Blockchain security firm Quantstamp says a phishing email and a compromised laptop were key steps in the recent Humanity Protocol incident that resulted in theBlockchain security firm Quantstamp says a phishing email and a compromised laptop were key steps in the recent Humanity Protocol incident that resulted in the

Quantstamp Links Humanity Protocol’s $36M Hack to Suspected NK Actors

For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com
Quantstamp Links Humanity Protocol’s $36m Hack To Suspected Nk Actors

Blockchain security firm Quantstamp says a phishing email and a compromised laptop were key steps in the recent Humanity Protocol incident that resulted in the theft of $36 million worth of Humanity (H) tokens. The company’s investigation points to North Korea-linked threat activity, citing technical indicators such as a South Korean digital certificate and malware behavior consistent with DPRK intrusion patterns.

Quantstamp reports that the attackers used a malicious attachment disguised as a token lockup schedule update supposedly connected to Bithumb, one of South Korea’s major cryptocurrency exchanges. After the file was delivered to a staff member, malware installed itself and provided attackers with full remote access—allowing them to reach sensitive wallet material used in the protocol’s operations.

Key takeaways

  • Quantstamp attributes the Humanity Protocol compromise to a phishing attachment that enabled full remote access to a compromised employee laptop.
  • The malware is reported to have been signed with a Hancom digital certificate associated with DPRK-like intrusion patterns.
  • Attackers were able to extract wallet credentials, including MetaMask wallet data and private keys, from a Humanity Protocol director.
  • Security firms continue to link North Korea-linked actors to a substantial share of crypto theft losses across recent years and 2025.
  • Quantstamp’s findings add to a growing pattern where targeted social engineering is used to reach individuals inside crypto projects.

Phishing attachment becomes the access point

In its incident response, Quantstamp said the Humanity Protocol attackers gained leverage through a compromised employee’s laptop. The method, according to the firm, was a phishing email with a malicious attachment that impersonated a token-related update.

The attachment was disguised as what appeared to be a token lockup schedule update from Bithumb. Once opened, the payload installed malware that Quantstamp says granted attackers full remote access to the device.

This matters because it shifts the incident from a purely on-chain exploit narrative to a more human-infrastructure risk narrative: the immediate breach mechanism relied on end-user compromise rather than a direct vulnerability in smart contract code.

Wallet credential theft and the role of remote access

Quantstamp added that the malware’s capabilities extended beyond general control of the laptop. The firm said the attackers used the access to copy Humanity Protocol director Chong Yee Wai’s MetaMask wallet credentials and private keys.

That workflow—stealing wallet material following remote compromise—can enable fast movement of funds. It also highlights why crypto incidents often hinge on endpoint security controls, such as phishing-resistant authentication and strong key-handling procedures, rather than only contract-level defenses.

Technical signals Quantstamp links to DPRK intrusions

Beyond the phishing and remote access, Quantstamp pointed to a technical detail it described as “characteristic of DPRK intrusions.” The firm said the malware was signed with a South Korean Hancom digital certificate.

Quantstamp’s attribution is consistent with how many threat reports are built in cyber investigations: while exact attribution is rarely confirmed publicly, analysts often use combinations of tooling, signing behavior, and operational patterns. In this case, the presence of a specific signing certificate and the observed malware behavior are presented as correlating indicators.

How this fits a broader pattern of North Korea-linked crypto theft

The suspected North Korean link does not appear in isolation. Quantstamp’s report is framed against a backdrop of major crypto thefts that multiple security assessments have attributed to North Korea-linked groups.

Cointelegraph previously reported that North Korea-linked threat actors were tied to at least $578 million of the $634 million stolen in crypto-related incidents in April, referencing an earlier analysis.

Separately, a May report by blockchain security company CertiK said the same actors have been linked to about $2 billion of the $3.4 billion lost to crypto exploits in 2025, while accounting for 12% of total incidents. CertiK characterized the operations as reflecting “precision and scale,” emphasizing that the focus is not only volume but effective execution.

