Go to app

Primary Attacker Addresses

Published 6/20/2026, 12:22:48 PM

The Humanity Protocol exploit, which occurred on June 8–9, 2026, resulted in a loss of approximately $32–$36 million. The funds were primarily moved through a central attacker-controlled wallet before being converted into ETH and BNB via decentralized exchanges (DEXs). Forensic analysis has linked the movement patterns to North Korean (DPRK) state-sponsored actors.

Primary Attacker Addresses

The following address has been identified by on-chain analysts as the primary hub for consolidating and moving the stolen assets:

  • Primary Attacker Wallet (Ethereum & BSC): 0x456Cb73b35022E4B524e5510807776453d984AeF

Fund Movement and Destinations

The attacker utilized a compromised developer laptop to gain control of multisig keys, allowing them to upgrade the protocol's bridge implementation to a malicious version. This enabled unauthorized withdrawals and minting across both Ethereum and BNB Smart Chain (BSC).

ActionChainAsset/AmountDestination & Status
Bridge DrainEthereum~141.2M H TokensSwapped for 18,510 ETH (~$30.8M); currently being "layered" through new wallets.
Malicious MintBSC~200M H TokensSwapped for 1,548 BNB (~$924k) via DEXs.
Residual HoldingsBSC~111M H TokensStill held in attacker-controlled wallets as of the last trace.

Current Status of Stolen Funds

  • ETH Consolidation: The bulk of the stolen value (~$30.8M) was converted to ETH. Analysts note that these funds have begun "layering"—a process of moving assets through multiple new, smaller wallets to obscure the trail before potentially heading to mixers or off-ramps.
  • DEX Dumping: The attacker immediately dumped a significant portion of the H tokens on DEXs, which caused the token price to crash by over 85% during the exploit window.
  • Recovery Efforts: Humanity Protocol has deployed a new token contract (0xE76c5b78f93909d34404E9eb4C1f19e7582a5dE1) for a 1:1 migration. All funds held in the attacker's addresses at the time of the snapshot (Ethereum block 25,274,179) have been blacklisted and excluded from the recovery.

Real-time tracking of these funds is being managed by security firms, with the "Humanity Protocol Exploiter" entity tag active on platforms like Arkham Intelligence for monitoring movements toward centralized exchanges or privacy protocols.

Next Steps:

  • Would you like to monitor the primary attacker wallet for any new outgoing transactions or movements to mixers?
  • I can perform a deep dive into the new H token contract's security and current liquidity levels.