Humanity Protocol Loses $30 Million in Private-Key Attack as H Token Plunges 85%
Humanity Protocol is a blockchain identity project that uses palm-print biometrics and zero-knowledge proofs to establish Proof of Humanity. H is its ecosystem’s native token. The incident not only inflicted heavy losses on holders but also exposed operational risks arising from cross-chain bridge controls and multisig private keys being concentrated on team members’ devices, undermining market confidence in decentralized identity infrastructure.
On June 8, 2026, an attacker used a private key from a director’s malware-compromised laptop to take control of contracts on Ethereum and BNB Chain. The attacker transferred or minted H tokens and sold them. Losses were initially estimated at $30 million–$32 million and later revised to more than $36 million, while H plunged about 89% within eight hours. Humanity invalidated the old tokens and will airdrop new H at a 1:1 ratio on July 1, based on a snapshot taken at 17:25 UTC that day.
All Coverage
9 original reportsThe Backstory
The history behind this eventHumanity Protocol to Overhaul Operational Security After Hack
Decentralized identity project Humanity Protocol aims to use biometric technology to establish proof of personhood in Web3. Crypto hackers, however, are increasingly shifting their focus away from smart-contract coding flaws and toward employee errors and weaknesses in corporate operations. The trend poses a new and serious cybersecurity challenge for major Web3 organizations.
Humanity Protocol founder Terence Kwok confirmed that an employee laptop was compromised in June 2026, exposing administrative private keys and multisignature keys. The breach led to the theft of Humanity (H) tokens worth $36 million. In response, the team said it would refocus its security defenses on operational security.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.