CryptoReal
CASE FILE — Jun 16, 2026

Seven Keys, One Laptop: How Humanity Protocol Lost $36 Million

Humanity Protocol marketed itself as a way to separate real people from bots and synthetic identity on-chain, branding itself, in the words of founder and CEO Terence Kwok, as the "trust layer of the internet" and a zero-knowledge competitor to Worldcoin built on proof-of-humanity.

On June 8, 2026, that trust layer was compromised from the inside. An attacker who had obtained a stolen private key altered the protocol's governing contracts mid-operation and walked away with roughly 447 million $H tokens, of which $36.4 million has been traced moving through Uniswap.

The mechanism was simple in retrospect: three of the protocol's six multisig keys — enough to clear the signing threshold — had reportedly been backed up onto a single employee's compromised laptop, and no timelock separated that threshold from full administrative control. Nothing about the smart contracts themselves was broken. The attacker simply became the admin.

Within hours, ZachXBT was publicly labeling the episode a "crime pump" and pressing the team to disclose its market-maker arrangements with a Hong Kong-based entity. PeckShield, tracing the same on-chain activity, reached an even more pointed conclusion — that this was not a hack at all, but a staged event. Separately, researcher banteg surfaced a message the attacker had sent to Chris Blec that, in one line, summed up how fragile the protocol's key management had actually been.

The irony was hard to miss: a project built around verifying human identity had failed to protect its own credentials. Its foundation counted Mario Nawfal — one of crypto's best-known hype figures — among its founding directors, and Kwok's earlier venture had reportedly burned through roughly $170 million before folding. The exploit also landed just seventeen days before a token unlock worth about $33 million at pre-crash prices.

In the aftermath, $H's price collapsed by roughly 90%, cross-chain bridges were shut down, and the BSC token contract remains, to this day, in the attacker's control.

01How it surfaced

Trading-security firm Specter was the first to flag unusual activity, reporting that 17 wallets which had interacted with Humanity Protocol were being drained, with losses already exceeding $5 million and climbing. The cause was unclear at that point, but the direction of the money was not — something tied to the protocol's own infrastructure had been breached.

About ninety minutes later, Specter's follow-up update put losses above $20 million. Roughly $9 million had already been converted to ETH, while another $9.9 million in $H sat untouched in attacker wallets — suggesting no urgency on the attacker's part. Sell pressure alone had already pushed $H down 87%.

Kwok's first public statement, issued roughly half an hour after that update, was brief and short on specifics: "We've detected a security incident involving the compromise of private keys belonging to a member of the Humanity Foundation. As a precaution, please do not interact with the bridge or any liquidity pools until we confirm it's safe." The framing — one member, one key — would not hold up.

A more complete statement from the official Humanity Protocol account followed, warning users about impersonators, confirming that security firms and exchanges had been engaged, and stating that only the official account or Kwok himself would issue further updates — a fairly standard incident-response script that, at the time, gave holders little sense of the scale of what was unfolding.

Beosin's own tracing showed roughly $16.2 million in $H already converted to ETH and consolidated into a single address by early evening — a pattern that looked deliberate rather than chaotic.

The story then shifted. PeckShield reported that an attacker-controlled address on BNB Chain had minted 100 million $H straight from the zero addressnew supply created via an unlimited mint function the attacker had just deployed. A second 100-million mint followed, then more, across multiple BSC transactions before the team could intervene. This was no longer a simple wallet drain — the attacker had effectively rewritten the token's supply rules.

ZachXBT weighed in shortly after, writing: "The 'incident' seems possibly staged. I am not buying the teams story, it's a convenient way for the active MM to have exited." Twenty minutes later, he went further: "You choose to crime pump your token for weeks with zero fundamentals and think CT will blindly trust your story? Disclose your active MM agreements with the HK entity first…" The message carried two distinct accusations — one about the price action in the weeks before the exploit (described elsewhere as an unusually "up only" chart), and one demanding the team name its Hong Kong market maker publicly. It never did.

