The hack of the KelpDAO bridge for $292 million in April and the theft of the private key from Humanity Protocol in June had already been linked earlier. In both cases, experts noted signs characteristic of operations related to DPRK, and the main suspect was the hacker group Lazarus.
Now, new on-chain evidence has emerged. According to blockchain analyst Specter, funds stolen in both attacks have started to flow into the same wallets. This method of moving assets usually points to the use of a single money laundering scheme.
How Did Hackers Move Funds Stolen From KelpDAO and Humanity Protocol?
According to Specter, the attacker behind the Humanity Protocol hack transferred 15,403 ETH worth about $23.6 million to a new address on the Ethereum network.
These funds were then moved to the Bitcoin network, where they mixed with assets previously linked to the KelpDAO hack. According to the analyst, this scheme further points to a connection between the two attacks.
Funds stolen in the attacks on Humanity Protocol and KelpDAO ended up in the same wallets, according to ZachXBT and Specter. Source: TRM Labs.
This scheme has long been considered one of the characteristic methods of the Lazarus Group. The group combines funds stolen in different attacks into shared Bitcoin wallets, then runs them through crypto mixers and over-the-counter (OTC) platforms to hide the origin of the assets.
What Links the Two Hacks
According to an investigation by Chainalysis, on April 18, hackers behind the KelpDAO attack compromised internal RPC nodes of LayerZero Labs and simultaneously launched a DDoS attack on external nodes.
This allowed them to trick the Ethereum bridge smart contract and withdraw 116,500 rsETH without the corresponding token burn in the original network.
This attack was linked to the Lazarus Group. Later, the Arbitrum Security Council froze more than 30,000 ETH from the funds that passed through the attackers’ wallets, and an emergency pause by KelpDAO helped prevent the withdrawal of another $95 million.
The Humanity Protocol hack followed a different scheme, but post-incident reports also point to the involvement of actors linked to North Korea.
A report by Quantstamp prepared for Humanity Protocol on June 11 says that the hacker sent a phishing email to company director Chong Yi Wai. The email was disguised as a message from the Korean exchange Bithumb.
Quantstamp called the attack characteristic of DPRK operations.
The malware gave the hacker remote access to Chong‘s computer running Windows. After that, the attacker copied the keys from the MetaMask wallet and used them to issue and sell unauthorized H tokens on the Ethereum and BNB Smart Chain networks. After this, the token price dropped by about 89%.
Read Also: SpaceX Stock Price: SPCX Price, Dynamics, and Tokenized Markets
According to Quantstamp, the attacker’s known addresses hold more than $21 million in ETH.
Legal Complexities May Hinder the Return of Funds
Currently, there are court rulings in the US against North Korea for compensation totaling more than $877 million, which have not yet been enforced. In May, plaintiffs sent a court notice to Arbitrum DAO demanding the seizure of about 30,766 ETH, or about $71 million, previously frozen after the attack.
They argue that since these funds may be linked to North Korea, they can be used to partially repay debts from existing court rulings.
Meanwhile, Arbitrum had already considered a proposal to return the frozen assets as part of a compensation program supported by Aave Labs, KelpDAO, LayerZero, EtherFi and Compound. The plan provided for compensation of losses to affected users.
Later, the court allowed Arbitrum to transfer funds linked to the KelpDAO hack back to Aave.
It is still unknown whether plaintiffs will seek the seizure of funds after the emergence of new evidence of possible North Korean involvement. However, judging by previous cases, the investigation into the Humanity Protocol hack and the potential distribution of returned funds may also become the subject of legal proceedings.
