Rongchai Wang
Jun 09, 2026 03:35
Humanity Protocol suffers $30M non-public key compromise, crashing H token by 85%. Safety considerations resurface over key administration practices.
The Humanity Protocol, a zkEVM-based identification blockchain sometimes called the “Chinese language Worldcoin,” has been hit by a devastating exploit. A non-public key compromise involving a member of the Humanity Basis allowed attackers to empty over $30 million value of H tokens, sending the token’s worth crashing 85% inside hours. H is at present buying and selling at $0.12, down from $0.70 previous to the assault, in response to CoinGecko.
Founder and CEO Terence Kwok confirmed the breach on June 8, stating on social media that the staff is working with safety consultants to deal with the state of affairs. He urged customers to keep away from interacting with the challenge’s bridge or liquidity swimming pools till additional discover. To this point, no extra specifics in regards to the breach or its decision timeline have been disclosed.
Onchain analyst Specter was among the many first to flag the assault, noting that wallets interacting with Humanity Protocol have been being systematically drained. Blockchain intelligence agency Arkham later reported that the attacker had funneled stolen funds via decentralized exchanges resembling Kyber Community and PancakeSwap. The full losses at the moment are estimated at over $30 million.
Personal Key Missteps Resurface
This isn’t the primary time Humanity Protocol has confronted scrutiny over non-public key administration. In December 2025, the challenge admitted to a safety flaw throughout its testnet part, the place plaintext non-public keys have been saved in browser sessionStorage—a difficulty flagged by SlowMist founder Yu Xian. Whereas the staff pledged to resolve the bug promptly, no official hyperlink between that testnet vulnerability and the present exploit has been established. Nevertheless, the incident highlights ongoing dangers tied to operational safety and personal key storage practices inside crypto tasks.
Personal key compromises have turn into an more and more frequent assault vector throughout the business. Simply two months in the past, the Drift Protocol suffered a $280 million exploit through compromised admin keys. In line with CertiK, non-public key breaches have been the second-most pricey assault sort in Could 2026, with $13.7 million stolen.
H Token Market Affect
The fallout has been brutal for H token holders. After plummeting 85% to $0.08 shortly after the exploit, the token has recovered barely to $0.12 as of June 9. Market cap estimates place the challenge’s worth at $122 million, although buying and selling volumes stay unclear amid the continued disaster.
Traders will now be watching carefully for updates from Humanity Protocol concerning its remediation efforts. Safety audits, non-public key administration reforms, and clear communication will likely be crucial to restoring confidence. Nevertheless, the broader market might take longer to neglect this high-profile breach.
Because the crypto house continues to evolve, incidents like this function stark reminders of the necessity for sturdy operational safety practices—particularly for tasks dealing with delicate consumer knowledge and self-sovereign identification options.
Picture supply: Shutterstock


