On-Chain Evidence Ties KelpDAO and Humanity Protocol Stolen Funds to a Common Bitcoin Exit Route

On-Chain Evidence Ties KelpDAO and Humanity Protocol Stolen Funds to a Common Bitcoin Exit Route

N
News Editor 01
2026-07-24 06:05:17
On-chain investigators say funds from the KelpDAO and Humanity Protocol exploits converged on the Bitcoin network, with both trails pointing to the same financial outflow point.

On-chain investigators have linked the KelpDAO and Humanity Protocol exploits through a shared fund flow on Bitcoin. Specter said the attacker behind the Humanity Protocol breach moved 15,403 ETH, worth about $23.6 million, into a relatively new Ethereum address before bridging the assets to the Bitcoin network, where they merged with proceeds previously traced to the KelpDAO hack.

Analysis cited from ZachXBT and Specter said the two incidents, though separate in execution, appear to end at the same financial cash-out point. Researchers said the pattern of gathering proceeds from multiple attacks into common Bitcoin wallets and then routing them through mixers and over-the-counter channels is frequently seen in operations associated with the Lazarus Group.

KelpDAO exploit centered on the bridge release process

Chainalysis said its investigation into the April 18 KelpDAO attack found that the perpetrators compromised internal RPC nodes run by LayerZero Labs while launching a DDoS attack against external nodes. That combination allowed them to mislead the Ethereum bridge contract and release 116,500 rsETH on the destination chain without a matching burn event on the source chain.

The attack was attributed to the Lazarus Group. The Arbitrum Security Council later froze more than 30,000 ETH tied to downstream hacker activity. KelpDAO’s emergency shutdown mechanism also blocked an additional $95 million from being withdrawn from the platform.

Humanity Protocol breach traced to phishing and wallet key theft

The Humanity Protocol incident used a different method, but post-breach findings again pointed to actors linked to North Korea. In an incident report dated June 11, Quantstamp said the attacker tricked company executive Chong Yee Wai with a malicious email disguised as a message from South Korean crypto exchange Bithumb.

Quantstamp said the malware installed during the attack gave the intruder remote desktop access. The attacker then copied MetaMask wallet keys from Chong’s Windows device and used them to mint and sell unauthorized $H tokens on Ethereum and BNB Smart Chain. After the incident, the token price fell nearly 89%. Quantstamp reported that known attacker addresses collected more than $21 million in ETH from the exploit.

Recovery efforts now face court and governance hurdles

Legal action has complicated the recovery path. The report said there are more than $877 million in outstanding judgments in U.S. courts against North Korea. In May, plaintiffs sought a preliminary injunction based on an April 30 court order to seize about 30,766 ETH, valued at roughly $71 million, that had been frozen by Arbitrum DAO.

The plaintiffs argued that assets linked to North Korea should be subject to confiscation. At the same time, Arbitrum started a governance process to move the frozen KelpDAO funds into a recovery initiative backed by Aave Labs, KelpDAO, LayerZero, EtherFi, and Compound. A court later approved the Arbitrum vote, clearing the path for the KelpDAO funds to be transferred to Aave. The report added that it is still unclear whether losses and recovery claims tied to the Humanity Protocol incident will face similar legal proceedings.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
300

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.