Quantstamp links fake Bithumb email to Humanity Protocol H token hack

Quantstamp links fake Bithumb email to Humanity Protocol H token hack

Humanity said phishing emails impersonating Bithumb compromised a director’s device, exposing private keys and enabling theft, token minting and sales tied by Quantstamp to possible North Korean threat actors.

ETH
BNB
UNI

Fact Check
All core elements of the claim are corroborated by multiple sources. Quantstamp's attribution of the breach to North Korean tactics is confirmed by cryptobriefing, crypto.news, and Binance Square (BlockchainReporter). The phishing email impersonating Bithumb compromising a director's device is confirmed by theblockbeats flash 351150 (Bithumb update notification → remote access trojan → key theft) and Binance Square (phishing compromise of a director's device). The theft and token sales (~141M H tokens stolen and sold) are confirmed across sources. The price rebound of nearly 40% to $0.3064 is precisely confirmed by theblockbeats flash 351127. The only minor discrepancy is the hack date (June 8 vs June 9), used variably across sources, which does not undermine the claim's substance.
Summary

Quantstamp said a fake Bithumb email used in the Humanity Protocol H token breach points to possible involvement by North Korean threat actors. Humanity said phishing emails impersonating the South Korean exchange compromised a director’s device and exposed wallet private keys, after which about 141.18 million H were moved on Ethereum and additional tokens were minted on BNB Chain. According to Humanity, the attacker later sold about 450 million H for roughly $34 million in ETH and BNB on Uniswap and PancakeSwap over about eight hours. Humanity said the June 9 attack caused losses of more than $31 million, while another report described it as a $36 million hack. The Ethereum H contract has been frozen, but the BNB Chain deployment remains under attacker control. H later rebounded nearly 40% in 24 hours to $0.3064 on June 14 after briefly falling below $0.051, according to HTX data. BlockBeats previously reported that analysts later raised questions about possible insider involvement.

Terms & Concepts
  • private keys: Secret cryptographic credentials that control access to crypto wallets and assets.
  • phishing lure: Deceptive message designed to trick victims into revealing credentials or engaging with malicious content.
  • minted: Created new tokens on-chain under a token contract.