{"id":20482,"date":"2026-06-09T10:44:31","date_gmt":"2026-06-09T10:44:31","guid":{"rendered":"https:\/\/cryptoted.net\/index.php\/2026\/06\/09\/humanity-protocol-says-compromised-admin-keys-led-to-36m-exploit\/"},"modified":"2026-06-09T10:44:31","modified_gmt":"2026-06-09T10:44:31","slug":"humanity-protocol-says-compromised-admin-keys-led-to-36m-exploit","status":"publish","type":"post","link":"https:\/\/cryptoted.net\/index.php\/2026\/06\/09\/humanity-protocol-says-compromised-admin-keys-led-to-36m-exploit\/","title":{"rendered":"Humanity Protocol says compromised admin keys led to $36M exploit"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p class=\"is-style-lead\">Humanity Protocol has disclosed that more than $36 million worth of H tokens have been stolen after attackers compromised multiple administrative keys and seized control of bridge infrastructure across Ethereum and BNB Smart Chain.<\/p>\n<div id=\"cn-block-summary-block_af88ac4bd962bd14ebcc11cb2e5d09b2\" class=\"cn-block-summary\">\n<p>\n        <span class=\"tabs__item is-selected\">Summary<\/span>\n    <\/p>\n<div class=\"cn-block-summary__content\">\n<ul class=\"wp-block-list\">\n<li>Humanity Protocol said more than $36 million was stolen after attackers compromised administrative keys linked to its Ethereum and BNB Smart Chain bridge infrastructure.<\/li>\n<li>The project said the breach began with a compromised employee laptop, allowing attackers to seize bridge controls and mint 200 million H tokens on BNB Smart Chain.<\/li>\n<li>Deposits and withdrawals on affected bridges have been suspended as Humanity Protocol works with exchanges and law enforcement on recovery efforts.<\/li>\n<\/ul><\/div>\n<\/div>\n<p><!-- .cn-block-summary --><\/p>\n<p>According to Humanity Protocol\u2019s June 9 incident update, the attack originated after an employee\u2019s laptop was compromised, allowing the attacker to gain access to key holders tied to the project\u2019s bridge administration systems.<\/p>\n<figure class=\"wp-block-embed is-type-rich is-provider-x wp-block-embed-x\">\n<div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">INCIDENT UPDATE:<\/p>\n<p>Last night, June 8, the H token was hit by a coordinated attack across Ethereum and BSC. While we\u2019re still investigating this incident, we want to be transparent with our community about what happened.<\/p>\n<p>As of right now, ~$36M+ has been stolen across both chains\u2026<\/p>\n<p>\u2014 Humanity (@Humanityprot) <a rel=\"nofollow\" href=\"https:\/\/x.com\/Humanityprot\/status\/2064281691016048761?ref_src=twsrc%5Etfw\">June 9, 2026<\/a><\/p><\/blockquote>\n<\/div>\n<\/figure>\n<p>The disclosure expands on an earlier statement from Humanity founder and CEO Terence Kwok, who had confirmed that private keys belonging to a Humanity Foundation member were compromised.\u00a0<\/p>\n<p>At the time, the project warned users to avoid the Humanity bridge and related liquidity pools while an investigation was underway.<\/p>\n<h2 class=\"wp-block-heading\">Compromised bridge controls enabled token theft and minting<\/h2>\n<p>Details released by Humanity Protocol show that three of six Gnosis Safe owner keys controlling the Hyperlane bridge ProxyAdmin on Ethereum were compromised. Using those credentials, the attacker transferred ownership of the ProxyAdmin contract to a wallet under their control, upgraded the bridge contract to a malicious implementation, and moved about 141.2 million H tokens in a single transaction.<\/p>\n<p>    <!-- .cn-block-related-link --><\/p>\n<p>On BNB Smart Chain, the attacker compromised three of five Safe owner keys and carried out a similar takeover of the bridge\u2019s ProxyAdmin contract. Humanity Protocol said the attacker then deployed a malicious contract containing an unlimited mint function and created 200,000,005 H tokens in two separate transactions.<\/p>\n<p>Earlier on June 9, on-chain analyst Specter reported that more than 17 wallets connected to or interacting with Humanity Protocol had been drained. Initial estimates placed losses near $19 million before later blockchain trackers raised the figure above $30 million.<\/p>\n<figure class=\"wp-block-embed is-type-rich is-provider-x wp-block-embed-x\">\n<div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">The attacker continues to drain hundreds of ethereum:0xcf5104d094e3864cfcbda43b82e1cefd26a016eb holders, with total losses now $20M + .<\/p>\n<p>$9M has been swapped for ETH, while $9.9M remains in ethereum:0xcf5104d094e3864cfcbda43b82e1cefd26a016eb tokens and has yet to be swapped.