• bitcoinBitcoin (BTC) $ 65,460.00
  • ethereumEthereum (ETH) $ 1,785.23
  • tetherTether (USDT) $ 0.998951
  • bnbBNB (BNB) $ 605.82
  • xrpXRP (XRP) $ 1.21
  • usd-coinUSDC (USDC) $ 0.999598
  • solanaSolana (SOL) $ 73.27
  • tronTRON (TRX) $ 0.318260
  • staked-etherLido Staked Ether (STETH) $ 2,265.05
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.04
  • hyperliquidHyperliquid (HYPE) $ 73.26
  • dogecoinDogecoin (DOGE) $ 0.086907
  • usdsUSDS (USDS) $ 0.999569
  • leo-tokenLEO Token (LEO) $ 9.68
  • rainRain (RAIN) $ 0.014103
  • wrapped-stethWrapped stETH (WSTETH) $ 2,779.67
  • zcashZcash (ZEC) $ 509.02
  • stellarStellar (XLM) $ 0.222837
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 76,243.00
  • moneroMonero (XMR) $ 348.48
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998762
  • cardanoCardano (ADA) $ 0.171499
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 2,466.93
  • whitebitWhiteBIT Coin (WBT) $ 53.92
  • canton-networkCanton (CC) $ 0.160524
  • chainlinkChainlink (LINK) $ 8.33
  • wrapped-eethWrapped eETH (WEETH) $ 2,465.31
  • usd1-wlfiUSD1 (USD1) $ 0.999762
  • ethena-usdeEthena USDe (USDE) $ 0.999076
  • susdssUSDS (SUSDS) $ 1.08
  • the-open-networkGram (prev. Toncoin) (GRAM) $ 1.66
  • labLAB (LAB) $ 13.90
  • bitcoin-cashBitcoin Cash (BCH) $ 214.72
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 76,366.00
  • daiDai (DAI) $ 0.999643
  • memecoreMemeCore (M) $ 3.11
  • litecoinLitecoin (LTC) $ 45.63
  • wethWETH (WETH) $ 2,268.37
  • hedera-hashgraphHedera (HBAR) $ 0.080938
  • suiSui (SUI) $ 0.801834
  • hashnote-usycCircle USYC (USYC) $ 1.13
  • usdt0USDT0 (USDT0) $ 0.998824
  • nearNEAR Protocol (NEAR) $ 2.29
  • avalanche-2Avalanche (AVAX) $ 6.93
  • shiba-inuShiba Inu (SHIB) $ 0.000005
  • paypal-usdPayPal USD (PYUSD) $ 0.999980
  • global-dollarGlobal Dollar (USDG) $ 1.00
  • crypto-com-chainCronos (CRO) $ 0.059946
  • tether-goldTether Gold (XAUT) $ 4,305.94
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.22
  • bittensorBittensor (TAO) $ 253.51
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • worldcoin-wldWorldcoin (WLD) $ 0.680562
  • uniswapUniswap (UNI) $ 3.70
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.13
  • pax-goldPAX Gold (PAXG) $ 4,317.63
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.060348
  • mantleMantle (MNT) $ 0.564663
  • ondo-financeOndo (ONDO) $ 0.372167
  • aster-2Aster (ASTER) $ 0.667170
  • little-pepe-5Little Pepe (LILPEPE) $ 2.16
  • polkadotPolkadot (DOT) $ 1.03
  • ripple-usdRipple USD (RLUSD) $ 0.999854
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • okbOKB (OKB) $ 75.74
  • htx-daoHTX DAO (HTX) $ 0.000002
  • falcon-financeFalcon USD (USDF) $ 0.995458
  • pi-networkPi Network (PI) $ 0.134429
  • usddUSDD (USDD) $ 0.998916
  • internet-computerInternet Computer (ICP) $ 2.41
  • skySky (SKY) $ 0.057224
  • bfusdBFUSD (BFUSD) $ 0.998567
  • bitget-tokenBitget Token (BGB) $ 1.82
  • pepePepe (PEPE) $ 0.000003
  • morphoMorpho (MORPHO) $ 1.94
  • ethereum-classicEthereum Classic (ETC) $ 7.42
  • aaveAave (AAVE) $ 76.42
  • quant-networkQuant (QNT) $ 71.21
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.00
  • cosmosCosmos Hub (ATOM) $ 1.99
  • superstate-short-duration-us-government-securities-fund-ustbInvesco Short Duration US Government Securities Fund (USTB) $ 11.12
  • united-stablesUnited Stables (U) $ 0.999403
  • kucoin-sharesKuCoin (KCS) $ 7.26
  • blockchain-capitalBlockchain Capital (BCAP) $ 107.07
  • jito-staked-solJito Staked SOL (JITOSOL) $ 124.46
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.22
  • usdtbUSDtb (USDTB) $ 0.999736
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 2,404.69
  • render-tokenRender (RENDER) $ 1.75
  • kaspaKaspa (KAS) $ 0.032417
  • binance-peg-wethBinance-Peg WETH (WETH) $ 2,262.26
  • algorandAlgorand (ALGO) $ 0.097118
  • rocket-pool-ethRocket Pool ETH (RETH) $ 2,631.35
  • janus-henderson-anemoy-treasury-fundJanus Henderson Anemoy Treasury Fund (JTRSY) $ 1.11
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.077378
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999945
  • nexoNEXO (NEXO) $ 0.817878
  • stable-2​​Stable (STABLE) $ 0.034179
  • wbnbWrapped BNB (WBNB) $ 759.61
  • dexeDeXe (DEXE) $ 17.20
  • ignition-fbtcFunction FBTC (FBTC) $ 76,389.00
  • ethenaEthena (ENA) $ 0.086131
  • venice-tokenVenice Token (VVV) $ 16.27