Later that night, banteg posted the on-chain note the attacker had sent to researcher Chris Blec, which removed any remaining doubt about how thin the protocol's internal security had been: "i was stressing out about needing to social engineer four different devs across three different timezones. then you drop a revelation that it's actually just one guy with six signer keys in his metamask. thank you king." The attacker, in other words, had braced for a hard target and found an easy one instead.

02The mechanics: one laptop, seven keys

Humanity Protocol's official account of events landed on June 9. According to that report, a developer's laptop had been infected with malware that gave the attacker full root access. Seven production private keys had been backed up onto that machine roughly a year earlier, during the mainnet setup process, and apparently never rotated afterward. No contract vulnerability was exploited and no protocol logic was broken — every transaction the attacker sent was, technically, authorized, just with credentials that didn't belong to them.

The company's own update characterized this as an operational-security lapse rather than a design flaw — a distinction that is accurate but somewhat misleading, since the entire architecture rested on the assumption that signing keys would remain physically separated. Once that assumption broke down, there was no timelock on the ProxyAdmin contract, no circuit breaker, and no monitoring gap between crossing the signing threshold and executing the upgrade — meaning the keys' security was effectively the system's only safeguard.

Kwok later gave CoinTelegraph a more specific account: "What we believe happened was some of the keys were accidentally backed up to a compromised device." He added that for certain contracts, multisig keys had been "set up in one place and then dispersed," with some ending up stored on the compromised machine. Kwok also confirmed that signing authority across the six-key multisig was actually held by only four individuals — meaning some people controlled more than one key each. A multisig only provides real protection when its signers are genuinely independent; here, three of the six Ethereum Safe keys and three of the five BSC Safe keys were all retrievable from the same single endpoint. Since the execution threshold was three signatures, the attacker effectively already held everything needed.

On June 11, security firm Quantstamp released preliminary findings identifying whose device had been the entry point. Chong Yee Wai, a Humanity Protocol director, received a spear-phishing email on June 5, 2026, at 02:00 UTC. The message impersonated South Korean exchange Bithumb and carried a malicious attachment — Bithumb_Circulating_Supply_Lockup_Schedule.zip — hosted on an attacker-controlled domain. Believing it genuine, Chong opened it, filled in the enclosed spreadsheet, and forwarded it to Kwok, who had independently received the same phishing lure via a different, uniquely tagged URL — a common technique for tracking which recipient takes the bait. The payload installed hncagent.exe, a first-stage loader signed with a South Korean Hancom certificate; Quantstamp described the overall pattern as consistent with known DPRK intrusion tactics.

By June 7, the attacker had remote-desktop access to Chong's Windows machine, undetected by either Sophos or Windows Defender. From there, the attacker extracted Chong's MetaMask browser extension along with its encryption key — the same wallet later shown to hold all six signer keys. The on-chain attack followed the next day.

QuillAudits summarized the underlying design flaw plainly: the ProxyAdmin contract, which governs upgrades for both the bridge and the token logic, had no timelock. A 24-hour delay combined with monitoring of the AdminChanged event would likely have given the team time to react before funds moved — but that safeguard didn't exist, so the outcome was effectively sealed the moment the attacker cleared the signing threshold.

There was also a detail the official post-mortem glossed over: while the BSC Safe's keys were rotated within hours of the exploit becoming public, the Ethereum-side wallet stayed compromised for at least fourteen more hours, as banteg later pointed out — meaning the team was actively responding on one chain while the attacker retained live access on the other.

The exploit itself unfolded through three separate actions. First, the compromised admin hot wallet sent 6,045,060 $H directly to an aggregation address on Ethereum — no contract call involved, simply a key and a transfer. Second, using three of the six stolen Ethereum Safe keys assembled offline, the attacker crossed the signing threshold, reassigned ProxyAdmin ownership, upgraded the bridge to a malicious implementation, and drained 141,182,632 $H in one transaction. Third, the identical playbook was run on BSC using three of five stolen keys, seizing the ProxyAdmin, deploying a malicious implementation, and activating an unlimited mint function.

