TLDR: One compromised developer machine exposed seven private keys tied to Humanity Protocol’s infrastructure. The attacker drained 141M H from the ETH bridge andTLDR: One compromised developer machine exposed seven private keys tied to Humanity Protocol’s infrastructure. The attacker drained 141M H from the ETH bridge and

Humanity Protocol Hack: How One Infected Device Handed an Attacker Seven Private Keys

2026/06/10 19:06
4 min di lettura
Per feedback o dubbi su questo contenuto, contattateci all'indirizzo crypto.news@mexc.com.

TLDR:

  • One compromised developer machine exposed seven private keys tied to Humanity Protocol’s infrastructure.
  • The attacker drained 141M H from the ETH bridge and minted 300M H on BSC using stolen Safe owner keys.
  • No smart contract bug was involved — every attacker action used legitimate, compromised private keys.
  • The BSC H token remains unrecoverable as the attacker still controls the ProxyAdmin and can mint freely.

Humanity Protocol confirmed on June 9, 2026, that a single compromised developer machine was the source of a coordinated cross-chain attack.

An attacker obtained seven private keys from one infected device, enabling unauthorized control over critical protocol infrastructure on both Ethereum and BNB Chain.

The incident resulted in losses exceeding $31 million and a near-total collapse of the H token’s market value.

One Device, Full Protocol Access

The investigation confirmed that a developer’s machine was infected with malware, giving the attacker complete root access.

During the Humanity Protocol mainnet launch in approximately June 2025, several private keys were inadvertently backed up to that same device.

Those keys included the admin hot wallet key, three ETH Safe owner keys, and three BSC Safe owner keys — seven in total, all stored on one machine.

Founder Terence Kwok acknowledged the breach publicly, stating: “We’ve detected a security incident involving the compromise of private keys belonging to a member of the Humanity Foundation. As a precaution, please do not interact with the bridge or any liquidity pools until we confirm it’s safe.” The team added it was already working with security experts at the time of that statement.

Because all seven keys resided on one device, a single point of compromise handed the attacker full operational control. The attack was not the result of a smart contract bug.

Every transfer, Safe transaction, and proxy upgrade the attacker executed used legitimate credentials, making early on-chain detection nearly impossible.

Three Attack Vectors, One Stolen Key Set

The first attack began on June 8, 2026, when the attacker used the compromised admin hot wallet key to transfer 6,045,060 H tokens directly to an aggregation wallet on Ethereum. That transaction required no contract interaction — just a stolen key and a direct outbound transfer.

The second vector followed hours later. Using three of the six stolen ETH Safe owner keys, the attacker assembled an offline Safe transaction and transferred Bridge ProxyAdmin ownership to their own wallet.

They then upgraded the bridge contract to a malicious implementation and swept 141,182,632 H in a single transaction. The entire ETH bridge lockbox was drained within minutes of the ProxyAdmin transfer.

The third vector targeted BNB Chain. Three BSC Safe owner keys — a completely separate set from the ETH compromised keys — were also stored on the same device.

The attacker used those keys to seize the BSC ProxyAdmin by the same method, then called mint() three times, producing 100 million H per transaction.

On-chain analyst Specter flagged the early stages of the attack on X, writing: “It appears that wallets linked to, or that have interacted with, @Humanityprot are being compromised. So far, more than 17 wallets holding $H tokens have been drained, resulting in total losses exceeding $5 million.”

Total BSC mints ultimately reached 300 million H, pushing the pre-attack supply of 141 million to 441 million — a 213% increase.

What Was Saved and What Remains at Risk

Not all protocol infrastructure was affected. The ETH H token contract remained untouched throughout the attack, as its ProxyAdmin was controlled by a clean 4-of-7 Safe.

On June 9, that Safe successfully froze the ETH H token by upgrading it to an implementation that blocks all transfers. The canonical Arbitrum bridge, holding approximately 87 million H, also remained unaffected.

However, the ETH bridge and the BSC H token contract remain fully under attacker control. The BSC ProxyAdmin has not been recovered, and the attacker retains the ability to mint additional H tokens at any time. Around 21.74 million H also remained in the aggregation wallet as of June 9, pending liquidation.

The Humanity Protocol private key compromise reflects a human and operational security failure. The investigation report stated the attack “was made possible entirely by key compromise resulting from inadequate key storage practices,” noting that production-grade signing keys were backed up to a general-purpose development machine rather than isolated hardware.

