@konam
A forensic analysis report by Quantstamp has been released regarding the $36 million hack of Humanity Protocol that occurred on June 8th. Rather than a flaw in the smart contract itself, this incident is a textbook example of a breach caused by poor operational security (OpSec) combined with social engineering tactics.
The hack began with a sophisticated phishing attack targeting an executive. The attacker distributed malware via an email impersonating a lock-up schedule from the domestic crypto exchange Bithumb, gaining remote access to an executive's Windows laptop. The critical security failure was that the laptop contained backups of seven private keys, including bridge management permissions and multi-sig signing keys for both the Ethereum and BNB chains. By compromising a single device, the attacker was able to bypass the multi-sig signing threshold and mint a massive amount of tokens unauthorized.
According to Quantstamp's analysis, the patterns of the digital signatures used to execute the malicious files and the attack tools show a high degree of correlation with the methods of North Korean-linked hacking groups (such as Lazarus). On-chain analyst ZachXBT, who initially suspected an inside job due to abnormal price fluctuations just before the lock-up release, confirmed through transaction tracking that this was indeed an external criminal hack.
The Humanity Protocol team has now secured their Ethereum-based contracts and officially retired the compromised BSC-version tokens. While the token price has shown short-term resilience as official compensation and recovery plans take shape, long-term restoration of trust will likely take time, given the fundamental failures exposed in their core key management system.