<\/p>\n<p>The\u2026 <a rel=\"nofollow\" href=\"https:\/\/t.co\/ew5wtUmLuo\">https:\/\/t.co\/ew5wtUmLuo<\/a> <a rel=\"nofollow\" href=\"https:\/\/t.co\/6QX8IbPWxh\">pic.twitter.com\/6QX8IbPWxh<\/a><\/p>\n<p>\u2014 Specter (@SpecterAnalyst) <a rel=\"nofollow\" href=\"https:\/\/x.com\/SpecterAnalyst\/status\/2064127980813582627?ref_src=twsrc%5Etfw\">June 8, 2026<\/a><\/p><\/blockquote>\n<\/div>\n<\/figure>\n<p>Blockchain monitoring data cited by Specter showed that the attacker sold a portion of the stolen tokens and converted part of the proceeds into Ethereum. According to the analyst\u2019s Telegram update, roughly $23.7 million had been swapped into ETH, while about $7.9 million remained in H tokens.<\/p>\n<p>Separate monitoring from Blockaid had suggested the attacker obtained proxy administrator rights on BNB Smart Chain and minted 100 million H tokens. Humanity Protocol had not confirmed that claim at the time, though the latest incident report now confirms that the attacker gained administrative control and minted additional H on the network.<\/p>\n<h2 class=\"wp-block-heading\">Team working with exchanges and law enforcement<\/h2>\n<p>In its latest statement, Humanity Protocol said deposits and withdrawals through the affected bridges have been halted while response efforts continue.<\/p>\n<p>The project said it is coordinating with exchanges and other parties to reduce further damage. Alongside an internal investigation, Humanity Protocol said it is also working with police authorities in an effort to investigate the breach and recover some of the stolen funds.<\/p>\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>\u201cWe know words can\u2019t fix this, but we\u2019re going to show up, keep you in the loop, and do the work to earn back the trust you placed in us. We\u2019re not going anywhere and are still continuing to build.\u201d<\/p>\n<\/blockquote>\n<p>Before the latest technical breakdown was published, Kwok said the team was working with security specialists and exchange partners. No reimbursement plan or recovery framework had been announced at that stage.<\/p>\n<p>Market reaction to the exploit was severe, with the protocol\u2019s native token plummeting over 90% in the aftermath.<\/p>\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"956\" height=\"759\" src=\"https:\/\/media.crypto.news\/2026\/06\/image-99.webp\" alt=\"H\/USDT price chart.\" class=\"wp-image-14465933\" srcset=\"https:\/\/media.crypto.news\/2026\/06\/image-99.webp 956w, https:\/\/media.crypto.news\/2026\/06\/image-99-300x238.webp 300w, https:\/\/media.crypto.news\/2026\/06\/image-99-768x610.webp 768w, https:\/\/media.crypto.news\/2026\/06\/image-99-880x699.webp 880w\" sizes=\"auto, (max-width: 956px) 100vw, 956px\"\/><\/figure>\n<p>Source: <a href=\"https:\/\/crypto.news\/price\/humanity-protocol\/\">crypto.news<\/a><\/p>\n<p>Humanity Protocol operates a zkEVM-based identity network that uses zero-knowledge proofs and palm biometrics to verify users without storing their personal information in centralized identity databases.<\/p>\n<p>The team said a full post-mortem report will be released once the investigation progresses further.<\/p>\n<p>    <!-- .cn-block-related-link --><\/p><\/div>\n<p><script async src=\"\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><br \/>\n<br \/><br \/>\n<br \/><a href=\"https:\/\/crypto.news\/humanity-protocol-says-compromised-admin-keys-led-to-36m-exploit\/\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Humanity Protocol has disclosed that more than $36 million worth of H tokens have been stolen after attackers compromised multiple administrative keys and seized control of bridge infrastructure across Ethereum and BNB Smart Chain. Summary Humanity Protocol said more than $36 million was stolen after attackers compromised administrative keys linked to its Ethereum and BNB [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":20483,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"tdm_status":"","tdm_grid_status":"","footnotes":""},"categories":[23],"tags":[],"kronos_expire_date":[],"class_list":["post-20482","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-crypto"],"_links":{"self":[{"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/posts\/20482","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/comments?post=20482"}],"version-history":[{"count":0,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/posts\/20482\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/media\/20483"}],"wp:attachment":[{"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/media?parent=20482"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/categories?post=20482"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/tags?post=20482"},{"taxonomy":"kronos_expire_date","embeddable":true,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/kronos_expire_date?post=20482"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}