• bitcoinBitcoin (BTC) $ 64,160.00
  • ethereumEthereum (ETH) $ 1,745.11
  • tetherTether (USDT) $ 0.999170
  • bnbBNB (BNB) $ 590.17
  • usd-coinUSDC (USDC) $ 0.999755
  • xrpXRP (XRP) $ 1.18
  • solanaSolana (SOL) $ 71.81
  • tronTRON (TRX) $ 0.320907
  • staked-etherLido Staked Ether (STETH) $ 2,265.05
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.02
  • hyperliquidHyperliquid (HYPE) $ 71.85
  • dogecoinDogecoin (DOGE) $ 0.085025
  • usdsUSDS (USDS) $ 0.999703
  • rainRain (RAIN) $ 0.014550
  • leo-tokenLEO Token (LEO) $ 9.63
  • wrapped-stethWrapped stETH (WSTETH) $ 2,779.67
  • stellarStellar (XLM) $ 0.241759
  • zcashZcash (ZEC) $ 469.93
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 76,243.00
  • canton-networkCanton (CC) $ 0.164397
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998762
  • whitebitWhiteBIT Coin (WBT) $ 53.06
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 2,466.93
  • moneroMonero (XMR) $ 333.27
  • cardanoCardano (ADA) $ 0.167071
  • chainlinkChainlink (LINK) $ 8.04
  • wrapped-eethWrapped eETH (WEETH) $ 2,465.31
  • labLAB (LAB) $ 15.63
  • usd1-wlfiUSD1 (USD1) $ 1.00
  • ethena-usdeEthena USDe (USDE) $ 0.998979
  • susdssUSDS (SUSDS) $ 1.08
  • the-open-networkGram (prev. Toncoin) (GRAM) $ 1.66
  • bitcoin-cashBitcoin Cash (BCH) $ 209.48
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 76,366.00
  • daiDai (DAI) $ 0.999592
  • memecoreMemeCore (M) $ 2.99
  • hedera-hashgraphHedera (HBAR) $ 0.080783
  • wethWETH (WETH) $ 2,268.37
  • litecoinLitecoin (LTC) $ 44.28
  • hashnote-usycCircle USYC (USYC) $ 1.13
  • suiSui (SUI) $ 0.752061
  • usdt0USDT0 (USDT0) $ 0.998824
  • nearNEAR Protocol (NEAR) $ 2.23
  • avalanche-2Avalanche (AVAX) $ 6.66
  • shiba-inuShiba Inu (SHIB) $ 0.000005
  • global-dollarGlobal Dollar (USDG) $ 1.00
  • paypal-usdPayPal USD (PYUSD) $ 0.999867
  • crypto-com-chainCronos (CRO) $ 0.059130
  • tether-goldTether Gold (XAUT) $ 4,251.82
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.22
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • bittensorBittensor (TAO) $ 240.27
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.14
  • worldcoin-wldWorldcoin (WLD) $ 0.625731
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.061497
  • uniswapUniswap (UNI) $ 3.13
  • pax-goldPAX Gold (PAXG) $ 4,261.28
  • aster-2Aster (ASTER) $ 0.676091
  • ondo-financeOndo (ONDO) $ 0.367608
  • mantleMantle (MNT) $ 0.540232
  • little-pepe-5Little Pepe (LILPEPE) $ 2.16
  • polkadotPolkadot (DOT) $ 0.983068
  • ripple-usdRipple USD (RLUSD) $ 0.999880
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • htx-daoHTX DAO (HTX) $ 0.000002
  • okbOKB (OKB) $ 73.19
  • falcon-financeFalcon USD (USDF) $ 0.994552
  • pi-networkPi Network (PI) $ 0.131511
  • usddUSDD (USDD) $ 0.999363
  • skySky (SKY) $ 0.057476
  • bfusdBFUSD (BFUSD) $ 0.998861
  • morphoMorpho (MORPHO) $ 1.99
  • internet-computerInternet Computer (ICP) $ 2.30
  • bitget-tokenBitget Token (BGB) $ 1.80
  • pepePepe (PEPE) $ 0.000003
  • aaveAave (AAVE) $ 74.68
  • ethereum-classicEthereum Classic (ETC) $ 7.16
  • quant-networkQuant (QNT) $ 70.48
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.00
  • united-stablesUnited Stables (U) $ 0.999887
  • superstate-short-duration-us-government-securities-fund-ustbInvesco Short Duration US Government Securities Fund (USTB) $ 11.12
  • blockchain-capitalBlockchain Capital (BCAP) $ 107.07
  • kucoin-sharesKuCoin (KCS) $ 7.22
  • cosmosCosmos Hub (ATOM) $ 1.86
  • jito-staked-solJito Staked SOL (JITOSOL) $ 124.46
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.21
  • usdtbUSDtb (USDTB) $ 1.00
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 2,404.69
  • algorandAlgorand (ALGO) $ 0.101130
  • render-tokenRender (RENDER) $ 1.71
  • binance-peg-wethBinance-Peg WETH (WETH) $ 2,262.26
  • ethenaEthena (ENA) $ 0.095001
  • rocket-pool-ethRocket Pool ETH (RETH) $ 2,631.35
  • janus-henderson-anemoy-treasury-fundJanus Henderson Anemoy Treasury Fund (JTRSY) $ 1.11
  • kaspaKaspa (KAS) $ 0.031149
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999945
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.076408
  • nexoNEXO (NEXO) $ 0.808883
  • wbnbWrapped BNB (WBNB) $ 759.61
  • stable-2​​Stable (STABLE) $ 0.033832
  • ignition-fbtcFunction FBTC (FBTC) $ 76,389.00
  • venice-tokenVenice Token (VVV) $ 15.33
