Humanity Protocol hack — June 2026
Incident facts
| Date of incident | (approximate) |
|---|---|
| Publicly disclosed | June 9, 2026 |
| Target type | Other |
| Loss | $36,000,000Published estimates range $32,000,000 to $36,000,000Price at time of incident |
| Method | Private key compromisemultisig signer keys backed up to one compromised laptop, used to seize bridge and token ProxyAdmin control |
| Chains | Ethereum, BNB Chain |
| Outcome | Unresolved |
What happened
Humanity Protocol operates an identity network built on palm-scan biometrics, and its H token trades on Ethereum and BNB Smart Chain. Between 8 and 9 June 2026 an attacker holding working private keys moved through three separate paths. About 6 million H were taken directly from a compromised admin hot wallet. Roughly 141 million H were drained on Ethereum after the bridge's ProxyAdmin ownership was transferred to the attacker and the bridge contract was upgraded to a malicious implementation. On BNB Smart Chain the attacker seized the token contract's ProxyAdmin and executed a series of unauthorised mints. The size of that mint is reported inconsistently: Halborn and The Crypto Times put it at about 300 million H, which is the figure consistent with the project's own tally of roughly 447 million H stolen or minted, while Decrypt and CoinDesk reported about 200 million.
No smart-contract flaw was involved; the project stated that all actions used legitimately authorised private keys. Founder Terence Kwok said the keys came from a compromised device, telling CoinDesk that some of them had been accidentally backed up to that device during setup. Halborn dates the accidental backup to the June 2025 mainnet launch and reports that malware obtained root access to the machine. From the single device the attacker obtained three of six signer keys on the Ethereum Safe and three of five on the BNB Chain Safe, meeting both approval thresholds.
The attacker sold most of the tokens on decentralised exchanges. H fell from roughly $0.70 to somewhere between $0.05 and $0.13 within about twelve hours, depending on the source.
The totals differ. CoinDesk's own on-chain assessment on 9 June found about 17 project wallets emptied, put the loss above $32 million and said it was still climbing. Humanity Protocol's public statement the same day said approximately $36 million or more had been stolen across both chains, the figure Decrypt and later coverage carried. The project halted bridge deposits and withdrawals and subsequently offered a $1 million USDT bounty for information leading to recovery and launched a new ERC-20 H contract with a 1:1 airdrop to holders based on a snapshot taken on 8 June 2026.
Law enforcement
Humanity Protocol said it was coordinating with exchanges and law enforcement and offered a $1 million USDT bounty for information leading to recovery. No arrests, charges or sanctions have been reported.
Sources
- DecryptSecondary · retrieved 2026-08-01
- CoinDeskSecondary · retrieved 2026-08-01
- CoinDeskSecondary · retrieved 2026-08-01
- The Crypto TimesSecondary · retrieved 2026-08-01
- HalbornSecondary · retrieved 2026-08-01
- Crypto Economy (needed to support the $1M bounty and token migration claims; verify before publishing)Secondary · retrieved 2026-08-01
Official post-mortem: https://humanityprotocol.notion.site/H-Token-Incident-Update-37ab0ec467a781d7af06e7dcedd66852
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Humanity Protocol hack — June 2026", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/humanity-protocolhttps://itokenly.com/hacks/humanity-protocolPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.