Humanity Protocol’s latest security incident appears to be tied to North Korea-linked cyber activity, according to an investigation by Quantstamp. The blockchainHumanity Protocol’s latest security incident appears to be tied to North Korea-linked cyber activity, according to an investigation by Quantstamp. The blockchain

Quantstamp Links Humanity Protocol’s $36M Hack to Suspected N. Korea Group

2026/06/14 20:46
5분 읽기
이 콘텐츠에 대한 의견이나 우려 사항이 있으시면 crypto.news@mexc.com으로 연락주시기 바랍니다
Quantstamp Links Humanity Protocol’s $36m Hack To Suspected N. Korea Group

Humanity Protocol’s latest security incident appears to be tied to North Korea-linked cyber activity, according to an investigation by Quantstamp. The blockchain security firm says a phishing email carrying a malicious attachment compromised an employee device and enabled the theft of $36 million worth of Humanity (H) tokens.

The attack chain, as described by Quantstamp, started with a message that masqueraded as a “token lockup schedule” update reportedly from South Korean exchange Bithumb. Once delivered, the malware granted full remote access to the compromised laptop and ultimately facilitated access to sensitive cryptocurrency wallet materials tied to a project executive.

Key takeaways

  • Quantstamp attributes the Humanity Protocol compromise to a phishing attachment that installed remote-access malware on a staff member’s laptop.
  • The incident led to theft of $36 million in Humanity (H) tokens, tied to unauthorized access of MetaMask credentials and private keys.
  • Quantstamp says the malware was signed with a South Korean Hancom digital certificate, a pattern it associates with DPRK intrusion activity.
  • Recent reporting and research link North Korea-linked threat actors to a large share of crypto theft losses and incidents, emphasizing “precision and scale.”
  • The broader pattern reinforces that operational security—especially around email and endpoints—remains a primary weak point even for decentralized projects.

Phishing to wallet theft: how the compromise worked

Quantstamp reported that a compromised employee’s laptop was the entry point for the attackers. In its incident response, the firm said the phishing email delivered a malicious attachment that was disguised as a token-related schedule update.

Crucially, the malware did more than trigger basic compromise indicators. Quantstamp said it gave the attackers full remote access to the laptop and enabled them to copy Humanity Protocol director Chong Yee Wai’s MetaMask wallet credentials and private keys. That access, according to the firm’s account of events, was leveraged to steal $36 million in Humanity (H) tokens on Monday.

From an investor and user standpoint, the incident highlights a persistent reality in crypto security: even when projects operate on decentralized infrastructure, centralized operational practices—like handling attachments and securing staff devices—can still determine whether funds remain protected.

Why Quantstamp points to DPRK-linked activity

Quantstamp did not rely solely on the phishing technique itself. The firm also analyzed the malware’s signing and behavior, stating that the malicious software was signed with a South Korean Hancom digital certificate.

Quantstamp characterized this detail as “characteristic of DPRK intrusions,” suggesting the attackers used tooling and operational steps commonly observed in past North Korea-linked campaigns. The combination of targeted social engineering (fake Bithumb-related content), endpoint takeover (remote access), and credential harvesting (MetaMask credentials and private keys) forms a cohesive attack narrative consistent with the firm’s attribution.

For readers tracking attribution in cyber incidents, the key takeaway is that this is not a generic accusation: Quantstamp’s conclusion is based on specific technical artifacts found during its incident response.

North Korea-linked theft: large numbers across recent years

The alleged DPRK connection to Humanity Protocol comes amid a broader set of statistics from blockchain security research. In a May report, CertiK linked the same category of actors to about $2 billion of the $3.4 billion lost to crypto exploits in 2025, and said they accounted for 12% of total incidents. CertiK described these losses as reflecting a focus on “precision and scale.”

Looking further back, the report cited an estimate that North Korea-linked actors stole about $6.75 billion in cryptocurrency across 263 documented incidents over the past decade. While such totals naturally depend on methodology and classification criteria, the report’s underlying message is consistent: DPRK-associated operations have repeatedly translated cyber capabilities into high-value thefts.

CertiK further argued that North Korea has “industrialized” crypto theft into a core state revenue mechanism, framing these activities as a meaningful share of the regime’s external income. That characterization matters because it suggests sustained institutional investment rather than isolated criminal hacking.

Denials and the persistence of cyber allegations

North Korea typically does not respond in a sustained way to cybercrime allegations. However, the reporting also referenced a denial carried by Korean Central News Agency coverage on May 3, in which a North Korean Foreign Ministry spokesperson rejected claims about crypto hacks.

In that statement, the spokesperson accused the United States of circulating “incorrect” narratives about a “non-existent ‘cyber threat’” from North Korea. The denial underscores a recurring tension in attribution: while investigators and researchers present technical evidence and pattern-based assessments, state actors continue to reject the framing publicly.

For users and teams building in crypto, the practical implication is to treat attributions as indicators of threat models rather than as proof of political intent. Regardless of who denies what, the operational lesson remains the same—phishing and endpoint compromise can rapidly convert into on-chain losses when wallet access is taken.

Next, readers should watch for updates from Humanity Protocol and Quantstamp on remediation steps and security controls—particularly any changes to how wallets are secured, how staff devices are hardened against social engineering, and what indicators will be shared publicly to prevent similar follow-on attacks.

This article was originally published as Quantstamp Links Humanity Protocol’s $36M Hack to Suspected N. Korea Group on Crypto Breaking News – your trusted source for crypto news, Bitcoin news, and blockchain updates.

시장 기회
CyberConnect 로고
CyberConnect 가격(CYBER)
$0.3566
$0.3566$0.3566
-4.47%
USD
CyberConnect (CYBER) 실시간 가격 차트

World Cup Combo: Aim for 200x

World Cup Combo: Aim for 200xWorld Cup Combo: Aim for 200x

Combine up to 20 World Cup matches in one order

면책 조항: 본 사이트에 재게시된 글들은 공개 플랫폼에서 가져온 것으로 정보 제공 목적으로만 제공됩니다. 이는 반드시 MEXC의 견해를 반영하는 것은 아닙니다. 모든 권리는 원저자에게 있습니다. 제3자의 권리를 침해하는 콘텐츠가 있다고 판단될 경우, crypto.news@mexc.com으로 연락하여 삭제 요청을 해주시기 바랍니다. MEXC는 콘텐츠의 정확성, 완전성 또는 시의적절성에 대해 어떠한 보증도 하지 않으며, 제공된 정보에 기반하여 취해진 어떠한 조치에 대해서도 책임을 지지 않습니다. 본 콘텐츠는 금융, 법률 또는 기타 전문적인 조언을 구성하지 않으며, MEXC의 추천이나 보증으로 간주되어서는 안 됩니다.

Score Your Share of 50K USDT

Score Your Share of 50K USDTScore Your Share of 50K USDT

Complete DEX+ tasks to unlock the Champion Wheel