Quantstamp links the theft of 141 million H tokens from Humanity Protocol to a phishing attack and DPRK hackers, highlighting cross-chain risks and.Quantstamp links the theft of 141 million H tokens from Humanity Protocol to a phishing attack and DPRK hackers, highlighting cross-chain risks and.

Quantstamp Investigation Links Humanity Protocol Hack to DPRK Actors, 141M H Moved

For feedback or concerns regarding this content, please contact us at [email protected]
blockchain3 main

The June 8 theft of 141 million H tokens from Humanity Protocol began not with a code exploit but with a compromised individual device—a classic hallmark of North Korean cyber campaigns. A new report from Quantstamp, obtained by WuBlockchain, lays out how attackers used a phishing attack to gain remote access to a director’s machine, then copied wallet data and private keys. The incident exposes the human endpoint as the weakest link even in well-funded Web3 projects.

Once inside, the attackers executed parallel operations on two separate chains. On Ethereum, they upgraded the H token contract and moved approximately 141.18 million H tokens out of the protocol’s control. On BNB Smart Chain, they took control of a ProxyAdmin contract and used it to mint additional H tokens. The dual-chain maneuver suggests preparation that pre-dated the phishing entry point and points to a group with deep blockchain engineering resources.

A Textbook DPRK Intrusion

Quantstamp flagged the tooling and certificate-signing patterns observed in the attack as characteristic of intrusions linked to the Democratic People’s Republic of Korea (DPRK). State-backed groups like Lazarus have spent years refining techniques that blend phishing, social engineering, and evasive on-chain laundering. The use of weaponized documents or lures to compromise a high-value target, followed by rapid contract reconfiguration, mirrors operations traced to Pyongyang against other DeFi projects.

What sets this incident apart is the attacker’s comfort moving between Ethereum and BNB Smart Chain simultaneously. Many exchange-based monitoring tools still treat chain activity in isolation, creating a blind spot that state actors exploit. The ability to mint fresh tokens on a separate network after draining the main contract increases the total haul while complicating recovery efforts for law enforcement.

Where the Stolen Tokens May Land

Large-scale DPRK crypto thefts historically route funds through decentralized exchanges, cross-chain bridges, and mixers before settling at unregulated offshore exchanges. The 141 million H tokens will likely follow that path, though the Quantstamp report does not detail post-theft movements. Given the volume, any attempt to cash out will face liquidity constraints, but slow, patient washing is a known DPRK tactic. Blockchain intelligence firms and centralized exchanges that actively blacklist flagged addresses may partially blunt the impact, but fungibility on DEXs remains a challenge.

The timing of the attack coincides with an already tense week for crypto security. Multiple protocols have faced bridge exploits, and regulators continue to cite user protection failures as justification for stricter oversight. The Humanity Protocol incident lands as banking lobbyists push to kill a major US crypto bill, a move that could leave consumer safeguards in a legislative limbo for months.

What This Means for Institutional Confidence

Protocols that market themselves as identity- or humanity-focused face a particular reputational hit when a single phishing link triggers a nine-figure loss. The breach does not appear to involve a flaw in the H token’s smart contract logic—the attack surface was the operational security of key personnel. This distinction matters for institutions weighing whether to integrate such protocols. A code audit report may show clean results, yet the entire deployment can still be undone by a weak device security policy.

Open questions remain. Humanity Protocol has not yet disclosed whether any of the stolen tokens were frozen or whether a recovery plan involving law enforcement is underway. Quantstamp’s attribution to DPRK, while detailed on tooling, does not release specific wallet addresses in the public version of the findings. Without on-chain attribution accessible to the community, exchanges and watchdogs may hesitate to act. The next few days will reveal whether the protocol can limit the damage and whether exchanges on both Ethereum and BNB Smart Chain coordinate a unified response. For now, the market is left with 141 million H tokens in the hands of state-backed thieves, a reminder that the most expensive hacks still often start with a single click.

Market Opportunity
Humanity Logo
Humanity Price(H)
$0.26392
$0.26392$0.26392
+2.07%
USD
Humanity (H) Live Price Chart

World Cup Combo: Aim for 200x

World Cup Combo: Aim for 200xWorld Cup Combo: Aim for 200x

Combine up to 20 World Cup matches in one order

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

One Of Frank Sinatra’s Most Famous Albums Is Back In The Spotlight

One Of Frank Sinatra’s Most Famous Albums Is Back In The Spotlight

The post One Of Frank Sinatra’s Most Famous Albums Is Back In The Spotlight appeared on BitcoinEthereumNews.com. Frank Sinatra’s The World We Knew returns to the Jazz Albums and Traditional Jazz Albums charts, showing continued demand for his timeless music. Frank Sinatra performs on his TV special Frank Sinatra: A Man and his Music Bettmann Archive These days on the Billboard charts, Frank Sinatra’s music can always be found on the jazz-specific rankings. While the art he created when he was still working was pop at the time, and later classified as traditional pop, there is no such list for the latter format in America, and so his throwback projects and cuts appear on jazz lists instead. It’s on those charts where Sinatra rebounds this week, and one of his popular projects returns not to one, but two tallies at the same time, helping him increase the total amount of real estate he owns at the moment. Frank Sinatra’s The World We Knew Returns Sinatra’s The World We Knew is a top performer again, if only on the jazz lists. That set rebounds to No. 15 on the Traditional Jazz Albums chart and comes in at No. 20 on the all-encompassing Jazz Albums ranking after not appearing on either roster just last frame. The World We Knew’s All-Time Highs The World We Knew returns close to its all-time peak on both of those rosters. Sinatra’s classic has peaked at No. 11 on the Traditional Jazz Albums chart, just missing out on becoming another top 10 for the crooner. The set climbed all the way to No. 15 on the Jazz Albums tally and has now spent just under two months on the rosters. Frank Sinatra’s Album With Classic Hits Sinatra released The World We Knew in the summer of 1967. The title track, which on the album is actually known as “The World We Knew (Over and…
Share
BitcoinEthereumNews2025/09/18 00:02
Aster is Predicted to Drop to $ 0.477166 By Jun 19, 2026

Aster is Predicted to Drop to $ 0.477166 By Jun 19, 2026

Aster is predicted to decrease -23.22% in the next 5 days and hit a price target of $0.477166 per ASTER. Check out today's Aster price prediction to learn why.
Share
CoinCodex2026/06/15 04:05
WikiLeaks lost 95% of income then adopted BTC in 2011

WikiLeaks lost 95% of income then adopted BTC in 2011

🚨 WikiLeaks lost 95% of its revenue, then turned to $BTC donations. 🌍 Major payment networks had blocked WikiLeaks after Cablegate leaks. ⚡ Satoshi Nakamoto warned
Share
COINTURK EN2026/06/15 04:42

Score Your Share of 50K USDT

Score Your Share of 50K USDTScore Your Share of 50K USDT

Complete DEX+ tasks to unlock the Champion Wheel