Humanity has released an independent investigation report by Quantstamp detailing the H token security incident. The report states that the attacker used tools and techniques bearing characteristics of North Korean hackers. The incident began with phishing communication that impersonated the Bithumb exchange and later expanded into on-chain attacks across Ethereum and BNB Chain.
Phishing email impersonated Bithumb
According to the report, the attacker communicated through a phishing email disguised as Bithumb and induced a project director to click a malicious attachment. That attachment deployed a remote access trojan on the director’s device. Once installed, the malware gave the attacker full desktop control and access to wallet private keys.
The report links this device compromise to the subsequent on-chain activity. With desktop control and the stolen private keys, the attacker was able to move from an email-based intrusion to contract-level actions involving the H token. Humanity’s disclosure presents the private key theft as a central step in the escalation of the incident.
Ethereum and BNB Chain attack flows
On Ethereum, the attacker used the stolen keys to upgrade the contract and transfer about 141.18 million H tokens. On BSC, the attacker took control of the ProxyAdmin contract and minted additional tokens. The stolen assets were then sold continuously on Uniswap and PancakeSwap for about eight hours, creating a clear impact on liquidity and market price.
Humanity said the H token contract on Ethereum has now been frozen and that the mainnet bridge was not affected. However, the BSC deployment has been taken over by the attacker and still retains minting authority. The team said it is working with exchanges and security parties on follow-up handling and recovery arrangements.
The team also warned users to be cautious of fake “compensation” or “claim” links. Humanity said further updates will be released through official channels. The Quantstamp report outlines the full sequence described by the team: phishing communication, malicious attachment execution, remote desktop access, private key exposure, contract actions on Ethereum and BNB Chain, and the extended sale of stolen assets through Uniswap and PancakeSwap.

