Humanity has published an independent investigation report prepared by Quantstamp on the H token security incident. According to the report, the attackers used tools and techniques bearing characteristics associated with North Korean hackers. They communicated through phishing emails while impersonating the Bithumb exchange, then induced a project director to click a malicious attachment.
Phishing email led to remote control and private key exposure
After the malicious attachment was opened, the attackers deployed a remote-control Trojan on the director’s device. The report says this gave them full desktop control and access to wallet private keys. That access became the entry point for the subsequent on-chain attacks carried out across Ethereum and BNB Chain.
On the Ethereum side, the attackers used the stolen key to upgrade the contract and transfer about 141.18 million H tokens. On the BSC side, they took control of the ProxyAdmin contract and minted additional tokens. The stolen assets were then sold continuously on Uniswap and PancakeSwap for about eight hours, creating a clear impact on liquidity and market prices.
Ethereum contract frozen while BSC deployment remains compromised
Humanity said the H token contract on Ethereum has now been frozen and that the mainnet bridge was not affected. However, the BSC deployment has been taken over by the attackers and still retains minting authority. The team is working with exchanges and security parties on the next steps for handling the incident and preparing a recovery plan.
The project also warned users to be cautious of fake “compensation” or “claim” links, adding that further updates will be released through official channels. Earlier, Humanity Protocol suffered an attack after the private key of a Humanity Foundation member was leaked, resulting in more than $31 million in stolen funds.