  • gatechain-tokenGate (GT) $ 6.74
  • bianrensheng币安人生 (BinanceLife) (币安人生) $ 0.717338
  • justJUST (JST) $ 0.082503
  • dexeDeXe (DEXE) $ 14.67
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.04
  • flare-networksFlare (FLR) $ 0.007466
  • beldexBeldex (BDX) $ 0.082058
  • binance-staked-solBinance Staked SOL (BNSOL) $ 108.24
  • filecoinFilecoin (FIL) $ 0.797194
  • jupiter-exchange-solanaJupiter (JUP) $ 0.188580
  • xdce-crowd-saleXDC Network (XDC) $ 0.030474
  • ghoGHO (GHO) $ 0.998714
  • yldsYLDS (YLDS) $ 0.999736
  • usual-usdUsual USD (USD0) $ 0.998985
  • new-x-ceo-is-backNEW X CEO IS BACK (XFLOKI) $ 0.506041
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999720
  • spiko-amundi-overnight-swap-fund-eurSpiko Amundi Overnight Swap Fund (EUR) (EURSAFO) $ 1.16
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 76,461.00
  • aptosAptos (APT) $ 0.656976
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 76,491.00
  • arbitrumArbitrum (ARB) $ 0.085540
  • hash-2Provenance Blockchain (HASH) $ 0.009964
  • injective-protocolInjective (INJ) $ 5.28
  • clbtcclBTC (CLBTC) $ 76,920.00
  • pump-funPump.fun (PUMP) $ 0.001504
  • a7a5A7A5 (A7A5) $ 0.013015
  • usxUSX (USX) $ 0.999407
  • midnight-3Midnight (NIGHT) $ 0.030351
  • true-usdTrueUSD (TUSD) $ 0.998112
  • adi-tokenADI (ADI) $ 3.92
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 2,419.84
  • ousgOndo Short-Term U.S. Government Bond Fund (OUSG) $ 115.60
  • dashDash (DASH) $ 36.06
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 33.97
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.200327
  • tbtctBTC (TBTC) $ 70,942.00
  • audieraAudiera (BEAT) $ 1.57
  • official-trumpOfficial Trump (TRUMP) $ 1.89
  • aerodrome-financeAerodrome Finance (AERO) $ 0.464807
  • humanityHumanity (H) $ 0.250179
  • kite-2Kite (KITE) $ 0.188204
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.35
  • euro-coinEURC (EURC) $ 1.15
  • c8ntinuumc8ntinuum (CTM) $ 0.087592
  • vechainVeChain (VET) $ 0.004995
  • mantle-staked-etherMantle Staked Ether (METH) $ 2,455.82
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.006807
  • lighterLighter (LIT) $ 1.66
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999983
  • bonkBonk (BONK) $ 0.000005
  • terra-lunaTerra Luna Classic (LUNC) $ 0.000072
  • resolv-wstusrResolv wstUSR (WSTUSR) $ 1.13
  • cocaCOCA (COCA) $ 1.30
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.603234
  • hastra-primePRIME (PRIME) $ 1.04
  • skyaiSkyAI (SKYAI) $ 0.390484
  • doge-strategyDoge Strategy (DOGESTR) $ 0.288297
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 2,406.26
  • spx6900SPX6900 (SPX) $ 0.411630
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 76,200.00
  • sei-networkSei (SEI) $ 0.054762
  • celestiaCelestia (TIA) $ 0.392598
  • apxusdapxUSD (APXUSD) $ 0.870437
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.997798
  • wrapped-flareWrapped Flare (WFLR) $ 0.009961
  • blockstackStacks (STX) $ 0.186135
  • jito-governance-tokenJito (JTO) $ 0.706950
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 2,266.86
  • curve-dao-tokenCurve DAO (CRV) $ 0.224112
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.12
  • ether-fiEther.fi (ETHFI) $ 0.362778
  • sun-tokenSun Token (SUN) $ 0.017213
  • kinesis-goldKinesis Gold (KAU) $ 136.66
  • pyth-networkPyth Network (PYTH) $ 0.038199
  • the9bitThe9bit (9BIT) $ 0.036286
  • binance-peg-xrpBinance-Peg XRP (XRP) $ 1.59
  • unibaseUnibase (UB) $ 0.116196
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 2,443.47
  • usdgoUSDGO (USDGO) $ 0.999782
  • gnosisGnosis (GNO) $ 105.02
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 2,421.84
  • plasmaPlasma (XPL) $ 0.109895
  • bittorrentBitTorrent (BTT) $ 0.00000027
  • noonNoon (NOON) $ 0.751949
  • sbtc-2sBTC (SBTC) $ 77,039.00
  • apenftAINFT (NFT) $ 0.00000027
  • grassGrass (GRASS) $ 0.427715
  • tezosTezos (XTZ) $ 0.239801
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 115.56
  • doublezeroDoubleZero (2Z) $ 0.074820
  • savings-usddSavings USDD (SUSDD) $ 1.03
  • kinesis-silverKinesis Silver (KAG) $ 68.54
  • monadMonad (MON) $ 0.021537
  • layerzeroLayerZero (ZRO) $ 1.01
  • msolMarinade Staked SOL (MSOL) $ 133.18
  • pendlePendle (PENDLE) $ 1.48
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 2,265.06

