Incident case file
Sign in to watchHumanity Protocol — DPRK Phishing & Token Drain
1 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Attacker: Six primary tainted wallets (source: transparency.humanity.org): 0x1dfe5cf3ed5a0ac82fdd0bfcdac7b6c6323f844a 0x456cb73b35022e4b524e5510807776453d984aef 0x9e995952ef7665b243eeef0693acd7fed7150504 0xaf2a4989922299eb14a29e332dad1012a8aad3a0 0xd1ea823d421e0c829ee11f772af487fd352678ea 0xee4b6b8967aa947ac3aef540ee07ea6099c566f7 Attribution: Lazarus Group / DPRK (Quantstamp report, June 12, 2026)
Timeline: On June 8–9, 2026, Humanity Protocol suffered a sophisticated phishing attack subsequently attributed to the Lazarus Group (DPRK) by Quantstamp in a report published June 12, 2026. Attackers obtained internal credentials through targeted phishing, then gained control of the ProxyAdmin contract on BSC. This access was used to authorize an unauthorized H token mint (BSC tx: 0x5a8f82f1064a7846ab3eb77bd1d36ec52dfd773c3957ad0aeea28da95fe9c5fb). Simultaneously, H token holdings were drained from multiple Ethereum-side addresses across six primary tainted wallets. Humanity Protocol immediately published a full transparency portal at transparency.humanity.org listing all 71,713 tainted addresses and 419,209 terminal transactions. The team paused affected contracts, coordinated with exchanges, and engaged law enforcement. As of June 12, approximately $36M in H tokens remain unrecovered and dispersed across a multi-hop downstream network.
Sources and coverage
- Articletransparency.humanity.orghttps://transparency.humanity.org
- Articlehacked.slowmist.iohttps://hacked.slowmist.io/
- Articlebscscan.comhttps://bscscan.com/tx/0x5a8f82f1064a7846ab3eb77bd1d36ec52dfd773c3957ad0aeea28da95fe9c5fb
- Articleetherscan.iohttps://etherscan.io/token/0xcf5104d094e3864cfcbda43b82e1cefd26a016eb
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)