VIP Signals · Elixir

Smarter Trading Starts Here

Get structured trading signals, weekly test sessions, and a transparent referral-based VIP access model.

Join Telegram

Phishing Through Bithumb Leads to $36M Theft From Humanity

0 Reading time: 9 min. abelcopy_editor

The theft of Humanity tokens worth $36 million may not have started with an attack on a smart contract, but with a regular email. According to Quantstamp, the attackers used a fake message on behalf of the South Korean exchange Bithumb and sent a malicious file to an employee.

After opening the attachment, the attackers gained remote access to the work laptop. The scenario then became critical for the project: MetaMask wallet data and private keys were copied from the device, allowing the assets to be withdrawn.

Ranking
of the best traders
according to the opinion of the REAL USERS
“Trades Closed From +40% Profit”
“+1,300$/Month in Profit”
“Stable 500$–600$ Withdrawals”

The Token Lockup Schedule Was Used as Bait

The email looked like a service update about the token lockup schedule. For a crypto company, such a topic does not seem suspicious, especially if the message is formatted as if from a well-known exchange.

This is exactly what made the attack dangerous. The attackers did not choose a random lure, but a context that could be understood by project employees and related to their usual work.

According to Quantstamp, the attachment installed malware. It opened full remote access to the laptop, after which the attackers were able to obtain sensitive data from Humanity Protocol director Chong Yi Wai.

The Problem Was Not Contracts, but Keys

In this story, the main vulnerability turned out to be outside the blockchain. If private keys fall into the hands of an attacker, the network treats subsequent transactions as ordinary operations by the wallet owner.

For crypto projects, this is one of the worst-case scenarios. A smart contract audit may not help if access to assets is stored on a device that can be infected through a phishing email.

Therefore, the attack demonstrates a broader risk. Without strict key management, isolation of work devices, and multi-level operation confirmation, even a large project can lose liquid assets through a single compromised laptop.

Traces Pointed to a North Korean Signature

Quantstamp separately noted a technical detail: the malware was signed with a digital certificate from South Korean Hancom. According to the company, this technique is characteristic of attacks previously linked to DPRK groups.

This does not automatically constitute proof in court. But for cybersecurity investigations, recurring signs are important: the method of file delivery, disguise as a familiar company, use of legitimate-looking certificates, and further work with keys.

In Humanity’s case, this combination is telling. The attackers used a token-related topic, a South Korean exchange as cover, and a tool that was supposed to look less suspicious to the security system.

North Korean Groups Back in the Spotlight

If Quantstamp’s version is confirmed, the incident will add to the list of major crypto thefts linked to the DPRK. According to the source, in April, groups associated with this country may have been involved in at least $578 million out of $634 million in crypto incident losses.

CertiK previously estimated the scale even higher. In its May report, the company wrote that similar groups were linked to about $2 billion out of $3.4 billion in crypto exploit losses in 2025. They accounted for about 12% of all incidents.

This ratio is important. It’s not about a large number of small attacks, but about a relatively small share of incidents with huge losses. This points to targeted operations, long preparation, and the selection of targets where a large sum can be obtained quickly.

Crypto Thefts Have Become a Separate System

According to CertiK, over the past decade, structures linked to the DPRK may have stolen about $6.75 billion in cryptocurrency. The reports mention 263 documented incidents.

The company believes that such operations have become one of the regime’s external financing mechanisms. This no longer looks like a set of isolated hacks. Rather, it is a permanent infrastructure working against exchanges, protocols, employees, and service providers.

For the industry, this changes the approach to security. The threat does not come only from code. It can start with an email, an interview, a fake document, a false update, or an infected file.

The Human Factor Remains the Main Entry Point

The Humanity case shows why phishing is so dangerous for the crypto market. Attackers do not always need to look for a complex protocol bug. Sometimes it is enough to convince one person to open a file.

If that person has access to wallets, internal systems, or keys, the damage can be immediate. In traditional business, an infected laptop often means a data leak. In the crypto industry, it can mean the direct loss of tokens, which are almost impossible to recover after being transferred.

Therefore, projects are forced to strengthen not only code audits but also operational security. Separate devices are needed for signing transactions, a ban on storing keys on work laptops, multi-factor procedures, and access restrictions even for executives.

DPRK Denies the Accusations

Pyongyang traditionally denies involvement in cyberattacks. On May 3, a DPRK Foreign Ministry representative, through the state agency KCNA, stated that the accusations from the US are based on false claims about an allegedly non-existent cyber threat.

Such statements do not stop blockchain analysts’ investigations. Security companies continue to track technical signs, fund movements, and recurring attack patterns.

For the market, this practical part is crucial. Political denials do not change the fact that crypto projects are increasingly facing well-prepared operations where phishing is combined with the rapid withdrawal of assets.

Humanity Needs to Restore Trust

For Humanity Protocol, the damage is not limited to $36 million. The project operates in the field of decentralized identity, where security and trust are of particular importance.

After such an attack, users and partners will expect answers to several questions. Where were the keys stored, why could they be accessed from a work device, what accesses did the employee have, and what restrictions will appear after the incident.

The market also needs to understand whether measures will be taken for compensation, monitoring of stolen funds, and strengthening internal procedures. Without this, the hack will remain not only a financial loss but also a reputational blow.

What Next?

Humanity Protocol needs to publish a clear report on the hack and post-incident measures. Changes in key management, email attachment verification, and employee access to wallets are especially important.

For the entire industry, this case became another reminder: the security of a crypto project does not end with a smart contract audit. If keys can be stolen through a laptop, protocol protection remains incomplete.

The main takeaway is simple. The attack on Humanity showed that phishing and employee compromise remain among the most dangerous scenarios for the crypto market. If the North Korean link is confirmed, it will be another example of a targeted operation where a well-prepared group gained access to assets through the human factor.

Read More: AI Audit of Zcash Did Not Reveal New Critical Errors

Top Verified Traders 🔥
Discover Our Best Trader Picks
elixir telegram review 1
falconai private club 2
Comments (0)

News about digital currencies, fintech trends and financial innovations

CoinSpot.io - the largest Runet resource about digital currencies, fintech trends and financial innovations. We talk about technologies, startups and entrepreneurs shaping the face of the financial world. Venture investments, p2p and digital technologies, cryptocurrencies, analytics and reviews - everything you need to know to stay in trend and earn.

Full or partial use of site materials is allowed only with the written permission of the editorial office, and a link to the source is mandatory!

Subscribe to email updates about new articles and important news from Coinspot.io