Skip to main content

Quantstamp Links Humanity Protocol’s $36M Hack to Suspected N. Korea Group



Humanity Protocol’s latest security incident appears to be tied to North Korea-linked cyber activity, according to an investigation by Quantstamp. The blockchain security firm says a phishing email carrying a malicious attachment compromised an employee device and enabled the theft of $36 million worth of Humanity (H) tokens.



The attack chain, as described by Quantstamp, started with a message that masqueraded as a “token lockup schedule” update reportedly from South Korean exchange Bithumb. Once delivered, the malware granted full remote access to the compromised laptop and ultimately facilitated access to sensitive cryptocurrency wallet materials tied to a project executive.



Key takeaways



  • Quantstamp attributes the Humanity Protocol compromise to a phishing attachment that installed remote-access malware on a staff member’s laptop.

  • The incident led to theft of $36 million in Humanity (H) tokens, tied to unauthorized access of MetaMask credentials and private keys.

  • Quantstamp says the malware was signed with a South Korean Hancom digital certificate, a pattern it associates with DPRK intrusion activity.

  • Recent reporting and research link North Korea-linked threat actors to a large share of crypto theft losses and incidents, emphasizing “precision and scale.”

  • The broader pattern reinforces that operational security—especially around email and endpoints—remains a primary weak point even for decentralized projects.



Phishing to wallet theft: how the compromise worked


Quantstamp reported that a compromised employee’s laptop was the entry point for the attackers. In its incident response, the firm said the phishing email delivered a malicious attachment that was disguised as a token-related schedule update.



Crucially, the malware did more than trigger basic compromise indicators. Quantstamp said it gave the attackers full remote access to the laptop and enabled them to copy Humanity Protocol director Chong Yee Wai’s MetaMask wallet credentials and private keys. That access, according to the firm’s account of events, was leveraged to steal $36 million in Humanity (H) tokens on Monday.



From an investor and user standpoint, the incident highlights a persistent reality in crypto security: even when projects operate on decentralized infrastructure, centralized operational practices—like handling attachments and securing staff devices—can still determine whether funds remain protected.



Why Quantstamp points to DPRK-linked activity


Quantstamp did not rely solely on the phishing technique itself. The firm also analyzed the malware’s signing and behavior, stating that the malicious software was signed with a South Korean Hancom digital certificate.



Quantstamp characterized this detail as “characteristic of DPRK intrusions,” suggesting the attackers used tooling and operational steps commonly observed in past North Korea-linked campaigns. The combination of targeted social engineering (fake Bithumb-related content), endpoint takeover (remote access), and credential harvesting (MetaMask credentials and private keys) forms a cohesive attack narrative consistent with the firm’s attribution.



For readers tracking attribution in cyber incidents, the key takeaway is that this is not a generic accusation: Quantstamp’s conclusion is based on specific technical artifacts found during its incident response.



North Korea-linked theft: large numbers across recent years


The alleged DPRK connection to Humanity Protocol comes amid a broader set of statistics from blockchain security research. In a May report, CertiK linked the same category of actors to about $2 billion of the $3.4 billion lost to crypto exploits in 2025, and said they accounted for 12% of total incidents. CertiK described these losses as reflecting a focus on “precision and scale.”



Looking further back, the report cited an estimate that North Korea-linked actors stole about $6.75 billion in cryptocurrency across 263 documented incidents over the past decade. While such totals naturally depend on methodology and classification criteria, the report’s underlying message is consistent: DPRK-associated operations have repeatedly translated cyber capabilities into high-value thefts.



CertiK further argued that North Korea has “industrialized” crypto theft into a core state revenue mechanism, framing these activities as a meaningful share of the regime’s external income. That characterization matters because it suggests sustained institutional investment rather than isolated criminal hacking.



