Private Key Breach Costs Humanity Protocol $30M and Its Core Identity Narrative

 

By Abhinav Tewari // June 9, 2026 @ 12:18 PM Make AlphaWire Logo preferred on Google News
Humanity Protocol

Share

Points of Focus

  • A private key compromise drained 17+ Humanity Protocol wallets for over $30M on June 9, 2026.
  • The attacker minted 100M additional $H tokens on BSC and swapped the proceeds for ETH, crashing $H by 90%.
  • ZachXBT stated the incident ‘seems possibly staged,’ publicly rejecting the team’s account of events.

 

Humanity Protocol, a palm-scan-based decentralized identity network that raised $50M at a $1.1 billion valuation, was drained of more than $30M on June 9, 2026, after a private key belonging to a Humanity Foundation member was compromised.

 

 

The $H token collapsed from $0.73 to a low of $0.05 within hours, a 90% decline that erased a rally that had taken the token to an all-time high of $0.85 on June 2. At the time of writing, $H is trading near $0.12, down approximately 83% over the past 24 hours, with volume exceeding $600M.

The breach did not involve a smart contract vulnerability. No code was exploited. A single compromised private key was enough.

 

How the attack unfolded

Onchain analyst Specter first flagged the breach, reporting that more than 17 wallets holding $H tokens had been drained, with initial loss estimates exceeding $5M, which later climbed to $30M. Five theft addresses were published on-chain. The attacker converted drained $H into ETH and BNB immediately, rotating into liquid assets before the market could price in the scale of the breach.

 

 

The attack then escalated beyond the initial drain. Blockaid confirmed that the attacker seized the $H token’s proxy admin on BSC and minted an additional 100M $H tokens, worth approximately $12.9M, to a new wallet at transaction hash 0x5a8f82f1064a7846ab3eb77bd1d36ec52dfd773c3957ad0aeea28da95fe9c5fb.

 

Lookonchain's Humanity Protocol Post on X
Lookonchain’s Humanity Protocol Post on X. Source: X

 

Register and unlock all content immediately

Create a free account to get full access to all our content.

Lookonchain reported that the attacker had accumulated 18,510 ETH, worth approximately $30.83M in total proceeds, with 111M $H tokens still in attacker-controlled wallets as of June 9.

 

 

Terence Kwok confirmed the incident publicly on X, stating: ‘We’ve detected a security incident involving the compromise of private keys belonging to a member of the Humanity Foundation.’ Kwok advised users to avoid the bridge and liquidity pools until safety could be confirmed and said the team was working with security experts. 

The official Humanity Protocol statement warned that impersonators typically exploit incidents like this and confirmed that the team would never send direct messages or request seed phrases.

 

Humanity Protocol's Statement
Humanity Protocol’s Statement. Source: X

 

ZachXBT’s market-making allegation and walkback

The official narrative drew immediate pushback from on-chain investigator ZachXBT. In a June 9 post, ZachXBT wrote: ‘You choose to crime pump your token for weeks with zero fundamentals and think CT will blindly trust your story? Disclose your active MM agreements with the HK entity first.’ He also added in a separate post that the incident ‘seems possibly staged’ and described it as ‘a convenient way for the active MM to have exited.’

ZachXBT subsequently updated his position. After further on-chain analysis, he stated the ‘sketchy MM/OTC and private key compromise are independent of one another and not related,’ adding: ‘Kind of funny if the team was pumping the token for weeks only to have gotten rekt shortly before the upcoming unlock later.’ The market-making allegation and the exploit are now treated as separate issues. The credibility damage from the initial accusation, however, is not undone by the walkback.

The identity narrative problem

Humanity Protocol positioned itself as a Sybil-resistant biometric identity layer: a blockchain where verified real humans could prove their identities and participate in the digital economy without compromising security or control. A protocol built entirely on that premise just lost $30M because a single person did not secure their private key.

The project raised $30M in a seed round backed by Kingsway Capital, Animoca Brands, Blockchain.com, and Shima Capital, followed by a $20M round led by Pantera Capital and Jump Crypto. The attacker extracted capital equivalent to 60% of the total fundraising in a single session. 

A June 25 token unlock remains on the calendar. With 111M in $H tokens still in attacker wallets and an unlock approaching, the supply overhang on $H is significant regardless of how the investigation resolves.

 

The hack fits the dominant 2026 pattern: the biggest losses have come from stolen keys, not flawed code. Drift Protocol lost $286M in April after attackers seized an administrative key. Kelp DAO lost $292M the same month through a single-validator bridge failure. DeFi hack losses exceeded $1 billion in the first four months of 2026, as per DeFiLlama data.

 

Share

Default avatar

Abhinav Tewari

Abhinav is a researcher and author specializing in cryptocurrency, blockchain, and Web3, translating complex protocols into actionable insight for institutions and builders. Drawing on experience across digital marketing, management, and research, he focuses on tokenization, stablecoins and payments, DeFi, and real‑world assets, with rigorous analysis of protocol economics, security, governance, and layer‑2 scalability.

Table of content

Ad

Related Articles