Key facts
- Quantstamp suspects North Korean hackers are behind the $36 million exploit of Humanity Protocol.
- The hack occurred via a phishing email containing a malicious attachment that compromised an employee's laptop.
- The malware utilized a South Korean Hancom digital certificate, a signature associated with North Korean cyber intrusions.
- Attackers gained access to a Humanity Protocol director's wallet credentials and private keys.
- North Korea-linked actors are responsible for a significant portion of cryptocurrency thefts.
Blockchain security firm Quantstamp has identified suspected North Korean threat actors behind the recent $36 million hack of Humanity Protocol. The breach occurred after a phishing email, disguised as an update from South Korean exchange Bithumb, delivered malware to a compromised employee's laptop.
The malware, signed with a South Korean Hancom digital certificate—a signature Quantstamp associates with North Korean intrusions—provided attackers with remote access. This allowed them to steal the MetaMask wallet credentials and private keys of Humanity Protocol director Chong Yee Wai, leading to the theft of $36 million in H tokens.
This incident adds to a growing list of major cryptocurrency thefts attributed to North Korea. Security firms report that North Korean-linked actors have been responsible for billions in stolen crypto, industrializing theft as a state revenue mechanism. In April alone, these actors were linked to at least $578 million of the $634 million stolen in crypto-related incidents.
