Humanity Protocol disclosed that attackers compromised an employee laptop and recovered enough private keys to take administrative control of key contracts, drain funds, and mint large amounts of $H. The project and outside investigators said the breach was not caused by a smart contract flaw; it stemmed from operational security weaknesses, including multiple multisig signer keys being accessible from a single device and the lack of a timelock on ProxyAdmin-controlled upgrades. Quantstamp tied the initial access to a spear-phishing email sent to director Chong Yee Wai, and the malware activity was described as consistent with DPRK tradecraft.
On-chain analysis and public reporting estimated at least 447 million $H were affected in the acknowledged attack path, while some researchers reported substantially larger mint activity on BSC and questioned gaps in the project’s disclosures. The incident triggered a sharp token-price collapse, forced bridge shutdowns, and left the BSC contract under attacker control, prompting reviews by ZachXBT, PeckShield, Specter, Beosin, SlowMist, and QuillAudits. Humanity later published an incident update and began recovery measures, including a new Ethereum token, a snapshot-based airdrop, and a claims portal that requires identity verification for compensation.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Humanity later introduced recovery measures including a new Ethereum token, a snapshot-based airdrop, and a claims portal requiring identity verification. These steps were presented as part of the project's response to the exploit and user compensation effort.
After the attack, investigators including ZachXBT, PeckShield, Specter, Beosin, SlowMist, and QuillAudits analyzed the incident. Some researchers documented substantially higher BSC mint activity than officially acknowledged and raised questions about disclosure discrepancies and possible pre-incident market-maker activity.
Following the 2026-06-08 compromise, the exploit caused the $H token price to collapse and led to bridge shutdowns, while the BSC contract remained under attacker control. Public reporting and on-chain analysis estimated at least 447 million $H were affected in the officially acknowledged attack path.
On 2026-06-08, attackers used private keys recovered from the compromised laptop to take administrative control of key contracts, drain funds, and mint large quantities of $H tokens. Reporting said the incident stemmed from operational security failures rather than a smart contract bug.
On 2026-06-05, attackers sent a spear-phishing email to director Chong Yee Wai, leading to compromise of an employee laptop. Quantstamp later linked this initial intrusion to malware behavior described as characteristic of DPRK intrusions.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 23 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.