Blockchain security firm Quantstamp has released its preliminary investigation report on the Humanity Protocol hack. The findings confirm that the incident, which saw the $H token price crash by 89%, was not a random attack but a sophisticated operation with strong ties to North Korean hacking groups.
A Single Phishing Email Triggered the Breach
The attack began on June 5, 2026, at 02:00 UTC, when Humanity Protocol director Chong Yee Wai received an email that appeared to come from the well-known Korean exchange Bithumb. The email discussed a circulating supply lockup schedule and contained a zip file named Bithumb_Circulating_Supply_Lockup_Schedule.zip, hosted on an attacker-controlled domain, celuweb.com.
Chong downloaded the file, filled out what seemed to be a spreadsheet, and even replied, copying colleague Terence Kwok on the email. Kwok had independently received the same phishing mail but with a slightly different tracking link — attackers commonly use separate links to identify which victim's device has been successfully infected.
North Korean Fingerprints in the Malware
The zip file contained hncagent.exe, a first-stage malware loader. Quantstamp noted it was signed using a legitimate South Korean Hancom certificate — a technique consistently linked to DPRK-affiliated hacking groups.
Between June 7 and June 8, the attacker ran a secondary executable eight times to install full remote desktop control over Chong's Windows machine. Tools used included Stas'm RDP Wrapper and two files disguised as Microsoft Defender's Network Inspection Service. A hidden GuestUser profile appeared on the system; neither Sophos nor Windows Defender flagged any suspicious activity.
With full access to Chong's machine, the attacker copied his MetaMask wallet data, Chrome extension encryption keys, and every private key stored on the device.
Token Theft and Market Collapse
On June 8, 2026, the attacker used the stolen keys across both Ethereum and BNB Smart Chain over roughly eight hours. The operation included: using Chong's stolen account key to replace a Hyperlane warp-route proxy and move approximately 141.18 million $H tokens to an attacker-controlled address; using three stolen Safe signer keys to seize a ProxyAdmin contract and mint around 100 million new $H tokens to a fresh wallet. All stolen $H was then dumped on Uniswap and PancakeSwap for ETH and BNB.
After the news, the $H token price collapsed by about 89%, nearly instantly wiping out liquidity providers and remaining holders. As of today, $H is trading at around $0.2058, down 23.4%, with trading volume dropping 26% to $75.3 million.
Recovery Outlook and Ongoing Investigation
Quantstamp's report remains preliminary as of June 11, 2026. Tracing of BSC proceeds and the full downstream wallet network is still active. If the DPRK attribution holds, recovering funds becomes significantly harder — North Korean cybercrime groups have historically moved stolen crypto through mixers and cross-chain bridges within days.
The incident underscores the risk of concentrating critical private keys on a single internet-connected device. One phishing email, three days of silent access, and eight hours of execution drained an entire protocol. A full investigation update is expected as Quantstamp continues on-chain tracing.