Humanity Protocol says phishing attack led to permanent BSC compromise

0 0


Humanity Protocol says a targeted phishing attack against one of its directors led to the theft of private keys used in the June 8 $H token compromise. It resulted in the permanent compromise of the project’s $BNB Chain deployment.

In a new incident update published June 12, the team shared findings from an independent investigation conducted by Quantstamp.

It concluded that the attacker used stolen administrative credentials to upgrade contracts. They then moved tokens across Ethereum and minted new $H on $BNB Smart Chain.

The attacker later sold the tokens across Uniswap and PancakeSwap over roughly eight hours. The move severely damaged liquidity and triggered a sharp collapse in the token’s market price.

Attack reportedly began with fake Bithumb email

According to Humanity Protocol, the compromise started with a phishing email impersonating crypto exchange Bithumb.

The targeted director had reportedly been communicating with Bithumb before receiving what appeared to be a legitimate update containing a malicious attachment.

The team said opening the file installed remote-access malware that gave the attacker full remote-desktop control over the machine. Also, this was done without triggering endpoint security protections.

With that access, the attacker allegedly copied wallet data and private keys stored on the device before executing the on-chain attack.

Quantstamp said the malware tooling and certificate-signing patterns observed during the investigation were “characteristic of DPRK-linked intrusions.” However, the report stopped short of making a definitive attribution.

Attackers upgraded contracts and minted new $H

Humanity Protocol said the attacker used stolen keys belonging to one of its directors to upgrade a contract on Ethereum and move roughly 141.18 million $H tokens.

On $BNB Chain, the attacker reportedly took control of a ProxyAdmin contract, allowing them to mint additional $H tokens directly.

The newly minted tokens were then sold into liquidity pools across Ethereum and BSC, intensifying market losses for holders and liquidity providers.

The team stressed that the incident did not stem from a vulnerability in the underlying smart contracts themselves.

Instead, the compromise resulted from unauthorized administrative access obtained through the phishing attack.

Ethereum frozen while BSC deployment abandoned

The incident also created a split between Humanity Protocol’s Ethereum and BSC deployments.

According to the update, the Ethereum token contract was successfully frozen using a separate clean multisig wallet that the attacker never controlled.

The project also said the canonical Humanity Mainnet bridge remains unaffected.

However, the $BNB Chain deployment has now been deemed permanently compromised. This is because the attacker still retains administrative control and can continue minting new tokens.

“This must be abandoned,” the team wrote regarding the BSC deployment.

The incident highlights growing concerns across the crypto industry around governance key management, operational security, and social-engineering attacks.


Final Summary

  • Humanity Protocol said a phishing attack impersonating Bithumb led to the theft of director keys used in the June 8 $H exploit.
  • The project froze its Ethereum deployment but said its $BNB Chain deployment must now be abandoned because the attacker still controls mint permissions.



Source link

Leave A Reply

Your email address will not be published.