SlowMist classified the incident simply as Private Key Leakage — no audit or bug-bounty scope would have caught it, since the contracts were never actually broken.

03Printing, draining, exiting

The sequence began on June 8 when 6,045,060 $H moved from the compromised admin hot wallet straight to an attacker-controlled address — no contract interaction, no multisig process, just a stolen key executing a transfer. $H was trading around $0.62 at that moment.

Hot wallet drain: 0x94a4b4a37439ad5c01a84b504c7f58eb5c2ab560352f147f78e62802bf4ee015

Sums referenced in this case file

From there, using three of the six Ethereum Safe keys to clear the threshold, the attacker assembled an offline transaction reassigning ProxyAdmin ownership, then upgraded the bridge to a malicious contract and swept 141,182,632 $H from it in a single transaction.

ETH bridge drain: 0xa665998ca9a2fcfe66d687647edede62c7acd554c7d35ea13c93788b8a129e5b

The same approach was then applied to BSC, using three of the five compromised Safe keys there: ProxyAdmin ownership seized, a malicious implementation deployed, and the unlimited mint function switched on. The attacker called mint() three separate times, at 100 million $H per call:

BSC mint 1: 0x5a8f82f1064a7846ab3eb77bd1d36ec52dfd773c3957ad0aeea28da95fe9c5fb BSC mint 2: 0x56a150859637e453679d833bbff0d1bdfe9b8a288ca1e7190b678940dd7208f3 BSC mint 3: 0x813b340ce6fac66764a182c94d1d3c8d1aec3686e434bb19c82d12c98867e746

That accounts for the 300 million tokens confirmed in Humanity Protocol's own incident report. But QuillAudits' on-chain review found considerably more: an additional 1,000,000,000 $H minted in a single transaction, plus two more 100,000,000-token mints beyond the three the team acknowledged — putting total documented BSC minting at roughly 1,500,000,000 $H.

BSC mint — 1,000,000,000 $H (undisclosed): 0x50662e5ff99298e0c8e5bb23f532be4e92d764ec507de46cb90b96a3f2831aab BSC mint — 100,000,000 $H (undisclosed): 0x3d52ab7994f483498ab37f3c54a3850cba5cd9b3c2ff5011c629c925da5b5607 BSC mint — 100,000,000 $H (undisclosed): 0x12816ceb6c2a28ff0e926f1ede112487a224d4be84b9b01373b4971e2bb38b57

The team has not addressed this discrepancy publicly. Combining the confirmed figures — 6,045,060 from the hot-wallet drain, 141,182,632 from the ETH bridge sweep, and 300,000,000 from the three acknowledged BSC mints — Humanity Protocol's own post-mortem put total losses at approximately 447.2 million $H. QuillAudits' independent tally, which includes all observed BSC mint transactions, comes to roughly 1,641,182,632 $H — considerably higher.

What the attacker ultimately extracted in value was about $36 million, generated entirely by selling stolen and freshly minted $H into decentralized exchanges — no centralized platforms were used at any point.

Arkham Intelligence has mapped the full cluster of theft-related addresses under a single "Humanity Protocol Exploiter" entity (12 addresses): View on Arkham

Beosin identified one confirmed consolidation address holding roughly $16.2 million worth of $H converted to ETH: 0x9e995952eF7665B243eeEF0693acD7FEd7150504

Funds from that address were subsequently moved to: 0xf3599f3C7dD37FF42B043A2945E90E98B4Fc9734 and 0x365e14eDFC2D4F582c814C40162f3846aCbce672

As of publication, the original consolidation address still holds around 21.7 million $H. Humanity Protocol has since launched a public tracker of the exploiter's addresses at transparency.humanity.org and posted a $1 million USDT bounty for information leading to recovery. The attacker has not engaged. In total: twelve addresses, an orderly exit, and $36.4 million moved through Uniswap.