Looking at longer time horizons, a report cited in the article states that over the past decade North Korea-linked actors stole an estimated $6.75 billion in cryptocurrency across 263 documented incidents. CertiK also said North Korea has “industrialized” crypto theft as a core state revenue mechanism, positioning the activity as a meaningful component of external income.

Denial from North Korea, and why attribution stays contentious

North Korea typically does not respond directly to cybercrime allegations. However, the article notes that on May 3, a Foreign Ministry spokesperson rejected claims of involvement in crypto hacks in a statement carried by the Korean Central News Agency.

In that response, the spokesperson argued that the US is spreading “incorrect” narratives about a “non-existent ‘cyber threat’” from North Korea, according to the report referenced in the piece.

For investors and operators, the key takeaway is not to treat attribution claims as courtroom-grade certainty, but to recognize that the patterns behind these incidents—especially endpoint compromise and credential theft—are actionable regardless of attribution debates. Even when state involvement is disputed, the practical defenses remain similar: harden access to personnel systems, reduce exposure to credential-harvesting malware, and ensure recovery and incident response plans assume that social engineering can succeed.

Going forward, the main things readers should watch are follow-up updates from Humanity Protocol and security monitors on whether additional wallets or related infrastructure were targeted, alongside broader tooling guidance from Quantstamp and other analysts on preventing phishing-led endpoint takeovers.

This article was originally published as Quantstamp Links Humanity Protocol’s $36M Hack to Suspected NK Actors on Crypto Breaking News – your trusted source for crypto news, Bitcoin news, and blockchain updates.

World Cup Combo: Aim for 200x

World Cup Combo: Aim for 200xWorld Cup Combo: Aim for 200x

Combine up to 20 World Cup matches in one order

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

US-Iran peace deal announced with ‘permanent’ end to military action

US-Iran peace deal announced with ‘permanent’ end to military action

WASHINGTON, June 15 —  The United States and Iran agreed a peace deal and an “immediate and permanent&r...
Share
Malaymail2026/06/15 08:49
Trump kritik serangan Israel terhadap Beirut ketika rundingan damai Iran

Trump kritik serangan Israel terhadap Beirut ketika rundingan damai Iran

Presiden Amerika Syarikat berkata ia tidak sepatutnya berlaku ketika Washington berada di ambang perjanjian damai dengan Iran.
Share
Free Malaysia Today2026/06/15 07:52
Adoption Leads Traders to Snorter Token

Adoption Leads Traders to Snorter Token

The post Adoption Leads Traders to Snorter Token appeared on BitcoinEthereumNews.com. Largest Bank in Spain Launches Crypto Service: Adoption Leads Traders to Snorter Token Sign Up for Our Newsletter! For updates and exclusive offers enter your email. Leah is a British journalist with a BA in Journalism, Media, and Communications and nearly a decade of content writing experience. Over the last four years, her focus has primarily been on Web3 technologies, driven by her genuine enthusiasm for decentralization and the latest technological advancements. She has contributed to leading crypto and NFT publications – Cointelegraph, Coinbound, Crypto News, NFT Plazas, Bitcolumnist, Techreport, and NFT Lately – which has elevated her to a senior role in crypto journalism. Whether crafting breaking news or in-depth reviews, she strives to engage her readers with the latest insights and information. Her articles often span the hottest cryptos, exchanges, and evolving regulations. As part of her ploy to attract crypto newbies into Web3, she explains even the most complex topics in an easily understandable and engaging way. Further underscoring her dynamic journalism background, she has written for various sectors, including software testing (TEST Magazine), travel (Travel Off Path), and music (Mixmag). When she’s not deep into a crypto rabbit hole, she’s probably island-hopping (with the Galapagos and Hainan being her go-to’s). Or perhaps sketching chalk pencil drawings while listening to the Pixies, her all-time favorite band. This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy Center or Cookie Policy. I Agree Source: https://bitcoinist.com/banco-santander-and-snorter-token-crypto-services/
Share
BitcoinEthereumNews2025/09/17 23:45

Score Your Share of 50K USDT

Score Your Share of 50K USDTScore Your Share of 50K USDT

Complete DEX+ tasks to unlock the Champion Wheel