  • gatechain-tokenGate (GT) $ 6.80
  • justJUST (JST) $ 0.082213
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.04
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • bianrensheng币安人生 (BinanceLife) (币安人生) $ 0.668121
  • flare-networksFlare (FLR) $ 0.007730
  • jupiter-exchange-solanaJupiter (JUP) $ 0.196547
  • binance-staked-solBinance Staked SOL (BNSOL) $ 108.24
  • filecoinFilecoin (FIL) $ 0.817779
  • beldexBeldex (BDX) $ 0.079788
  • audieraAudiera (BEAT) $ 2.14
  • xdce-crowd-saleXDC Network (XDC) $ 0.030228
  • ghoGHO (GHO) $ 0.998657
  • injective-protocolInjective (INJ) $ 5.55
  • new-x-ceo-is-backNEW X CEO IS BACK (XFLOKI) $ 0.506041
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999720
  • yldsYLDS (YLDS) $ 0.999959
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 76,461.00
  • aptosAptos (APT) $ 0.665211
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 76,491.00
  • usual-usdUsual USD (USD0) $ 0.998736
  • arbitrumArbitrum (ARB) $ 0.087900
  • spiko-amundi-overnight-swap-fund-eurSpiko Amundi Overnight Swap Fund (EUR) (EURSAFO) $ 1.17
  • clbtcclBTC (CLBTC) $ 76,920.00
  • pump-funPump.fun (PUMP) $ 0.001511
  • midnight-3Midnight (NIGHT) $ 0.031269
  • a7a5A7A5 (A7A5) $ 0.013230
  • usxUSX (USX) $ 0.999159
  • true-usdTrueUSD (TUSD) $ 0.998007
  • dashDash (DASH) $ 37.56
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 2,419.84
  • ousgOndo Short-Term U.S. Government Bond Fund (OUSG) $ 115.59
  • aerodrome-financeAerodrome Finance (AERO) $ 0.494936
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 33.97
  • adi-tokenADI (ADI) $ 3.78
  • tbtctBTC (TBTC) $ 70,942.00
  • humanityHumanity (H) $ 0.261356
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.207774
  • hash-2Provenance Blockchain (HASH) $ 0.008617
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.43
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.007265
  • official-trumpOfficial Trump (TRUMP) $ 1.91
  • lighterLighter (LIT) $ 1.76
  • c8ntinuumc8ntinuum (CTM) $ 0.087592
  • vechainVeChain (VET) $ 0.005172
  • mantle-staked-etherMantle Staked Ether (METH) $ 2,455.82
  • spx6900SPX6900 (SPX) $ 0.469980
  • euro-coinEURC (EURC) $ 1.16
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999983
  • kite-2Kite (KITE) $ 0.183510
  • bonkBonk (BONK) $ 0.000005
  • resolv-wstusrResolv wstUSR (WSTUSR) $ 1.13
  • cocaCOCA (COCA) $ 1.30
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.633761
  • terra-lunaTerra Luna Classic (LUNC) $ 0.000074
  • skyaiSkyAI (SKYAI) $ 0.410887
  • doge-strategyDoge Strategy (DOGESTR) $ 0.288297
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 2,406.26
  • hastra-primePRIME (PRIME) $ 1.04
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 76,200.00
  • apxusdapxUSD (APXUSD) $ 0.939292
  • celestiaCelestia (TIA) $ 0.404477
  • jito-governance-tokenJito (JTO) $ 0.782692
  • curve-dao-tokenCurve DAO (CRV) $ 0.244070
  • wrapped-flareWrapped Flare (WFLR) $ 0.009961
  • sei-networkSei (SEI) $ 0.054775
  • blockstackStacks (STX) $ 0.193842
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 2,266.86
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.997902
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.12
  • the9bitThe9bit (9BIT) $ 0.042367
  • kinesis-goldKinesis Gold (KAU) $ 139.50
  • sun-tokenSun Token (SUN) $ 0.016995
  • ether-fiEther.fi (ETHFI) $ 0.341103
  • pyth-networkPyth Network (PYTH) $ 0.039391
  • binance-peg-xrpBinance-Peg XRP (XRP) $ 1.59
  • unibaseUnibase (UB) $ 0.117855
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 2,443.47
  • usdgoUSDGO (USDGO) $ 0.999782
  • grassGrass (GRASS) $ 0.479516
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 2,421.84
  • gnosisGnosis (GNO) $ 106.19
  • layerzeroLayerZero (ZRO) $ 1.08
  • noonNoon (NOON) $ 0.751949
  • sbtc-2sBTC (SBTC) $ 77,039.00
  • tezosTezos (XTZ) $ 0.249092
  • kinesis-silverKinesis Silver (KAG) $ 70.44
  • monadMonad (MON) $ 0.022196
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 115.56
  • bittorrentBitTorrent (BTT) $ 0.00000027
  • savings-usddSavings USDD (SUSDD) $ 1.03
  • conflux-tokenConflux (CFX) $ 0.050456
  • apenftAINFT (NFT) $ 0.00000027
  • flokiFLOKI (FLOKI) $ 0.000027
  • msolMarinade Staked SOL (MSOL) $ 133.18
  • akash-networkAkash Network (AKT) $ 0.872963
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 2,265.06