04An open question

ZachXBT revised his assessment on June 8, concluding after further tracing of the laundering trail that the market-maker activity and the private-key compromise appeared to be two unrelated issues. His remark: "Kind of funny if the team was pumping the token for weeks only to have gotten rekt shortly before the upcoming unlock later this month." That revision was not a clean bill of health, however — the earlier demand for disclosure of market-maker agreements with the Hong Kong entity has never been answered.

Separately, weeks before the exploit, the Humanity Foundation had already presented over 100 early investors with revised vesting terms: accept a 70% haircut for immediate liquidity on June 25, or extend the lockup to September 2026 with quarterly payouts spread over three years. One affected backer, known as Ogle, wrote publicly: "When a founding team treats its early backers with complete hostility as this one has, and disregards signed agreements, it's hard not to wonder what's actually going on behind the scenes of the company."

Dr. Hakan Ünal, senior security operations lead at Cyvers, told CoinTelegraph that genuine breaches and staged incidents can look nearly identical on-chain, since in both cases the attacker is operating with legitimate admin rights. "What distinguishes them," he said, "is the surrounding behavior. A genuine compromise usually shows speed and improvisation: funds rushed to fresh wallets, swaps at bad prices, mixer use, and no insider timing. Right now the evidence is mixed, which is why the question is open."

Allium Labs research lead Elton Shehdula's forensic review reached a firmer conclusion: the pattern was consistent with a planned, coordinated operation rather than opportunistic theft. Wallets later used by the attacker had reportedly been funded from an exchange and a mixer weeks beforehand, the minting authority appeared "warmed up" days ahead of the attack, and the eventual dump was executed simultaneously across two chains. Shehdula characterized this level of preparation as consistent with either an insider, or an external actor who had quietly held the compromised key for some time.

PeckShield's own forensic timeline, published on Telegram, traced pre-attack fund movements in detail. A major $H holder sent 20 million $H (about $5.16 million) to address 0x686d1d7B04e453dcdA68e6C003271ce20E01BE37 on May 28 — ten days before the exploit. That sending address, 0x91844A3C6BDA5B1c1f663e2280F99896efe06F42, was later itself drained to 0xD1ea823D421E0c829ee11F772AF487fd352678EA, now tagged on Etherscan as Humanity Protocol Exploiter 5.

From there, 56.7 million $H (about $15 million) moved on May 29 into two BitGo deposit addresses: 0x6E6a9fCC3A26aB1F85BF87fb8c544Af42699ce5b and 0x0E0e9fE6B97c9d4EaF040A7365c78F431064D1E0. Separately, Rekt News's own on-chain review found a further ~5.9 million $H moved into one of those same BitGo addresses on June 8 — the day of the exploit itself:

June 8 transfer into BitGo deposit address 2: 0xa8dc8dbf6dee00d615a44d643dadef7a5d403c4525535abfe594401732bb6acb

A separate wallet received $6 million USDT from FalconX on May 30 and forwarded it to OKX:

FalconX transfer 1 (4,000,000 USDT): 0xbe45706c5fd2753cea76de59c85878b021a89b4d476c66846f4c227e86ef3de7 FalconX transfer 2 (1,999,990 USDT): 0x20072681946fc27edecb76bda885b2a9c255c0dd92e81e00dbbb34a6645384a5 FalconX transfer 3 (9 USDT): 0xf5275113711d55d131bd63c6117ed42ff5934b6675d319d3300a7a15be5b6f3b Address that forwarded $6M USDT to OKX: 0x3dB75DF4104255528674f798DeC42Ff3977740bd

PeckShield also identified a second large holder who, on May 28, sent a record 72 million $H (about $12 million) to a wallet tied to a purported market-maker financier:

