Go to app

Comparison of Exploits

Published 6/27/2026, 6:37:11 AM

The Lazarus Group (North Korean state-sponsored actors) has been linked to the exploits of both Kelp DAO and Humanity Protocol in 2026. While the attribution for Kelp DAO is definitive and supported by infrastructure analysis, the attribution for Humanity Protocol is based on tactical similarities and security firm analysis rather than a formal government indictment.

Comparison of Exploits

FeatureKelp DAO ExploitHumanity Protocol Exploit
DateApril 18, 2026June 8–9, 2026
Estimated Loss$292 Million (116,500 rsETH)$31–$36 Million
Primary VectorRPC Node Poisoning (Infrastructure)Private Key Compromise (Malware)
AttributionLazarus Group (TraderTraitor subunit)Lazarus Group (per Quantstamp)
StatusResolved (Attributed)Unresolved (Tactical Attribution)

Kelp DAO Exploit (April 2026)

The Kelp DAO incident is one of the largest DeFi hacks of 2026, attributed to the TraderTraitor subunit of the Lazarus Group [Source: https://www.galaxy.com/insights/research/lazarus-group-kelp-dao-exploit/].

  • Mechanism: The attackers did not exploit a smart contract bug. Instead, they compromised two internal RPC nodes used by LayerZero’s Decentralized Verifier Network (DVN). By launching a DDoS attack on external nodes, they forced a failover to these poisoned nodes, which then validated a fraudulent "burn" of 116,500 rsETH [Source: https://www.warpcast.com/decrypt/0x45111324].
  • Market Impact: The exploit triggered a massive liquidity crisis on Aave, resulting in approximately $6.2 billion in panic withdrawals as users fled the platform.

Humanity Protocol Exploit (June 2026)

The Humanity Protocol breach occurred roughly two months later and is widely attributed to Lazarus Group based on the "fingerprints" of the attack.

  • Mechanism: The attack was a private key compromise resulting from a developer's laptop being infected with malware via a phishing email [Source: https://www.theblock.co/post/humanity-protocol-hack-details]. This exposure allowed attackers to access backups of seven private encryption keys, compromising the protocol's token admin multisig and bridge proxies.
  • Execution: Attackers drained 187.6 million $H tokens and minted an additional 100 million tokens, extracting roughly 16,320 ETH and 2,700 BNB [Source: https://www.quantstamp.com/blog/humanity-protocol-exploit-analysis].
  • Attribution Status: Security firm Quantstamp linked the $36M loss to North Korean actors, noting that the social engineering tactics and malware delivery methods align with documented Lazarus Group campaigns [Source: https://www.quantstamp.com/blog/humanity-protocol-exploit-analysis]. However, formal forensic evidence linking specific Lazarus-controlled wallets to the Humanity Protocol funds is less public than in the Kelp DAO case.

Summary of Findings

The Lazarus Group's involvement in the Kelp DAO exploit is considered a high-confidence attribution by major research firms like Galaxy and LayerZero Labs [Source: https://www.galaxy.com/insights/research/lazarus-group-kelp-dao-exploit/]. The Humanity Protocol exploit is attributed to them by security researchers (e.g., Quantstamp) due to the specific malware and social engineering patterns used, though it lacks the same level of formal consensus as the Kelp DAO incident. Combined, these attacks were part of a 2026 surge in North Korean cyber-activity that also included a $285 million exploit of Drift Protocol [Source: https://www.theblock.co/post/humanity-protocol-hack-details].