Investigation Summary

2026-06-11 Humanity

https://www.humanity.org/hincidentupdate

Thumbnail for Investigation Summary

A phishing email impersonating Bithumb led Humanity Protocol director Chong Yee Wai to download a malicious attachment from an attacker-controlled host, after which a Hancom-signed loader and remote-access tooling gave the attacker control of his Windows machine. Quantstamp assessed the loader-signing pattern as characteristic of DPRK intrusions, and the attacker copied MetaMask and private-key material from the host. On 8 June 2026, the stolen keys were used to alter Ethereum/BSC contract control, mint and move roughly 241 million $H, drain about 150 operational wallets, and sell tokens on Uniswap and PancakeSwap, causing an approximately 89% market-price drop. Known attacker-controlled proceeds exceeded USD 21 million in ETH, with BNB-side tracing still in progress.

Indicators of Compromise

Type Value First Seen Last Seen
WALLET 0xd73cd1117646625ffe23a55860035… 2026-06-11 2026-06-11
WALLET 0xd1ea823d421e0c829ee11f772af48… 2026-06-11 2026-06-11
WALLET 0xe943dbD064Ec283bDc95c39FaEE61… 2026-06-11 2026-06-11
URL https://go.skimresources.com/?i… 2026-06-11 2026-06-11
URL https://go.skimresources.com/?i… 2026-06-11 2026-06-11
DOMAIN celuweb.com 2026-06-11 2026-06-11
WALLET 0x6Aa22CB8420E94Fc2119364b4c788… 2026-06-09 2026-06-09

Related Reports

« Back