Close Menu
Crypto Breaking News
    Crypto Breaking News
    • News
      • Press Release
      • Featured
      • Events
      • Exchanges
      • Bitcoin
      • Ethereum
      • Solana
      • Ripple
      • Artificial Intelligence (AI)
      • Real World Assets (RWA)
      • Markets & Finance
      • Regulation & Policy
      • Press Releases by PR Newswire
      • News by CoinPedia
      • News by Coincu
      • News by Blockchain Wire
    • Crypto
      • Companies
      • Events
      • Partners
      • Buy Crypto
      • Timers
    • Advertise
      • Submit a Press Release
      • Logos
      • About
      • Services
    • Offers
      • Marketing Services
      • Wallets & Tools
    • Account
    • Video
    • Contact
    Submit PR
    Crypto Breaking News
    Crypto News Exchanges

    Quantstamp Links Humanity Protocol’s $36M Hack to Suspected NK Actors

    14 June 2026
    FacebookTwitterLinkedInCopy Link
    News Feed
    Google NewsRSS
    Quantstamp Links Humanity Protocol’s $36m Hack To Suspected Nk Actors
    Quantstamp Links Humanity Protocol’s $36m Hack To Suspected Nk Actors

    Blockchain security firm Quantstamp says a phishing email and a compromised laptop were key steps in the recent Humanity Protocol incident that resulted in the theft of $36 million worth of Humanity (H) tokens. The company’s investigation points to North Korea-linked threat activity, citing technical indicators such as a South Korean digital certificate and malware behavior consistent with DPRK intrusion patterns.

    Quantstamp reports that the attackers used a malicious attachment disguised as a token lockup schedule update supposedly connected to Bithumb, one of South Korea’s major cryptocurrency exchanges. After the file was delivered to a staff member, malware installed itself and provided attackers with full remote access—allowing them to reach sensitive wallet material used in the protocol’s operations.

    Key takeaways

    • Quantstamp attributes the Humanity Protocol compromise to a phishing attachment that enabled full remote access to a compromised employee laptop.
    • The malware is reported to have been signed with a Hancom digital certificate associated with DPRK-like intrusion patterns.
    • Attackers were able to extract wallet credentials, including MetaMask wallet data and private keys, from a Humanity Protocol director.
    • Security firms continue to link North Korea-linked actors to a substantial share of crypto theft losses across recent years and 2025.
    • Quantstamp’s findings add to a growing pattern where targeted social engineering is used to reach individuals inside crypto projects.

    Phishing attachment becomes the access point

    In its incident response, Quantstamp said the Humanity Protocol attackers gained leverage through a compromised employee’s laptop. The method, according to the firm, was a phishing email with a malicious attachment that impersonated a token-related update.

    The attachment was disguised as what appeared to be a token lockup schedule update from Bithumb. Once opened, the payload installed malware that Quantstamp says granted attackers full remote access to the device.

    This matters because it shifts the incident from a purely on-chain exploit narrative to a more human-infrastructure risk narrative: the immediate breach mechanism relied on end-user compromise rather than a direct vulnerability in smart contract code.

    Wallet credential theft and the role of remote access

    Quantstamp added that the malware’s capabilities extended beyond general control of the laptop. The firm said the attackers used the access to copy Humanity Protocol director Chong Yee Wai’s MetaMask wallet credentials and private keys.

    That workflow—stealing wallet material following remote compromise—can enable fast movement of funds. It also highlights why crypto incidents often hinge on endpoint security controls, such as phishing-resistant authentication and strong key-handling procedures, rather than only contract-level defenses.

    Technical signals Quantstamp links to DPRK intrusions

    Beyond the phishing and remote access, Quantstamp pointed to a technical detail it described as “characteristic of DPRK intrusions.” The firm said the malware was signed with a South Korean Hancom digital certificate.

    Quantstamp’s attribution is consistent with how many threat reports are built in cyber investigations: while exact attribution is rarely confirmed publicly, analysts often use combinations of tooling, signing behavior, and operational patterns. In this case, the presence of a specific signing certificate and the observed malware behavior are presented as correlating indicators.

    How this fits a broader pattern of North Korea-linked crypto theft

    The suspected North Korean link does not appear in isolation. Quantstamp’s report is framed against a backdrop of major crypto thefts that multiple security assessments have attributed to North Korea-linked groups.

    Cointelegraph previously reported that North Korea-linked threat actors were tied to at least $578 million of the $634 million stolen in crypto-related incidents in April, referencing an earlier analysis.

    Separately, a May report by blockchain security company CertiK said the same actors have been linked to about $2 billion of the $3.4 billion lost to crypto exploits in 2025, while accounting for 12% of total incidents. CertiK characterized the operations as reflecting “precision and scale,” emphasizing that the focus is not only volume but effective execution.

    Looking at longer time horizons, a report cited in the article states that over the past decade North Korea-linked actors stole an estimated $6.75 billion in cryptocurrency across 263 documented incidents. CertiK also said North Korea has “industrialized” crypto theft as a core state revenue mechanism, positioning the activity as a meaningful component of external income.

