- Crypto investigator ZachXBT detected a merge in the flow of the funds linked to the Kelp DAO and Humanity Protocol exploits.
- The trend rules out possible insider involvement and strengthens previous findings pointing to foreign actors.
The past few months have seen two major exploits that cost Kelp DAO (WRSETH) and Humanity Protocol (H) millions of dollars. A prominent crypto investigator later revealed that the bad actors in the two incidents are likely connected, suggesting they may be operating from a single group.
Convergence of Kelp DAO and Humanity Protocol Stolen Funds
According to a report attributed to ZachXBT, a popular crypto sleuth, the movements of the stolen funds from the Kelp DAO and Humanity Protocol attacks have merged at a single wallet address just past midnight on Saturday (UTC). Their flow overlapped under transaction hash 5d31655a905b1b39ce1a477268b5084cc821157371860b792e60a3fa4aa24931.

ZachXBT stated that analysts initially raised concerns about insider supply control and active market-making tactics via centralized exchanges (CEXs) following the H token attack. The exploit occurring shortly before investor unlocks reinforced their theory.
Fast-forward to the new discovery, the investigator pointed out that the money trail now rules out possible insider involvement. The latest facts support LayerZero (ZRO) Labs’ initial findings linking the North Korean hacking outfit Lazarus Group to Kelp’s pseudonymous attacker, TraderTraitor.
The Kelp DAO Incident
The Kelp DAO attack in April marked the biggest crypto heist in 2026 by far. The incident drained around $292 million to $294 million in a very short window.
The event immediately wiped roughly $400 million from Kelp’s total value locked (TVL) in merely hours. Its contagion effect also affected Aave (AAVE). The bad debt in its system crashed its TVL by $7 billion during the period.
Reports later claimed that Kelp DAO froze $71 million worth of the exploit’s proceeds. However, the remaining were already out of its reach.
The blame game revolved from security lapses on Kelp DAO’s part to the failure of LayerZero’s omnichain messaging protocol.
The Humanity Protocol Heist
Humanity Protocol’s case in early June led to a $36 million loss across three transactions. The incident had an ironic twist: the attacker employed a Sybil attack on a network that promised to protect users from such a vulnerability. Furthermore, the absurdity of the event crashed the H token by nearly 90% in hours.
The attack was made possible by a central point of failure in its system, as the chain entrusted only one guy with six signer keys for its multi-sig and hot wallets.