Quantstamp Investigation Links H Token Exploit to North Korean Hackers

0 0


Blockchain security firm Quantstamp has released its official investigation into the June 8 security breach of the Humanity (H) token, attributing the attack to hacking groups linked to North Korea (DPRK). The report details a sophisticated phishing campaign that targeted an executive of the project, leading to the theft of approximately 141.18 million H tokens.

How the Attack Unfolded

According to Quantstamp’s findings, the attackers first gained remote access to an executive’s device through a targeted phishing attack. Once inside, they extracted wallet data and private keys, which allowed them to upgrade the H token contract on the Ethereum network. The hackers then transferred a significant portion of the stolen tokens. In a subsequent move, they seized proxy administrator privileges on the $BNB Smart Chain, enabling them to mint an unlimited number of additional H tokens, effectively draining the project’s liquidity.

Evidence Pointing to North Korea

Quantstamp’s analysis identified specific tools and certificate signing patterns in the attack that are consistent with previous operations attributed to North Korean state-sponsored hacking groups, such as the Lazarus Group. These groups are known for their sophisticated social engineering tactics and have been increasingly targeting the cryptocurrency sector to generate revenue for the regime. The security firm noted that the operational security and tooling used in this breach matched the ‘typical characteristics’ of DPRK-linked cyberattacks.

Impact on the H Token Ecosystem

The unauthorized minting and transfer of tokens caused immediate market disruption. The H token’s value experienced significant volatility following the incident, raising concerns among investors about the security of cross-chain bridge contracts and proxy upgrade mechanisms. The incident serves as a stark reminder of the persistent threat posed by advanced persistent threat (APT) groups to decentralized finance (DeFi) projects, particularly those with complex smart contract architectures.

Why This Matters

This attack is not an isolated event. It is part of a broader pattern of North Korean cyber operations targeting the crypto industry, which the United Nations and various cybersecurity firms have documented extensively. For project developers and token holders, this incident underscores the critical importance of robust operational security, hardware wallet usage, and multi-signature governance for smart contract upgrades. For the broader market, it highlights the geopolitical dimensions of crypto security, where state-sponsored actors are using sophisticated attacks to fund illicit activities.

Conclusion

The Quantstamp report provides a clear and technically detailed attribution of the H token hack to North Korean actors. While the immediate financial damage is quantifiable, the long-term impact on trust in token governance models remains to be seen. The incident reinforces the need for the crypto industry to adopt more rigorous security protocols, especially regarding private key management and administrative privileges.

FAQs

Q1: How did the hackers steal the H tokens?
The attackers used a phishing email to gain remote access to an executive’s device, stole private keys, upgraded the token contract, and then transferred approximately 141.18 million tokens. They also compromised proxy admin rights on $BNB Smart Chain to mint additional tokens.

Q2: Why does Quantstamp believe North Korea is responsible?
Quantstamp identified specific tool signatures, certificate signing patterns, and operational methods in the attack that are consistent with previous cyberattacks attributed to North Korean state-sponsored hacking groups like the Lazarus Group.

Q3: What should other crypto projects learn from this incident?
Projects should enforce strict hardware wallet security for executives, implement multi-signature governance for contract upgrades, conduct regular security audits, and train staff to recognize advanced phishing attempts targeting personal devices.



Source link

Leave A Reply

Your email address will not be published.