    Denial from North Korea, and why attribution stays contentious

    North Korea typically does not respond directly to cybercrime allegations. However, the article notes that on May 3, a Foreign Ministry spokesperson rejected claims of involvement in crypto hacks in a statement carried by the Korean Central News Agency.

    In that response, the spokesperson argued that the US is spreading “incorrect” narratives about a “non-existent ‘cyber threat’” from North Korea, according to the report referenced in the piece.

    For investors and operators, the key takeaway is not to treat attribution claims as courtroom-grade certainty, but to recognize that the patterns behind these incidents—especially endpoint compromise and credential theft—are actionable regardless of attribution debates. Even when state involvement is disputed, the practical defenses remain similar: harden access to personnel systems, reduce exposure to credential-harvesting malware, and ensure recovery and incident response plans assume that social engineering can succeed.

    Going forward, the main things readers should watch are follow-up updates from Humanity Protocol and security monitors on whether additional wallets or related infrastructure were targeted, alongside broader tooling guidance from Quantstamp and other analysts on preventing phishing-led endpoint takeovers.

    Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure

    Crypto Breaking News
    • Website
    • Facebook
    • X (Twitter)
    • Pinterest
    • Instagram
    • Tumblr
    • LinkedIn

    The Crypto Breaking News editorial team curates the latest news, updates, and insights from the global cryptocurrency and blockchain industry.

    Related Posts

    Moonpay Vault Lets Chatgpt And Claude Users Approve Crypto Payments

    MoonPay Vault lets ChatGPT and Claude users approve crypto payments

    52 minutes ago
    Ark Analyst: Crypto Enters Longest Consolidation Cycle Yet

    ARK Analyst: Crypto Enters Longest Consolidation Cycle Yet

    2 hours ago
    Us Prosecutors Seek Changes To Clarity As Voting Window Tightens: Report

    US Prosecutors Seek Changes to CLARITY as Voting Window Tightens: Report

    3 hours ago
    Bitcoin Stalls As Split Fomc Meets Amid Iran-War Oil Shock (+8%)

    Bitcoin stalls as split FOMC meets amid Iran-war oil shock (+8%)

    4 hours ago
    Binance Adds Adgm-Regulated Gold And Silver Options For Traders

    Binance Adds ADGM-Regulated Gold and Silver Options for Traders

    5 hours ago
    Binance Rolls Out Regulated Gold And Silver Options Via Adgm

    Binance Rolls Out Regulated Gold and Silver Options via ADGM

    6 hours ago

    Search Crypto News

    Featured Crypto News

    Win 3 Free Ga Passes To Bitcoin Asia 2026 In Hong Kong With Cryptobreaking

    Win 3 Free GA Passes to Bitcoin Asia 2026 in Hong Kong With CryptoBreaking

    24 July 2026

    Latest News

    • MoonPay Vault lets ChatGPT and Claude users approve crypto payments
    • ARK Analyst: Crypto Enters Longest Consolidation Cycle Yet
    • US Prosecutors Seek Changes to CLARITY as Voting Window Tightens: Report
    • Bitcoin stalls as split FOMC meets amid Iran-war oil shock (+8%)
    • Binance Adds ADGM-Regulated Gold and Silver Options for Traders
    • Binance Rolls Out Regulated Gold and Silver Options via ADGM
    • AI Debt Insurance Costs Hit Record as Asian Semiconductor Slide Deepens
    • As Crypto Matures, Market Fundamentals Matter More Than 100x Bets
    • Bitcoin Asia 2026 Brings Full Enterprise and Business Development Track to Hong Kong
    • BNY Plans to Put Transfer Agency Records Onchain in Blockchain Push

    Join 20,000+ Crypto Followers

    • Facebook2.4K
    • Twitter4.5K
    • Instagram7.2K
    • LinkedIn4.3K
    • Telegram55
    • Threads1000
    Crypto.com
    AVATRADE

    About Crypto Breaking News

    About Crypto Breaking News

    Crypto Breaking News is a fast-growing digital media platform focused on the latest developments in cryptocurrency, blockchain, and Web3 technologies. Our goal is to provide fast, reliable, and insightful content that helps our readers stay ahead in the ever-evolving digital asset space.

    Web3 Digital L.L.C-FZ
    License Number: 2527596
    📞 +971 50 449 2025
    ✉️ info@cryptobreaking.com
    📍Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, United Arab Emirates

    FacebookX (Twitter)InstagramPinterestYouTubeTumblrBlueskyLinkedInRedditTikTokTelegramThreadsRSS

    Links

    • Crypto News
    • Submit a Press Release
    • Advertise
    • Contact Us
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • Stocks Breaking News

    advertising

    eToro Crypto 300x300
    © 2026 CryptoBreaking.com | All rights reserved | Powered by Web3 Digital & Osom One

    Type above and press Enter to search. Press Esc to cancel.

    Change Location
    Find awesome listings near you!