New Evidence Links Two Major Cryptocurrency Hacks
Blockchain investigators found that funds stolen from two major crypto hacks ended up in the same wallets.
Fresh blockchain evidence suggests that the recent attacks on KelpDAO and Humanity Protocol are more closely connected than previously believed. Investigators have discovered that funds stolen in both incidents were transferred to the same cryptocurrency wallets, strengthening suspicions that the attacks were carried out by the same threat actor.
In April, hackers stole approximately $292 million worth of cryptocurrency from KelpDAO. Two months later, Humanity Protocol suffered another major breach, losing around $23.6 million in Ethereum. From the beginning, cybersecurity researchers suspected that both attacks could be linked to the Lazarus Group, the North Korean state-backed hacking organization.
Those suspicions have now gained further support. Blockchain analyst Specter reported that the assets stolen in both hacks eventually converged in the same wallets. This pattern suggests that the attackers used a shared money laundering infrastructure, a tactic that has long been associated with the Lazarus Group.
According to the investigation, the hackers moved 15,403 ETH, worth roughly $23.6 million, stolen from Humanity Protocol onto the Bitcoin network. There, the funds were combined with cryptocurrency previously taken from KelpDAO, following a laundering strategy that investigators have repeatedly linked to Lazarus operations.
A separate investigation by Chainalysis found that the KelpDAO exploit was made possible by a vulnerability in an Ethereum bridge, allowing attackers to steal 116,500 rsETH. However, part of the stolen assets was successfully frozen, and the project's rapid response prevented an additional $95 million in potential losses.
The Humanity Protocol attack followed a different method. According to a report by Quantstamp, hackers gained control of the project's corporate wallet and used it to mint and sell unauthorized H tokens. As a result, the token's price plunged by approximately 89%, while wallets controlled by the attackers still hold more than $21 million worth of ETH.
The case could also have legal implications. Authorities in the United States are currently pursuing proceedings related to the seizure of some of the frozen assets, as creditors of North Korea seek to use the funds to satisfy outstanding court judgments.
Together, these incidents demonstrate that blockchain investigations can continue to uncover valuable evidence long after an attack has taken place. By tracing on-chain transactions, investigators have identified new links between what initially appeared to be two separate cyberattacks, adding further weight to the theory that the same hacking group was behind both operations.
We use cookies and similar technologies to improve your experience, analyze traffic, and deliver personalized content and ads.
By clicking “Accept all”, you agree to the storing of cookies on your device.
You can choose to reject non-essential cookies or manage your preferences at any time.
For more information, please refer to our privacy policy.
Buttons:
Accept all
Reject non-essential
Manage settings