Large $H holder (linked to Exploiter 1): 0xbaAb7211438F33bE0344d57978C7571f2d797ab2 Wallet handling assets for the purported market maker: 0x943839Ff3D418C1435d4458e533FD90696D65238

PeckShield noted that the pattern of these addresses resembled a market maker operating across multiple centralized exchanges, and stated its conclusion bluntly: "The protocol developer's keys, the market maker's financier keys, and the market maker's wallet keys can't all be on the same computer. Therefore, I'm certain this wasn't an attack. I'm certain this was a staged performance, which, at its core, is nothing less than a Rug Pull." ZachXBT's own laundering analysis landed on a different reading, treating the market-maker activity and the hack as unrelated. Both investigators nonetheless agreed that something was off with $H's trading behavior in the run-up to the exploit.

There's also the matter of the network's actual user base. Kwok told DLNews that of roughly 9 million "Human IDs" registered on the network, just under one million had completed biometric verification — meaning as much as 88% of the claimed user base may not represent verified humans, a striking figure for a protocol whose stated purpose was proving exactly that.

05Where things stand

The BSC token contract is still under the attacker's control; the ProxyAdmin has not been recovered, meaning whoever carried out the exploit retains the ability to mint $H on BSC at will. Meanwhile, the same core team is already working on a separate venture called "Everything," which raised $6.9 million in seed funding in January 2026, led by Humanity Investments — Humanity's own venture arm — with participation from Animoca Brands and Hex Trust. Some community members have speculated the exploit could have been a way to walk away from $H while pivoting attention to the new project; that theory remains unproven, though the timing has drawn scrutiny. The team has not responded to ZachXBT's market-maker allegations, and the bridges remain offline.

An official recovery portal is now live at humanity-recovery.com. Holders from before the incident can swap legacy H for a repegged token at a 1:1.048 ratio, through a window closing June 22, 2026. The original H token has been deprecated across Ethereum, BSC, and Humanity Mainnet, replaced by a newly audited ERC-20 on Ethereum. Holders are eligible for a 1:1 airdrop based on balances captured in a snapshot at June 8, 17:25:35 UTC — roughly seven minutes before the attack's first transaction.

New H token contract: 0xE76c5b78f93909d34404E9eb4C1f19e7582a5dE1

For cases too complicated for the automatic airdrop, a separate H Compensation Fund and claims process has been set up at claim.humanity.org. Claimants must complete identity verification before compensation is processed — the team cites AML requirements tied to the exploit's alleged DPRK connection. A protocol built to verify identity is, in effect, asking its own victims to prove who they are before recovering their funds.

The June 25 unlock — 266.5 million $H across six allocations, including the foundation treasury and a strategic reserve, and visible to any trading desk on Tokenomist — remains scheduled, though at a token price now far below where it stood when investors were first asked to choose between a haircut and a delayed payout.

Humanity Protocol had raised money to build what it called the trust layer of the internet, and lost control of that layer in a single night because seven private keys sat on one laptop, compromised through a spear-phishing campaign Quantstamp linked to patterns associated with DPRK actors. Its founder had already presided over the loss of roughly $170 million at a previous company. Its foundation counted a well-known crypto hype figure, Mario Nawfal, among its founding directors. Its early investors had been pushed into a haircut-or-wait ultimatum weeks before the token's value evaporated. Its six-signer multisig turned out to be, in practice, one laptop. And its claimed 9 million verified identities may have been mostly automated accounts.

When Quantstamp's preliminary findings were published, Specter — the analyst who first spotted the exploit — described the report as the shortest post-mortem imaginable: no timestamps, no real detail, just a restatement of facts already known. Humanity Protocol built its brand on proving that people are who they claim to be. In this case, investigators have identified whose device was compromised — an unusual level of clarity for a private-key incident. What remains unresolved is whether anyone will actually be held accountable for it.

Humanity ProtocolPrivate Key Leak
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.