On-Chain Funds Merge: A Critical Link Emerges Between Two Major Hacks

A new development has surfaced in blockchain security. Renowned on-chain investigator ZachXBT highlighted a concerning pattern in an analysis posted on June 27th: stolen funds from the recent high-profile Humanity Protocol breach have begun to intersect on the blockchain with proceeds from the earlier Kelp DAO exploit.

The Incidents: A Tale of Two Major Losses

Both attacks resulted in significant financial damage. Public records show that Kelp DAO's LayerZero bridge was compromised on April 18, 2026, due to infrastructure vulnerabilities, leading to a loss of approximately $292 million. The North Korean Lazarus Group is widely considered the prime suspect.

More recently, on June 9, 2026, Humanity Protocol's team addresses and deployer were breached via a developer's compromised device, resulting in the theft of around $32 million. Initially, these were treated as separate incidents.

ZachXBT's Insight: Tracing the Digital Footprint

ZachXBT's monitoring revealed that, about an hour before his post, funds associated with both heists began showing signs of interaction and merging. This "funds confluence" is a potent clue in on-chain forensics.

  • The Implication: It strongly suggests a direct link between the wallets or entities controlling the proceeds from different attacks.
  • Investigative Value: It provides tangible on-chain evidence to potentially connect seemingly isolated cases, pointing to a single group or a coordinated criminal network.

Security Implications and Industry Warning

If corroborated, this finding carries significant weight. It could indicate an organized, persistent campaign targeting various DeFi protocols and infrastructure. Attackers may be recycling tools, techniques, or access after a successful breach to quickly identify the next target.

Furthermore, it raises the bar for project security audits and threat modeling. Teams must guard not only against isolated exploits but also against systemic risks associated with becoming an Advanced Persistent Threat (APT) target. A failure in infrastructure security, developer device hygiene, or private key management can trigger a chain reaction.

Investigations are ongoing. Security professionals recommend that all projects reassess their security posture, particularly checking permissions and access points for potential links to known attack patterns or suspicious addresses.