Humanity Protocol disclosed that an attacker stole more than $36 million in H tokens after compromising an employee's laptop that stored multiple admin keys for the project's cross-chain bridges. The machine held three of the six Ethereum keys and three of the five BNB Chain keys that governed the bridge contracts — enough to clear the multisignature approval threshold on both networks without any additional signer.
Once inside, the attacker transferred ownership of the Ethereum bridge to their own wallet, swapped the contract code for a malicious upgrade and drained roughly 141 million H in a single transaction. On BNB Chain, the same actor installed a contract with an unlimited mint function and created about 200 million additional H, sending the new tokens directly to their own address.
Why it matters
The post-mortem is the part the rest of DeFi will read. Founder Terence Kwok told CoinDesk the team had correctly set up a multisig across four individuals — but during deployment, several of those keys were backed up to a single compromised device, collapsing the entire purpose of a multisig into a single point of failure.
Humanity is not a small, unaudited experiment. The project raised $20 million last year from Pantera Capital and Jump Crypto at a $1.1 billion valuation. That a high-profile, well-capitalized identity project shipped bridge admin keys onto one laptop will be cited for years in arguments about operational security standards in DeFi.
Market impact
H plunged more than 80% intraday, bottoming near five cents, before recovering to roughly 20 cents — still well below the ~67 cent level it traded at before the breach. Onchain investigator ZachXBT said the key compromise appears disconnected from a separate round of suspicious market-making in H ahead of a large scheduled token unlock, when the price ran from 20 cents to 70 cents in two weeks. The project has since pulled its team page offline, halted bridge deposits and withdrawals, and is coordinating with exchanges and law enforcement on recovery.
Frequently asked questions
-
How did the attacker drain Humanity Protocol's bridges?
The attacker compromised an employee laptop that held three of six Ethereum and three of five BNB Chain bridge admin keys, enough to clear the multisig threshold. They then upgraded the bridge contracts and drained ~141M H on Ethereum and minted ~200M new H on BNB Chain.
-
Why is a single laptop holding multisig keys a problem?
Multisig wallets are designed to spread keys across different people and devices so no single machine can move funds. Storing multiple signing keys on one device collapses that defense — a single compromise crosses the approval threshold and defeats the entire point of multisig.
-
What did founder Terence Kwok say caused the breach?
Kwok told CoinDesk the team had set up a multisig across four individuals correctly, but several keys were accidentally backed up to a compromised device during deployment, leaving the keys accessible from one machine.
-
How much was stolen and what is H trading at now?
More than $36M worth of H was taken. H fell more than 80% intraday to about five cents and has since recovered to roughly 20 cents, still well below the ~67 cent level it traded at before the breach.
-
Who backs Humanity Protocol and how much did it raise?
Humanity Protocol raised $20 million from Pantera Capital and Jump Crypto last year at a $1.1 billion valuation. The project has since removed its team page from its website and is coordinating with exchanges and law enforcement on recovery.
CoinDesk