
Humanity Protocol Realigns Focus on Operational Security Post $36M Hack
Vexoda Newsroom
Following a significant hack that resulted in the theft of $36 million worth of tokens, Humanity Protocol is prioritizing operational security. The incident highlights an increase in attacks targeting
Humanity Protocol recently announced it will refocus its cybersecurity efforts on operational security after suffering a major hack that resulted in the theft of $36 million worth of tokens, according to Terence Kwok, the company's founder. The exploit was traced back to compromised production keys stored on an employee’s laptop.
The incident occurred during last year's mainnet launch when several critical keys were inadvertently backed up onto this machine, including admin hot wallet and multisig owner keys across both chains. This breach underscores that operational security is as crucial as smart-contract security in protecting cryptocurrency assets.
Blockchain security firm Quantstamp identified the exploit as being linked to North Korea-linked threat actors who used a phishing email disguised as an update from South Korean exchange Bithumb, which installed malware providing remote access to the machine. This highlights how social engineering can be more effective than technical vulnerabilities for attackers.
The hack comes at a time when operational failures and social engineering schemes are driving an increase in cryptocurrency exploits. According to blockchain security company CertiK, phishing was responsible for 508 million dollars in losses during Q1 of this year, while wallet compromises contributed $807 million in the second quarter.
These incidents also reveal a broader trend where North Korean actors continue to pose significant threats within the crypto industry. Despite overall decreases in hack-related losses, CertiK warns that these numbers can be misleading due to large-scale hacks like Bybit's in early 2025.
As Humanity Protocol rebuilds its security protocols with operational safety as a top priority, traders and investors should remain vigilant about potential social engineering threats. The industry is increasingly recognizing the importance of human factors in cybersecurity measures.
Source: Cointelegraph. Summarized and rewritten by the Vexoda Newsroom. This is market news, not financial advice.