Founder Confirms the Breach
Humanity Protocol founder Terence Kwok has confirmed a security incident involving the compromise of private keys belonging to a member of the Humanity Foundation. The breach occurred on June 9, 2026, and triggered a sharp collapse in the project's native H token. Kwok addressed the incident publicly, telling users to avoid interacting with the project's bridge or any liquidity pools until the team confirms it is safe, and said the project was already working with security experts.
Onchain data showed losses exceeding 30 million USD, with the H token crashing by roughly 90% after the attacker began offloading the stolen tokens. Blockchain analytics account Lookonchain flagged the exploit as it unfolded, reporting that the hacker was dumping H and swapping it for ETH, creating immediate downward pressure on the market. Blockchain security monitor PeckShieldAlert also flagged active wallet compromises across the Humanity Protocol ecosystem as the attack developed.
The exact loss figure has varied across reports as the situation developed, ranging from around 30 million USD in early onchain estimates up to 36 million USD across both chains according to later project statements. Regardless of the precise total, the incident ranks among the more significant security failures of 2026.
How the Attack Happened
The breach did not stem from a smart contract flaw or a protocol logic error. Instead, attackers obtained private keys tied to the project, which gave them direct access to funds. According to the project, attackers compromised three of six Gnosis Safe keys on Ethereum and three of five on BSC, seizing ProxyAdmin control. From there, the attacker drained around 141.2 million H and minted an additional 200 million H through malicious contract upgrades.
Meir Dolev, co-founder and CTO at blockchain security platform Cyvers, described the incident as an operational security failure rather than a smart contract bug, with the attacker gaining admin access through a private key tied to a Humanity Foundation member. That distinction matters. A foundation-level key compromise means the vulnerability was inside the project itself rather than in its public-facing infrastructure, raising harder questions about internal key management.
Private key compromises remain one of the most damaging attack vectors in crypto, since they bypass on-chain security mechanisms and grant direct control over project-linked assets. The attacker moved quickly, with onchain analysts observing large-scale token sales followed by conversions into ETH and BNB. Investigators reported that roughly 9 million USD worth of stolen H had already been swapped into ETH, with additional millions sitting in attacker-controlled wallets awaiting liquidation.
The Token Collapse
The H token's price reflected the severity of the breach. The token plunged from highs around 0.73 USD on Monday to a Tuesday morning low near 0.05 to 0.08 USD, a drop of as much as 90% depending on the reference point. The crash erased most of the gains from a recent rally that had pushed the token close to its all-time high of around 0.80 USD just a week earlier.
The collapse wiped out a huge portion of the token's market capitalization, which fell from around 2 billion USD to roughly 35.7 million USD at the low. Trading volume surged into the hundreds of millions as panic selling intensified across exchanges, and liquidity rapidly deteriorated across trading venues. As of the most recent reporting, H had recovered slightly but remained down dramatically on the day.
The timing was particularly damaging. The breach hit just as H had emerged as one of the stronger-performing tokens in the Proof-of-Humanity and AI-identity sector, having surged significantly above its yearly low in the weeks before the attack.
The Project's Response
In an official statement, Humanity Protocol confirmed the breach originated from a Foundation member's private keys, and Kwok emphasized that the core protocol and smart contracts were not exploited. The team advised users to immediately avoid bridges and liquidity pools, revoke token approvals, and rely only on verified official channels for updates.
The team said it had halted deposits and withdrawals to the affected bridges and was working with security firms, exchange partners, and police to recover funds. In a statement acknowledging the impact on its community, the project said the people in its community worked hard for what they hold and that the team felt the weight of that, promising a post-mortem.
At the time of the early reporting, Humanity Protocol had not yet released a detailed technical analysis, recovery plan, or compensation framework for affected users. The team asked users to trust updates only from its official account and from Kwok directly, and said the core protocol and user funds on the main contracts remained secure.
Inside Humanity Protocol
Humanity Protocol launched in 2024 as a decentralized digital identity network built around palm-scan biometrics and zero-knowledge cryptography. The project lets people prove they are human without revealing personal data, positioning itself as a rival to Sam Altman's Worldcoin in the Proof-of-Humanity space. Its pitch is to verify real human users and filter out bots and fake accounts, which drew significant institutional attention.
The project raised 50 million USD across two funding rounds, backed by investors including Pantera Capital, Jump Crypto, Animoca Brands, and Blockchain.com, and reached a reported valuation of 1.1 billion USD. The H token launched in June 2025 via what the project called a Fairdrop mechanism, touted as a token distribution exclusively for verified real humans.
The project has faced scrutiny before. Shortly after the token launch, a reported leaked conversation suggested that of the 9 million Human IDs created online, only about 1 million had completed biometric verification, raising questions about how many users were genuine. The founder, Terence Kwok, previously ran hospitality-tech startup Tink Labs, which raised about 160 million USD and became one of Hong Kong's first unicorns before shutting down in 2019 amid financial troubles.
A Difficult Stretch for DeFi Security
The Humanity Protocol breach extends one of the worst periods on record for DeFi security. According to DeFiLlama data, more than 885 million USD has been lost to DeFi hacks in the first six months of 2026. The year's largest single incident came on April 1, when Drift Protocol suffered a 286 million USD attack.
The pattern of attacks has shifted. Attackers are increasingly targeting validators, RPC nodes, governance systems, and private keys rather than purely smart contract vulnerabilities. Private key and operational security failures have proven especially devastating because they bypass the on-chain security mechanisms that protocols rely on, granting attackers direct control over funds. The Humanity breach echoes similar recent incidents where compromised keys, rather than code flaws, led to major losses.
What Comes Next
For now, the situation remains active. Humanity Protocol has paused its affected bridges, is tracking the stolen funds with security partners, and has promised a full post-mortem. The immediate guidance for users is clear: avoid the bridge and all liquidity pools, revoke token approvals, and follow only the project's official channels and Kwok directly for updates.
The longer-term questions center on recovery and trust. Whether the project can recover any of the stolen funds, how it will address affected users, and how it will overhaul its internal key management will all shape its path forward. For a project built specifically around the premise of verifying and protecting real humans, a foundation-level security failure of this scale represents a serious test of its credibility in the Proof-of-Humanity sector.













