{"id":24124,"date":"2026-06-10T05:32:13","date_gmt":"2026-06-10T05:32:13","guid":{"rendered":"https:\/\/nft.runfyers.com\/index.php\/2026\/06\/10\/humanity-protocols-h-token-crashes-over-80-after-36m-private-key-breach\/"},"modified":"2026-06-10T05:32:13","modified_gmt":"2026-06-10T05:32:13","slug":"humanity-protocols-h-token-crashes-over-80-after-36m-private-key-breach","status":"publish","type":"post","link":"https:\/\/nft.runfyers.com\/index.php\/2026\/06\/10\/humanity-protocols-h-token-crashes-over-80-after-36m-private-key-breach\/","title":{"rendered":"Humanity Protocol\u2019s H Token Crashes Over 80% After $36M Private-Key Breach"},"content":{"rendered":"<p><\/p>\n<div>\n<p><b>Humanity Protocol\u2019s H token<\/b><span style=\"font-weight: 400;\"> plummeted by over 80% on June 9 after the project confirmed an exploit involving compromised private keys, resulting in the theft of over $36 million in tokens and their dumping onto the market.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">In a post-mortem published on the evening of June 9, Humanity stated that the incident occurred between June 8 and June 9 via <\/span><b>three attack vectors<\/b><span style=\"font-weight: 400;\"> across Ethereum and BNB Smart Chain. These included direct theft from an admin hot wallet, a bridge drain on Ethereum, and the unauthorized minting of 300 million H tokens on BSC. The project noted that the root cause was malware on an internal machine that had mistakenly stored multiple production keys, turning a breach on a personal device into a crisis at the bridge admin and token supply level.<\/span><\/p>\n<h3><span class=\"ez-toc-section\" id=\"How_the_Exploit_Happened\"\/><b>How the Exploit Happened<\/b><span class=\"ez-toc-section-end\"\/><\/h3>\n<p><span style=\"font-weight: 400;\">Humanity initially stated that the incident stemmed from a laptop breach by an internal staff member. The <\/span><a href=\"https:\/\/humanityprotocol.notion.site\/H-Token-Incident-Update-37ab0ec467a781d7af06e7dcedd66852\" data-wpel-link=\"external\" target=\"_blank\" rel=\"nofollow external noopener noreferrer\"><span style=\"font-weight: 400;\">post-mortem<\/span><\/a><span style=\"font-weight: 400;\"> later clarified a more severe detail: a device had been compromised with root access via malware, while multiple production keys had been mistakenly backed up to it during the mainnet launch phase around June 2025.<\/span><\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">INCIDENT UPDATE:<\/p>\n<p>Last night, June 8, the H token was hit by a coordinated attack across Ethereum and BSC. While we\u2019re still investigating this incident, we want to be transparent with our community about what happened.<\/p>\n<p>As of right now, ~$36M+ has been stolen across both chains\u2026<\/p>\n<p>\u2014 Humanity (@Humanityprot) <a href=\"https:\/\/x.com\/Humanityprot\/status\/2064281691016048761?ref_src=twsrc%5Etfw\" data-wpel-link=\"external\" target=\"_blank\" rel=\"nofollow external noopener noreferrer\">June 9, 2026<\/a><\/p>\n<\/blockquote>\n<p><span style=\"font-weight: 400;\">From this compromise point, the attacker obtained enough keys to operate on both Ethereum and BNB Smart Chain. On Ethereum, the attacker seized control of the <\/span><b>Bridge ProxyAdmin<\/b><span style=\"font-weight: 400;\">, upgraded the bridge to a malicious version, and withdrew approximately 141.18 million H tokens in a single transaction. An admin hot wallet was also drained of an additional 6.05 million H tokens.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">On BNB Smart Chain, the incident went further than a bridge drain. The attacker compromised the ProxyAdmin of the BSC H token and minted 300 million H tokens across three iterations on June 9. The supply of H on BSC surged from around 141.12 million H to 441.12 million H, expanding the supply on this chain to over three times its pre-attack level.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">According to Humanity, this was not a smart contract flaw in the traditional sense. The attacker signed transactions using valid private keys after internal key storage was compromised, turning an operational failure into control over the bridge and token admin across multiple chains.