The Humanity Protocol hack has now been formally linked to North Korean hackers, and the forensic trail investigators pieced together explains something that looked confusing back in June: how attackers cleared two separate multisig wallets, on two separate blockchains, without ever touching a smart contract bug. H, the project's token, is trading around $0.07 as of Wednesday — after a volatile round trip that saw it crash roughly 90% on the day of the theft, spike more than 200% in a relief rally weeks later, sink to a fresh all-time low near $0.018 by late June, and then drop another 31% in an August 17 sell-off before settling near current levels — this isn't a price story. It's a story about how a state-sponsored hacking crew beat crypto's favorite security feature using nothing more exotic than a fake email.
How a single phishing email led to a $36M theft
The attack didn't start with code. It started with an email impersonating Bithumb, one of South Korea's largest exchanges, carrying an attachment disguised as an update to Humanity Protocol's token-lockup schedule. A developer at the project opened it. The attachment installed malware that gave the attackers full remote access to that one laptop — effectively root control of the machine.
That's the part any employee at any company could fall for. What made it catastrophic is what happened to be sitting on that laptop: an accidental backup, dating back to the project's June 2025 mainnet launch, of seven private keys. Three belonged to the Ethereum-side Safe multisig wallet, three to the BNB Chain-side Safe multisig, and one was a hot wallet key. The attackers also lifted the MetaMask credentials of a company director, Chong Yee Wai. One compromised device, seven keys, two chains.
Why "3-of-6 multisig" wasn't as safe as it sounds
Multisig wallets are supposed to be crypto's answer to a single point of failure: no one person can move funds alone, because a threshold of independent signers has to approve first. Humanity Protocol's setup required 3 of 6 signatures on Ethereum and 3 of 5 on BNB Chain — thresholds that look reasonably conservative on paper.
The problem is that a threshold only protects you if the signing keys are actually distributed across independent people, devices and locations. If enough of those key shares happen to live on the same laptop, the multisig collapses into something closer to a single-signature wallet the moment that laptop is compromised. That's what happened here, and it's the detail that both Halborn's technical writeup and Quantstamp's forensic report converge on: this wasn't a contract flaw an audit would have caught. It was a custody failure a code review would never see.
With enough keys to independently clear both signing thresholds, the attackers moved roughly 6 million H tokens out of the hot wallet, drained another 141 million by pushing a malicious upgrade through the Ethereum bridge contract, and minted 300 million more directly on BNB Chain — a combined 447 million H tokens converted into roughly $36 million in ETH and BNB — then dumped the proceeds on Uniswap and PancakeSwap.
Is this part of a bigger North Korean pattern?
Quantstamp's later analysis is what turned this from "a crypto team got hacked" into something more specific: the malware and a signature pattern tied to an abused Hancom code-signing certificate matched tradecraft the firm describes as characteristic of North Korean state-linked intrusions. That's a meaningful reframe. A random malware infection is bad luck. A targeted, multi-stage social-engineering operation using a stolen certificate is espionage-grade planning aimed specifically at crypto custody.
And it isn't an isolated case. CertiK's 2025 data puts North Korea behind roughly $2 billion of the $3.4 billion stolen from crypto that year — around 12% of all incidents by count, but a wildly outsized share of the dollar value, because these operations specifically hunt for concentrated pools of funds like project treasuries and multisig wallets rather than scattering across retail wallets. Humanity Protocol fits that pattern precisely: not the biggest DeFi hack of the year, but a clean, repeatable template — phish an insider, find where the keys actually live, drain fast, launder through DEXs.
What happens to your H tokens now?
There's no recovery of the stolen funds on the table, and the team isn't claiming there will be. Humanity Protocol's response has been to deploy a new, audited ERC-20 contract and airdrop replacement tokens 1:1 to holders based on a June 8 pre-hack snapshot, alongside a Compensation Fund meant to cover edge cases the snapshot doesn't. That claim process is live now at the project's official claim portal. Because of the North Korea attribution, claimants filing Compensation Fund claims — for example, post-snapshot buyers or holders with LP exposure — should expect KYC/AML identity verification to be part of it, a direct consequence of the funds' likely path toward sanctioned laundering infrastructure.
The honest read for holders is that the airdrop makes people whole on paper for tokens they held at the snapshot, but it doesn't undo the theft itself, and anyone exposed through liquidity pools, the bridge, or purchases made after the snapshot may not be fully covered. More broadly, the actual lesson here — that a multisig is only as strong as the weakest device holding its keys — applies well beyond one project. Plenty of smaller teams likely have the same accidental single point of failure sitting on a laptop somewhere, with no reason yet to think it's been fixed.
The practical takeaway for the sector is that security reviews built around smart-contract audits are answering the wrong question if the real risk is a phishing email landing in the right inbox. That's a harder problem to solve with a bug bounty, and it's exactly the gap North Korean operators keep finding.
Sources
- https://cointelegraph.com/news/humanity-protocol-hack-linked-north-korean-actors-quantstamp
- https://www.coindesk.com/tech/2026/06/09/humanity-s-usd36-million-exploit-happened-because-a-multisig-wallet-lived-on-one-laptop
- https://crypto.news/humanity-founder-reveals-employee-laptop-breach-behind-36m-exploit/
- https://www.halborn.com/blog/post/explained-the-humanity-protocol-hack-june-2026
- https://cointelegraph.com/news/humanity-protocol-operational-security-36m-hack
- https://crypto.news/humanity-protocol-sets-new-h-airdrop-after-36m-exploit/
- https://claim.humanity.org/
- https://coinmarketcap.com/currencies/humanity-protocol/