The attack may have been planned well in advance, as the attacker held all seven keys before executing coordinated moves across two chains within a 15-hour window.

The post Humanity Protocol Hack: How One Infected Device Handed an Attacker Seven Private Keys appeared first on Blockonomi.

Opportunità di mercato
Logo Humanity
Valore Humanity (H)
$0.18893
$0.18893$0.18893
-2.97%
USD
Grafico dei prezzi in tempo reale di Humanity (H)

Predict & Trade to Win Rewards

Predict & Trade to Win RewardsPredict & Trade to Win Rewards

Guaranteed rewards with $500,000 prize pool

Disclaimer: gli articoli ripubblicati su questo sito provengono da piattaforme pubbliche e sono forniti esclusivamente a scopo informativo. Non riflettono necessariamente le opinioni di MEXC. Tutti i diritti rimangono agli autori originali. Se ritieni che un contenuto violi i diritti di terze parti, contatta crypto.news@mexc.com per la rimozione. MEXC non fornisce alcuna garanzia in merito all'accuratezza, completezza o tempestività del contenuto e non è responsabile per eventuali azioni intraprese sulla base delle informazioni fornite. Il contenuto non costituisce consulenza finanziaria, legale o professionale di altro tipo, né deve essere considerato una raccomandazione o un'approvazione da parte di MEXC.

Potrebbe anche piacerti

Why The Green Bay Packers Must Take The Cleveland Browns Seriously — As Hard As That Might Be

Why The Green Bay Packers Must Take The Cleveland Browns Seriously — As Hard As That Might Be

The post Why The Green Bay Packers Must Take The Cleveland Browns Seriously — As Hard As That Might Be appeared on BitcoinEthereumNews.com. Jordan Love and the Green Bay Packers are off to a 2-0 start. Getty Images The Green Bay Packers are, once again, one of the NFL’s better teams. The Cleveland Browns are, once again, one of the league’s doormats. It’s why unbeaten Green Bay (2-0) is a 8-point favorite at winless Cleveland (0-2) Sunday according to betmgm.com. The money line is also Green Bay -500. Most expect this to be a Packers’ rout, and it very well could be. But Green Bay knows taking anyone in this league for granted can prove costly. “I think if you look at their roster, the paper, who they have on that team, what they can do, they got a lot of talent and things can turn around quickly for them,” Packers safety Xavier McKinney said. “We just got to kind of keep that in mind and know we not just walking into something and they just going to lay down. That’s not what they going to do.” The Browns certainly haven’t laid down on defense. Far from. Cleveland is allowing an NFL-best 191.5 yards per game. The Browns gave up 141 yards to Cincinnati in Week 1, including just seven in the second half, but still lost, 17-16. Cleveland has given up an NFL-best 45.5 rushing yards per game and just 2.1 rushing yards per attempt. “The biggest thing is our defensive line is much, much improved over last year and I think we’ve got back to our personality,” defensive coordinator Jim Schwartz said recently. “When we play our best, our D-line leads us there as our engine.” The Browns rank third in the league in passing defense, allowing just 146.0 yards per game. Cleveland has also gone 30 straight games without allowing a 300-yard passer, the longest active streak in the NFL.…
Condividi
BitcoinEthereumNews2025/09/18 00:41
DFA says trilateral talks with US, Japan strengthen PHL maritime, economic resilience

DFA says trilateral talks with US, Japan strengthen PHL maritime, economic resilience

THE Philippines’ trilateral talks with the United States and Japan focused on maritime cooperation aimed at promoting a free Indo-Pacific, Department of Foreign
Condividi
Bworldonline2026/06/10 21:15
Genius Group (GNS) Stock Climbs 8% After Q1 Revenue Soars 171% and Returns to Profit

Genius Group (GNS) Stock Climbs 8% After Q1 Revenue Soars 171% and Returns to Profit

Genius Group (GNS) stock rises 8.48% after Q1 2026 revenue jumps 171%, company returns to profit, clears debt, and expands AI education offerings. The post Genius
Condividi
Blockonomi2026/04/02 19:17

RealStocks Now Live

RealStocks Now LiveRealStocks Now Live

Trade real U.S. stock via regulated brokerage