Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
cryptocurrency-platform-riskphishing-campaign-intelligencecredential-access-methodoperational-disruption

Humanity Protocol Compromise Let Attackers Seize Admin Keys and Mint $H

Updated 12d agoFirst seen Jun 16, 20262 sources

Humanity Protocol disclosed that attackers compromised an employee laptop and recovered enough private keys to take administrative control of key contracts, drain funds, and mint large amounts of $H. The project and outside investigators said the breach was not caused by a smart contract flaw; it stemmed from operational security weaknesses, including multiple multisig signer keys being accessible from a single device and the lack of a timelock on ProxyAdmin-controlled upgrades. Quantstamp tied the initial access to a spear-phishing email sent to director Chong Yee Wai, and the malware activity was described as consistent with DPRK tradecraft.

On-chain analysis and public reporting estimated at least 447 million $H were affected in the acknowledged attack path, while some researchers reported substantially larger mint activity on BSC and questioned gaps in the project’s disclosures. The incident triggered a sharp token-price collapse, forced bridge shutdowns, and left the BSC contract under attacker control, prompting reviews by ZachXBT, PeckShield, Specter, Beosin, SlowMist, and QuillAudits. Humanity later published an incident update and began recovery measures, including a new Ethereum token, a snapshot-based airdrop, and a claims portal that requires identity verification for compensation.

Share:
Humanity Protocol Compromise Let Attackers Seize Admin Keys and Mint $H
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Jun 9, 202620d ago

Humanity launches recovery and compensation mechanisms

Humanity later introduced recovery measures including a new Ethereum token, a snapshot-based airdrop, and a claims portal requiring identity verification. These steps were presented as part of the project's response to the exploit and user compensation effort.

Rekt - Humanity Protocol - Rekt

Researchers publish competing analyses of the Humanity exploit

After the attack, investigators including ZachXBT, PeckShield, Specter, Beosin, SlowMist, and QuillAudits analyzed the incident. Some researchers documented substantially higher BSC mint activity than officially acknowledged and raised questions about disclosure discrepancies and possible pre-incident market-maker activity.

Rekt - Humanity Protocol - Rekt
Jun 8, 202621d ago

Bridge shutdowns and token price collapse follow exploit

Following the 2026-06-08 compromise, the exploit caused the $H token price to collapse and led to bridge shutdowns, while the BSC contract remained under attacker control. Public reporting and on-chain analysis estimated at least 447 million $H were affected in the officially acknowledged attack path.

Rekt - Humanity Protocol - Rekt

Attackers seize admin control and exploit Humanity Protocol

On 2026-06-08, attackers used private keys recovered from the compromised laptop to take administrative control of key contracts, drain funds, and mint large quantities of $H tokens. Reporting said the incident stemmed from operational security failures rather than a smart contract bug.

Rekt - Humanity Protocol - Rekt
Jun 5, 202624d ago

Spear-phishing email compromises Humanity Protocol director

On 2026-06-05, attackers sent a spear-phishing email to director Chong Yee Wai, leading to compromise of an employee laptop. Quantstamp later linked this initial intrusion to malware behavior described as characteristic of DPRK intrusions.

Rekt - Humanity Protocol - Rekt
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

30 LINKEDOpen in app
Threat actors
1 linked
Malware
1 linked
Affected products
3 linked
Windows DefenderWindowsMetamask
Organizations
24 linked
HancomCyVersMeta PlatformsOKXArkham IntelligenceMicrosoft CorporationSophosSlowMistUniswapPeckShieldQuantstampBitGoBithumbCointelegraphFalconXHumanity ProtocolAnimoca BrandsHumanity InvestmentsEverythingDL NewsQuillAuditsBeosinHex TrustAllium Labs
Breaches
1 linked
HUMANITYPROTOCOL-2026-06
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Humanity Protocol Compromise Let Attackers Seize Admin Keys and Mint $H | Mallory