Denials and the persistence of cyber allegations


North Korea typically does not respond in a sustained way to cybercrime allegations. However, the reporting also referenced a denial carried by Korean Central News Agency coverage on May 3, in which a North Korean Foreign Ministry spokesperson rejected claims about crypto hacks.



In that statement, the spokesperson accused the United States of circulating “incorrect” narratives about a “non-existent ‘cyber threat’” from North Korea. The denial underscores a recurring tension in attribution: while investigators and researchers present technical evidence and pattern-based assessments, state actors continue to reject the framing publicly.



For users and teams building in crypto, the practical implication is to treat attributions as indicators of threat models rather than as proof of political intent. Regardless of who denies what, the operational lesson remains the same—phishing and endpoint compromise can rapidly convert into on-chain losses when wallet access is taken.



Next, readers should watch for updates from Humanity Protocol and Quantstamp on remediation steps and security controls—particularly any changes to how wallets are secured, how staff devices are hardened against social engineering, and what indicators will be shared publicly to prevent similar follow-on attacks.



https://www.cryptobreaking.com/quantstamp-links-humanity-protocols-36m/?utm_source=blogger%20&utm_medium=social_auto&utm_campaign=Quantstamp%20Links%20Humanity%20Protocol’s%20$36M%20Hack%20to%20Suspected%20N.%20Korea%20Group%20

Comments

Popular posts from this blog

Mastercard Launches AI Agent Pay System With Ripple and Solana Help

Mastercard has launched Agent Pay for Machines, a payments system built for autonomous software agents. The service allows AI agents to send and receive payments without direct human action. It brings Ripple, Coinbase, and Solana Foundation into Mastercard’s push for automated digital commerce. Ripple Brings XRPL and RLUSD to Mastercard’s Agent Pay System Mastercard introduced Agent Pay for Machines on June 10 as a tool for machine-led payments. The system targets high-volume and low-value transactions across business and consumer use cases. It also supports automated settlement between software agents and connected machines. Ripple will support the system through the XRP Ledger and its RLUSD stablecoin. The company said that settlement will become more important as automated commerce grows. It also sees blockchain rails as useful for fast and rule-based payments. RippleX senior vice president Markus Infanger said XRPL and RLUSD support enterprise-grade agent payments. He said the tool...

Coinbase's x402 launches AI agents app store for payments

Coinbase-backed x402 has unveiled Agentic.market, a dedicated marketplace aimed at increasing the usefulness of AI agents by aggregating thousands of apps and services that agents can access without any API keys. The rollout positions the platform as a central hub for agents to discover, evaluate, and deploy capabilities across a standardized payments layer. Coinbase product lead Nick Prince described Agentic.market in a video posted on X as a storefront for discovering, comparing, and using x402 services. The marketplace is designed to give both humans and their AI agents access to a wide range of tools—from data feeds to consumer apps—without the friction of managing API credentials. A storefront for discovering, comparing, and using x402 services. Thousands of services. Zero API keys. Powered by x402. Prince added that the market offers a web interface for humans to browse and assess services, alongside a programming layer that lets AI agents autonomously search, filter, and integra...

Solana Policy Institute Calls on SEC to Safeguard DeFi Developers from Overly Strict Regulations

US Crypto Policy Innovation: Advocates Push for Clear Regulations and Developer Protections The Solana Policy Institute has urged the U.S. Securities and Exchange Commission (SEC) to differentiate between centralized crypto exchanges and non-custodial decentralized finance (DeFi) software. The nonprofit emphasizes that developers creating and publishing non-custodial code should not be classified as intermediaries, advocating for balanced regulation that fosters innovation without compromising security or legality. Key Takeaways Advocates call for regulatory clarity distinguishing between non-custodial DeFi protocols and centralized exchanges. The Institute argues that applying traditional securities laws to DeFi code risks stifling innovation and pushing activity offshore. Authorities are encouraged to adopt a custody-and-control-based framework to clarify legal liabilities. Legislation proposals aim to shield developers from legal liabilities associated with blockchain code and activ...