Two DeFi protocols hit within days of each other. Stolen funds ending up in the same wallets. And one question that demands an answer: is this the work of a single attacker operating in series?
On-chain investigations are pointing to a troubling connection between the Humanity Protocol exploit and the Kelp DAO exploit. The details emerging from the data challenge the assumption that these were two isolated incidents.
Here is what the blockchain data reveals — and why this case could mark a turning point in how DeFi approaches multi-protocol security.
Two Exploits, Overlapping Wallets: What the Blockchain Shows
On-chain analysis is often the only reliable thread to follow in crypto hack investigations. In this case, security researchers have identified shared fund flows between addresses linked to both exploits. Tokens from the Kelp DAO hack and those from the Humanity Protocol breach passed through identical intermediary wallets — a strong signal of coordination, or even a single common origin.
This type of commingling is a classic technique used by hackers to obscure their trail before laundering funds through mixers like Tornado Cash or cross-chain bridges. The fact that both fund flows converge toward the same addresses before dispersal points to a shared exfiltration infrastructure — which strongly suggests a single actor or an organized group.
Kelp DAO, a liquid restaking protocol on Ethereum, and Humanity Protocol, a project focused on decentralized identity verification, operate in very different verticals. Their only apparent common ground: both were targeted within a tight timeframe, using exploitation methods that share notable technical similarities.
Attacker Profile: Sophistication and Strategic Targeting
What stands out in this case is the apparent level of sophistication behind the attacks. Compromising two distinct protocols — each with different smart contract architectures — within a short window is not the result of opportunistic luck. It requires an in-depth reconnaissance phase, a precise understanding of the specific vulnerability vectors in each protocol, and the operational capacity to manage multiple attacks simultaneously.
The most advanced threat actors — often linked to state-sponsored groups such as the North Korean Lazarus Group — operate with exactly this kind of multi-target strategy. Without formal attribution at this stage, the modus operandi is reminiscent of documented campaigns in which multiple DeFi protocols are hit in sequence to maximize the haul before security teams can react and freeze assets.
Both protocols have communicated about their respective incidents, but no public coordination between their security teams has been announced. This is precisely the gap that attackers exploit: while each team manages its own crisis in isolation, the funds keep moving.
What This Means for DeFi Security
If the link between the two exploits is confirmed, the implications extend far beyond the two protocols involved. Decentralized finance suffers from a structural problem: each protocol treats its security in isolation, while attackers operate across the entire ecosystem. A real-time shared alert system between protocols — similar to the ISACs (Information Sharing and Analysis Centers) used in traditional finance — would allow this type of multi-target pattern to be detected far more quickly.
Platforms like Chainalysis, Arkham Intelligence, and TRM Labs are playing an increasingly important role in post-exploit tracing. But the real challenge remains prevention: regular audits, active bug bounty programs, and above all a culture of threat intelligence sharing between security teams. As long as DeFi remains fragmented on this front, multi-protocol attackers will continue to operate one step ahead.
The Humanity Protocol and Kelp DAO case illustrates an uncomfortable reality: in an ecosystem as interconnected as DeFi, the security of one protocol depends on the security of its neighbors. It is a lesson the industry can no longer afford to ignore.