Humanity has released an independent investigation report prepared by Quantstamp, detailing the sequence of events behind the H token security incident. According to the report, the tools and methods used by the attackers showed characteristics associated with North Korean hackers. The compromise began with phishing emails in which the attackers impersonated the Bithumb exchange and communicated with the project side.
Phishing Email Led to Desktop Control and Private Key Theft
The report states that the attackers induced a project director to open a malicious attachment. After the attachment was executed, a remote control trojan was deployed on the director’s device. This gave the attackers full desktop control and allowed them to obtain wallet private keys, turning an off-chain compromise into a series of on-chain attacks.
On Ethereum, the attackers used the stolen keys to upgrade a contract and transfer approximately 141.18 million H tokens. The stolen assets were then sold on Uniswap. The investigation also said that the attack extended to BNB Chain. On the BSC side, the attackers took control of the ProxyAdmin contract and minted additional tokens.
BSC Deployment Remains Under Attacker Control
The stolen assets were sold continuously on Uniswap and PancakeSwap for about eight hours, causing a clear impact on liquidity and market prices. Humanity said the Ethereum-side H token contract has now been frozen and that the mainnet bridge was not affected by the incident.
However, the BSC deployment has been taken over by the attackers and still retains minting authority. Humanity said its team is working with exchanges and security parties on follow-up handling and recovery plans. The team also warned users to be cautious of fake “compensation” or “claim” links, adding that further updates will be released through official channels.

