Share
Subscribe to the AlphaWire Newsletter
Humanity Protocol, a palm-scan-based decentralized identity network that raised $50M at a $1.1 billion valuation, was drained of more than $30M on June 9, 2026, after a private key belonging to a Humanity Foundation member was compromised.
We're aware of a security incident involving the compromise of private keys belonging to a member of the Humanity Foundation. The safety of our community is our top priority, and we want to be fully transparent about what we know.
As a precaution, please do NOT interact with the…— Humanity (@Humanityprot) June 9, 2026
The $H token collapsed from $0.73 to a low of $0.05 within hours, a 90% decline that erased a rally that had taken the token to an all-time high of $0.85 on June 2. At the time of writing, $H is trading near $0.12, down approximately 83% over the past 24 hours, with volume exceeding $600M.
The breach did not involve a smart contract vulnerability. No code was exploited. A single compromised private key was enough.
Onchain analyst Specter first flagged the breach, reporting that more than 17 wallets holding $H tokens had been drained, with initial loss estimates exceeding $5M, which later climbed to $30M. Five theft addresses were published on-chain. The attacker converted drained $H into ETH and BNB immediately, rotating into liquid assets before the market could price in the scale of the breach.
It appears that wallets linked to, or that have interacted with, @Humanityprot are being compromised.
So far, more than 17 wallets holding $H (Humanity Protocol) tokens have been drained, resulting in total losses exceeding $5 million.
Theft addresses:… pic.twitter.com/EOmMHkYxU2
— Specter (@SpecterAnalyst) June 8, 2026
The attack then escalated beyond the initial drain. Blockaid confirmed that the attacker seized the $H token’s proxy admin on BSC and minted an additional 100M $H tokens, worth approximately $12.9M, to a new wallet at transaction hash 0x5a8f82f1064a7846ab3eb77bd1d36ec52dfd773c3957ad0aeea28da95fe9c5fb.

Create a free account to get full access to all our content.
Lookonchain reported that the attacker had accumulated 18,510 ETH, worth approximately $30.83M in total proceeds, with 111M $H tokens still in attacker-controlled wallets as of June 9.
We've detected a security incident involving the compromise of private keys belonging to a member of the Humanity Foundation. As a precaution, please do not interact with the bridge or any liquidity pools until we confirm it's safe.
We're already working with security experts…
— Terence Kwok 「 🖐️ ✦ 🌏 」 (@terencekwok) June 9, 2026
Terence Kwok confirmed the incident publicly on X, stating: ‘We’ve detected a security incident involving the compromise of private keys belonging to a member of the Humanity Foundation.’ Kwok advised users to avoid the bridge and liquidity pools until safety could be confirmed and said the team was working with security experts.
The official Humanity Protocol statement warned that impersonators typically exploit incidents like this and confirmed that the team would never send direct messages or request seed phrases.

The official narrative drew immediate pushback from on-chain investigator ZachXBT. In a June 9 post, ZachXBT wrote: ‘You choose to crime pump your token for weeks with zero fundamentals and think CT will blindly trust your story? Disclose your active MM agreements with the HK entity first.’ He also added in a separate post that the incident ‘seems possibly staged’ and described it as ‘a convenient way for the active MM to have exited.’
ZachXBT subsequently updated his position. After further on-chain analysis, he stated the ‘sketchy MM/OTC and private key compromise are independent of one another and not related,’ adding: ‘Kind of funny if the team was pumping the token for weeks only to have gotten rekt shortly before the upcoming unlock later.’ The market-making allegation and the exploit are now treated as separate issues. The credibility damage from the initial accusation, however, is not undone by the walkback.
Humanity Protocol positioned itself as a Sybil-resistant biometric identity layer: a blockchain where verified real humans could prove their identities and participate in the digital economy without compromising security or control. A protocol built entirely on that premise just lost $30M because a single person did not secure their private key.
The project raised $30M in a seed round backed by Kingsway Capital, Animoca Brands, Blockchain.com, and Shima Capital, followed by a $20M round led by Pantera Capital and Jump Crypto. The attacker extracted capital equivalent to 60% of the total fundraising in a single session.
A June 25 token unlock remains on the calendar. With 111M in $H tokens still in attacker wallets and an unlock approaching, the supply overhang on $H is significant regardless of how the investigation resolves.
The hack fits the dominant 2026 pattern: the biggest losses have come from stolen keys, not flawed code. Drift Protocol lost $286M in April after attackers seized an administrative key. Kelp DAO lost $292M the same month through a single-validator bridge failure. DeFi hack losses exceeded $1 billion in the first four months of 2026, as per DeFiLlama data.
Create a free account to continue reading AlphaClub articles and access exclusive features.
Share