<\/span><\/p>\n<h3><span class=\"ez-toc-section\" id=\"H_Token_Erases_Early-June_Rally\"\/><b>H Token Erases Early-June Rally<\/b><span class=\"ez-toc-section-end\"\/><\/h3>\n<p><span style=\"font-weight: 400;\">H had rallied strongly prior to the incident, climbing from the $0.20 region in late May to a short-term peak near $0.855 in early June. Following the exploit, the token dropped below $0.10 across several venues, with charts recording a low of around $0.074 before recovering to the $0.16-$0.22 zone.<\/span><\/p>\n<div id=\"attachment_162300\" style=\"width: 2352px\" class=\"wp-caption alignnone\"><noscript><\/noscript><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-162300\" class=\"lazyload size-full wp-image-162300\" src=\"https:\/\/nftevening.com\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-09-at-20.53.47.jpg\" alt=\"H price chart (4h)\" width=\"2342\" height=\"1440\"\/><\/p>\n<p id=\"caption-attachment-162300\" class=\"wp-caption-text\">H price chart (4h). Source: TradingView<\/p>\n<\/div>\n<p><span style=\"font-weight: 400;\">The decline indicates that the market was reacting not only to the volume of H sold by the attacker, but also to the supply risk after 300 million H tokens were unauthorizedly minted on BSC. According to the post-mortem, H on BSC should be considered permanently compromised, meaning any decisions regarding the bridge, deposits, or token migration could further impact liquidity.<\/span><\/p>\n<h3><span class=\"ez-toc-section\" id=\"ZachXBT_Walks_Back_MM_Link\"\/><b>ZachXBT Walks Back MM Link<\/b><span class=\"ez-toc-section-end\"\/><\/h3>\n<p><span style=\"font-weight: 400;\">Humanity\u2019s incident quickly escalated beyond a technical exploit when ZachXBT, one of the most followed on-chain investigators in crypto, publicly questioned the project directly under their incident update. Initially, ZachXBT claimed that H had been \u201c<\/span><b>crime pumped<\/b><span style=\"font-weight: 400;\">\u201d for weeks despite lacking clear fundamentals, while demanding that Humanity disclose its active market-making agreements with an entity in Hong Kong.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Those remarks caused suspicions surrounding the hack to spread even faster, as H had just pumped significantly before crashing, right as it was about to enter a June unlock period. Several accounts subsequently questioned whether the private-key compromise could merely be an explanation for an intentional dump.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">However, ZachXBT later updated that after further analysis of the laundering flows, the market maker\/OTC activity and the private-key compromise appeared to be two independent issues. In another response, he stated that he had initially been suspicious due to the MM and OTC activity ahead of the unlock, but the evidence shared pointed in the opposite direction. ZachXBT also sarcastically noted that if the team had pumped the token for weeks only to get exploited right before the unlock, it was a rather expensive \u201c<\/span><b>karma.<\/b><span style=\"font-weight: 400;\">\u201c<\/span><\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">Update: After further analysis of the laundering it seems the sketchy MM \/ OTC &amp; private key compromise are independent of one another and not related.<\/p>\n<p>Kind of funny if the team was pumping the token for weeks only to have gotten rekt shortly before the upcoming unlock later\u2026<\/p>\n<p>\u2014 ZachXBT (@zachxbt) <a href=\"https:\/\/x.com\/zachxbt\/status\/2064227594632155390?ref_src=twsrc%5Etfw\" data-wpel-link=\"external\" target=\"_blank\" rel=\"nofollow external noopener noreferrer\">June 9, 2026<\/a><\/p>\n<\/blockquote>\n<p><span style=\"font-weight: 400;\">In addition, some posts also recalled the past of<\/span><b> founder Terence Kwok <\/b><span style=\"font-weight: 400;\">at Tink Labs, a Hong Kong travel-tech startup that raised significant funding before shutting down in 2019. Nevertheless, there is currently no public evidence linking these old controversies directly to the H hack.<\/span><\/p>\n<h3><span class=\"ez-toc-section\" id=\"June_Unlock_Keeps_Pressure_on_H\"\/><b>June Unlock Keeps Pressure on H<\/b><span class=\"ez-toc-section-end\"\/><\/h3>\n<p><span style=\"font-weight: 400;\">According to Tokenomics data, Humanity Protocol is scheduled to unlock approximately 266.47 million H tokens on June 25, 2026, equivalent to around 2.7% of the total supply and <\/span><b>9.6% of the market cap <\/b><span style=\"font-weight: 400;\">at the time of recording. This unlock amount is allocated to various groups, including investors and foundation-related parties.