Comparison of Thefts
Published 6/27/2026, 3:25:32 PM
Evidence from on-chain investigations and security reports confirms that the Lazarus Group, a North Korea-linked threat actor, is responsible for the combined theft of approximately $324–$326 million from Kelp DAO and Humanity Protocol in early 2026. While the attack vectors differed—targeting bridge infrastructure in one case and using social engineering in the other—investigators have definitively linked the two incidents through the commingling of stolen funds in shared Bitcoin laundering pipelines.
Comparison of Thefts
| Feature | Kelp DAO Exploit | Humanity Protocol Hack |
|---|---|---|
| Date | April 18–21, 2026 | June 2–9, 2026 |
| Amount Stolen | ~$292 Million (116,500 rsETH) | ~$32–$36 Million |
| Primary Method | Infrastructure/RPC Compromise | Phishing & Private Key Theft |
| Target | LayerZero Bridge Nodes | Company Director (Chong Yee Wai) |
| Attribution | Lazarus Group (Confirmed by Chainalysis) | Lazarus Group (Confirmed by Quantstamp) |
| Token Impact | Emergency pause saved $95M | $H token crashed ~89% ($0.67 to $0.05) |
Suspected Group and Methods
The Lazarus Group (specifically the TraderTraitor subgroup) has been identified by Chainalysis, Quantstamp, and TRM Labs as the perpetrator of both attacks.
- Kelp DAO Method: Attackers compromised internal RPC nodes operated by LayerZero Labs and launched a simultaneous DDoS attack against external nodes. This forced a failover to malicious nodes, tricking the Ethereum bridge contract into releasing funds without a corresponding token burn.
- Humanity Protocol Method: A phishing email impersonating the Bithumb exchange was sent to a director, delivering malware that granted remote desktop access. The attackers then copied MetaMask private keys to drain 17+ wallets and mint unauthorized tokens on the BNB Smart Chain.
Investigation and Connection Status
Investigators ZachXBT and Specter identified that 15,403 ETH (~$23.6M) from the Humanity Protocol hack was moved to addresses where it was crossed to the Bitcoin network and mixed directly with proceeds from the Kelp DAO exploit. This consolidation into a single laundering pipeline is considered a signature Lazarus Group technique.
Recovery and Legal Status:
- Frozen Assets: The Arbitrum Security Council successfully froze approximately 30,766 ETH (~$71M) related to the Kelp theft.
- Recovery Initiative: A recovery plan backed by Aave Labs, KelpDAO, and LayerZero has been approved by governance to return these funds.
- Legal Complications: Plaintiffs holding over $877M in U.S. court judgments against North Korea have served restraining notices on the Arbitrum DAO in an attempt to seize the frozen assets as part of their legal claims against the state.
While the attribution to the Lazarus Group is widely accepted by major security firms, the final recovery of the frozen $71M remains complicated by the ongoing legal battle between the protocol's users and the holders of U.S. court judgments.