North Korean Hackers Behind $36M Humanity Protocol Heist, Says Quantstamp
Quantstamp, a leading blockchain security firm, has identified what appears to be North Korean involvement in the $36 million Humanity Protocol hack. The smoking gun?

Quantstamp, a leading blockchain security firm, has identified what appears to be North Korean involvement in the $36 million Humanity Protocol hack. The smoking gun? A fraudulent Bithumb email that attackers used to infiltrate the system—a classic social engineering tactic we've seen from Pyongyang-linked threat actors before.
The Attack Vector
Here's how the breach likely went down: hackers spoofed a legitimate Bithumb (a major Korean crypto exchange) email to trick Humanity Protocol employees into compromising their credentials. This isn't sophisticated in a technological sense, but it's devastatingly effective. Once inside, attackers gained access to the protocol's systems and drained $36 million in crypto assets.
Quantstamp's analysis examined the attack's operational patterns, infrastructure, and techniques used—all pointing toward known North Korean hacking groups. The use of a fake Bithumb phishing email is particularly telling, as it demonstrates familiarity with Korean crypto infrastructure and targets, something we've repeatedly documented from DPRK-backed threat actors.
Why This Matters for Your Crypto Portfolio
This hack should trigger alarm bells across the crypto ecosystem. North Korean hacking syndicates have become increasingly sophisticated in their targeting of decentralized finance protocols. Unlike random cybercriminals, state-sponsored actors operate with strategic intent: they're actively funding their regime through crypto theft.
The $36 million loss to Humanity Protocol follows a troubling pattern. We've seen similar attacks on crypto bridges, DEXs, and custodial services over the past two years. The targeting is deliberate—protocols with lower security maturity and less institutional oversight become attractive targets.
What Happened to Humanity Protocol?
Humanity Protocol, which focuses on identity verification and human-centric blockchain applications, became victim to poor operational security. The breach demonstrates that even projects operating in the Web3 space need enterprise-grade security protocols. A single compromised email account became the entry point for a devastating attack.
The incident reinforces a critical lesson: social engineering remains crypto's biggest vulnerability. Hardware wallets, multi-signature schemes, and advanced encryption mean nothing if an employee hands over credentials via a phishing email.
The Broader Threat Landscape
North Korean hacking operations have stolen approximately $100+ million in crypto annually over the past several years, according to various blockchain intelligence firms. These aren't random attacks—they're coordinated, well-resourced, and directly tied to funding state operations under international sanctions.
For traders and portfolio managers, this means increased vigilance around exchange security, bridge protocols, and DeFi platforms. Verify communications directly with projects, enforce stricter authentication protocols, and assume sophisticated actors are actively targeting your holdings.
Alpha Take
The Humanity Protocol hack reinforces that crypto security is only as strong as its weakest link—and that link is usually human. North Korean threat actors have proven they'll target any protocol with inadequate email and access controls. If you're holding assets in lesser-known protocols or bridges, demand transparency about their security infrastructure and incident response procedures. This remains an endemic risk in our market.
Originally reported by
CoinTelegraph
Not financial advice. Crypto investing involves significant risk. Past performance does not guarantee future results. Always do your own research.