<\/span><\/p>\n<div id=\"attachment_162299\" style=\"width: 1922px\" class=\"wp-caption alignnone\"><noscript><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-162299\" class=\"size-full wp-image-162299\" src=\"https:\/\/nftevening.com\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-09-at-21.22.40.png\" alt=\"H Unlock Schedule Details\" width=\"1912\" height=\"936\"\/><\/noscript><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-162299\" class=\"lazyload size-full wp-image-162299\" src=\"https:\/\/nftevening.com\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-09-at-21.22.40.png\" alt=\"H Unlock Schedule Details\" width=\"1912\" height=\"936\"\/><\/p>\n<p id=\"caption-attachment-162299\" class=\"wp-caption-text\">H Unlock Schedule Details. Source: Tokenomics<\/p>\n<\/div>\n<p><span style=\"font-weight: 400;\">This unlocking milestone arrives right after a week of intense volatility for H, as the exploit sparked concerns regarding liquidity and supply on BSC. With an additional 266.47 million H set to unlock, investors will have to price in not only the damages from the hack but also the fresh supply pressure for the remainder of June.<\/span><\/p>\n<h3><span class=\"ez-toc-section\" id=\"BSC_Token_Remains_the_Key_Risk\"\/><b>BSC Token Remains the Key Risk<\/b><span class=\"ez-toc-section-end\"\/><\/h3>\n<p><span style=\"font-weight: 400;\">The greatest risk currently lies with H on the BNB Smart Chain. Humanity stated that the attacker still holds the ProxyAdmin of the BSC token, meaning the token on this chain can continue to be minted, paused, or drained. The project also views H on the BSC as permanently compromised.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The handling of this token portion will heavily dictate the ability to restore trust post-hack. Whether the bridge will be reopened, how exchanges handle deposits and withdrawals, whether related wallets are flagged, or whether the project opts for a token migration or holder support are all points the market will monitor closely. With H on BSC still out of control, how Humanity coordinates with exchanges and holders will determine the next developments of the incident.<\/span><\/p>\n<\/div>\n<p><a href=\"https:\/\/nftevening.com\/humanity-protocol-h-token-crashes-private-key-breach\/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=humanity-protocol-h-token-crashes-private-key-breach\" target=\"_blank\" rel=\"noopener\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Humanity Protocol\u2019s H token plummeted by over 80% on June 9 after the project confirmed an exploit involving compromised private keys, resulting in the theft of over $36 million in tokens and their dumping onto the market. In a post-mortem published on the evening of June 9, Humanity stated that the incident occurred between June [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":24125,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_publicize_message":"","jetpack_is_tweetstorm":false,"jetpack_publicize_feature_enabled":true},"categories":[9],"tags":[21],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"https:\/\/nftevening.com\/wp-content\/uploads\/2026\/06\/0906.jpg","jetpack_sharing_enabled":true,"jetpack_likes_enabled":true,"_links":{"self":[{"href":"https:\/\/nft.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/24124"}],"collection":[{"href":"https:\/\/nft.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/nft.runfyers.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/nft.runfyers.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/nft.runfyers.com\/index.php\/wp-json\/wp\/v2\/comments?post=24124"}],"version-history":[{"count":0,"href":"https:\/\/nft.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/24124\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/nft.runfyers.com\/index.php\/wp-json\/wp\/v2\/media\/24125"}],"wp:attachment":[{"href":"https:\/\/nft.runfyers.com\/index.php\/wp-json\/wp\/v2\/media?parent=24124"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/nft.runfyers.com\/index.php\/wp-json\/wp\/v2\/categories?post=24124"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/nft.runfyers.com\/index.php\/wp-json\/wp\/v2\/tags?post=24124"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}