Key Highlights

  • Attackers compromised the private keys of a Humanity Foundation team member and drained more than $32 million from at least 17 associated wallets, converting $23.7 million into ETH while leaving approximately $7.9 million in H tokens.

  • The H token fell nearly 89% following the breach, erasing a recent record rally, as the team urged users to avoid the protocol's bridge and liquidity pools while coordinating with security firms and exchanges.

  • Onchain analyst ZachXBT publicly questioned the official account of events, suggesting the incident may have been staged and that the team could have coordinated with a market maker ahead of the drain.

More than $32 million was drained from at least 17 wallets associated with Humanity Protocol on June 9 after attackers obtained the private keys of a member of the Humanity Foundation. Founder Terence Kwok confirmed the breach, stating that the compromised keys had been used to empty wallets linked to the project. Of the total stolen, $23.7 million was swapped into ETH, while approximately $7.9 million remained in the protocol's H token at the time of reporting.

The H token's price collapsed nearly 89% in the hours following the drain, reversing a record rally that had built over the preceding days. The team urged users to avoid interacting with the protocol's bridge and liquidity pools while it worked with blockchain security firms and centralized exchanges to contain the fallout and attempt to freeze or recover the stolen funds.

The incident drew additional scrutiny from onchain analyst ZachXBT, who publicly questioned whether the exploit was genuine, suggesting the events may have been orchestrated by insiders and that the team could have coordinated with a market maker in advance. The project has not publicly addressed ZachXBT's claims, and the competing accounts have added uncertainty to recovery efforts.

Humanity Protocol is a palm-scan-based decentralized identity platform designed to verify human uniqueness without relying on a central authority, positioning it as a competitor to Worldcoin's biometric identity approach. The exploit fits a growing pattern of private key compromises in 2026, in which attackers bypass smart contract security entirely by targeting the individuals who control wallets rather than seeking vulnerabilities in onchain code.