Wallets linked to Humanity Protocol were drained for over $32 million on Monday, sending the project's native H token down roughly 89% in 24 hours, according to onchain analyst Specter and CoinGecko data. The exploit hit 17 wallets that had interacted with the protocol, with losses initially pegged around $5 million before climbing as the attacker laundered proceeds.
Of the stolen funds, around $23.7 million has been swapped into Ethereum, while roughly $7.9 million remains sitting in H tokens, per Specter's Telegram updates. Humanity Protocol founder Terence Kwok confirmed the incident on X, attributing it to the compromise of private keys belonging to a member of the Humanity Foundation rather than a flaw in protocol code. The team said it is working with security experts and exchange partners on resolution.
Why it matters
The vector matters more than the dollar number. A private-key compromise is a single point of failure — it can't be patched with a contract upgrade, only with operational controls around key custody that the foundation now has to rebuild under pressure. For a project pitching itself as a decentralized identity layer built on biometrics and zero-knowledge proofs, a breach of the founding team's key management undercuts the trust argument the protocol sells to potential integrators.
The pattern Specter flagged — 17 wallets sharing "a common exposure related to Humanity Protocol" — is consistent with a signing environment being compromised, not a smart-contract drain. That distinction will shape whether affected users have any recovery path at all.
Market impact
An 89% single-day collapse in H wiped out the token's liquidity bid and put it deep into the price-discovery void. Roughly a quarter of the stolen funds still sit in H on the attacker's address, which means the dump risk is not over: any move to swap that residual into ETH or stablecoins will set a fresh lower low. The H token's market structure is effectively rebuilt from here, and the project is negotiating that rebuild while the attacker still controls a non-trivial reserve.
Frequently asked questions
-
How much was stolen in the Humanity Protocol exploit?
Onchain analyst Specter put total losses above $32 million, up from an initial estimate of around $5 million. Roughly $23.7 million has been swapped into Ethereum, while about $7.9 million remains in H tokens on the attacker's address.
-
How did the attacker drain the Humanity Protocol wallets?
Humanity Protocol founder Terence Kwok said the breach stemmed from compromised private keys belonging to a member of the Humanity Foundation, not a flaw in the protocol's smart contracts. Specter's onchain analysis identified 17 affected wallets sharing a common exposure tied to Humanity Protocol.
-
What is happening with the H token price?
The H token fell roughly 89% in the 24 hours following the exploit, according to CoinGecko data. With most of the stolen funds already swapped into ETH and a residual H balance still on the attacker's address, the token remains exposed to further downside.
-
Can users recover funds lost in the Humanity Protocol hack?
The article does not say. Because the breach was attributed to a private-key compromise rather than a smart-contract bug, recovery depends on operational and legal remedies rather than a code fix, and the team has not outlined a reimbursement plan.
-
What is Humanity Protocol?
Humanity Protocol is a decentralized identity verification project that uses biometrics and zero-knowledge proofs to let users prove their humanness without revealing personal data. The H token is the project's native asset.
TheBlock