Quantstamp links June 8 H token breach to North Korean hackers
A single compromised laptop cost Humanity Protocol somewhere between $32 million and $36 million. On June 8, attackers drained roughly 141 million H tokens from the project’s Ethereum bridge in one transaction, then minted additional tokens on BNB Smart Chain for good measure.
Blockchain security firm Quantstamp has linked the breach to hackers with ties to North Korea, adding Humanity Protocol to the growing list of crypto projects allegedly targeted by state-sponsored actors in 2026.
How a developer’s laptop became a $36 million liability
Malware installed on a developer’s laptop compromised private keys that had been backed up on the infected machine. Those keys controlled multiple production systems, giving attackers the ability to move tokens at will.
Approximately 141 million H tokens were siphoned from the Ethereum bridge in a single transaction. On BNB Smart Chain, the hackers minted additional H tokens, converting most of the proceeds into ETH.
Humanity Protocol has emphasized that its smart contract infrastructure wasn’t breached. The vulnerability was purely operational, a failure of key management and device security rather than a flaw in the underlying code.
The market reaction was brutal
The H token’s price collapsed by 80% to 90% in the immediate aftermath of the breach becoming public.
On-chain investigators, including Lookonchain and the pseudonymous blockchain sleuth ZachXBT, published their own analyses of the breach. Their findings confirmed the malware-induced private key compromise as the root cause, though the degree to which state-sponsored actors were definitively involved remained a point of discussion among independent researchers.
Quantstamp’s attribution to North Korean hackers places this incident within a broader pattern. North Korea-linked groups have been responsible for some of the largest crypto heists in history, and 2026 has seen a continuation of that trend with attacks targeting projects like KelpDAO.
Private keys remain crypto’s weakest link
For a project focused specifically on identity and privacy, which is Humanity Protocol’s entire thesis, the irony is difficult to ignore. A protocol designed to secure human identity was undone by basic operational security failures on a single device.
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
BTC, ETH, XRP, ZEC consolidate near highs as breakout levels approach
As chip stocks plummet, "cybersecurity software" surges across the board, CrowdStrike and Palo Alto Networks hit new highs
CrowdStrike surged 13.8% in a single day to a record high, while Palo Alto Networks soared 13%. The software ETF outperformed the semiconductor ETF by more than 10 percentage points in a single day, marking the largest gap in history. Analysts believe that regardless of the pace of AI development, security demand will only continue to rise. Capital is accelerating its rotation from computing hardware to security software, with segments such as identity management and data governance expected to benefit first.
Altman can afford to wait, but Masayoshi Son can't: OpenAI will not go public this year, exposing a $20 billion gap and a credit weakness for SoftBank.
OpenAI has postponed its public listing, putting its largest external shareholder, SoftBank, in a liquidity crisis. This week, SoftBank is conducting a roadshow in New York, seeking to issue $10-20 billion in bonds to repay the $40 billion bridge loan previously borrowed to increase its investment in OpenAI. According to Bloomberg estimates, SoftBank faces a funding gap of at least $20 billion, and the yield on its existing U.S. dollar bonds has already exceeded 8.5%, with pricing approaching junk status.
Meeting postponed, gold price drops rapidly

