Incident case file
Sign in to watchHumanity Protocol — DPRK Phishing & Token Drain
1 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Ledger
Attacker
Funds moved to
Linked
Chronology
1 beatOn June 8–9, 2026, Humanity Protocol suffered a sophisticated phishing attack subsequently attributed to the Lazarus Group (DPRK) by Quantstamp in a report published June 12, 2026. Attackers obtained internal credentials through targeted phishing, then gained control of the ProxyAdmin contract on BSC. This access was used to authorize an unauthorized H token mint (BSC tx: 0x5a8f82f1064a7846ab3eb77bd1d36ec52dfd773c3957ad0aeea28da95fe9c5fb). Simultaneously, H token holdings were drained from multiple Ethereum-side addresses across six primary tainted wallets. Humanity Protocol immediately published a full transparency portal at transparency.humanity.org listing all 71,713 tainted addresses and 419,209 terminal transactions. The team paused affected contracts, coordinated with exchanges, and engaged law enforcement. As of June 12, approximately $36M in H tokens remain unrecovered and dispersed across a multi-hop downstream network.
Sources and coverage
- Articletransparency.humanity.orghttps://transparency.humanity.org
- Articlehacked.slowmist.iohttps://hacked.slowmist.io/
- Articlebscscan.comhttps://bscscan.com/tx/0x5a8f82f1064a7846ab3eb77bd1d36ec52dfd773c3957ad0aeea28da95fe9c5fb
- Articleetherscan.iohttps://etherscan.io/token/0xcf5104d094e3864cfcbda43b82e1cefd26a016eb
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)