/nYWYIGxrAA
— Parv (@Parv_EP) April 6, 2026
Simon Wijckmans, one other cybersecurity founder and product chief, additionally replied to Choi sharing a clip from considered one of his personal interviews with a candidate, “William Nation”, who did not say that Kim Jong-Un is a dictator after Wijckmans requested him to do it
Yep pic.twitter.com/Aht731yvRc
— Simon (@SimonWijckmans) April 6, 2026
Some Crypto Builders Remain Sceptic
Despite the overwhelming proof, the wackiness of the story nonetheless finds flabbergasted nonbelievers.
On a distinct thread from a number of days in the past, Paolo Caversaccio, a Switzerland‑primarily based engineer and entrepreneur centered on cryptography, privateness and safety, shared considered one of his makes an attempt to make use of the identical Kim Jong-Un insult tactic to ensure he’s not working with North Korean spies.
going ahead I’ll request from each exterior contributor to my repos a pleasant Kim Jong Un insult; it’s a simple however highly effective technique to forestall DPRK dev code (and a few of them are actually good) to be merged (they may by no means ever get the approval to do that). this man handed it… pic.twitter.com/Ms86or5GiP
— sudo rm -rf –no-preserve-root / (@pcaversaccio) April 4, 2026
He then entered an argument with lengthy‑time Ethereum ecosystem developer and founder Micah Zoltu concerning the precise effectiveness of the approach. But Caversaccio’s argument was compelling: he has been coping with DPRK IT employees for greater than three years.
After dealing for greater than 3 years with DPRK IT employees I can confidently declare this filter could be very sturdy. We will in all probability launch some DPRK interviews publicly at some and can hyperlink it right here, they all the time fail with this query. You in all probability assume my filter is a few random…
— sudo rm -rf –no-preserve-root / (@pcaversaccio) April 5, 2026
Market Implications
The actual deal for merchants proper now isn’t guessing the following meme, however figuring out which groups can defend towards nation‑state attackers.
For some time now, crypto has been getting into a section the place geopolitics, state‑sponsored cyber ops, and HR compliance are as essential as code audits. North Korean infiltration danger is now a structural issue for the business.
Considering this, merchants ought to keep in mind that protocols with weak contributor vetting, opaque multisigs, or advert‑hoc governance current elevated tail‑danger that markets will more and more worth in.
It can also be advisable to search for initiatives that may show stronger operational safety, incident response and KYC for important roles could take pleasure in comparatively stronger valuations and extra sticky TVL.
Cover picture from Perplexity. BTCUSDT chart from Tradingview.

