Humanity Says $36M H Token Exploit Stemmed From Keys on One Laptop

Humanity Protocol said an attacker stole more than $36 million in H tokens after compromising an employee laptop that held multiple bridge admin keys. The incident exposed a basic multisig security failure, allowing the attacker to take control of bridges on Ethereum and BNB Chain.

Humanity Says $36M H Token Exploit Stemmed From Keys on One Laptop

What happened?

Humanity Protocol said an attacker stole more than $36 million in H tokens after compromising an employee laptop that held multiple bridge admin keys. The incident exposed a basic multisig security failure, allowing the attacker to take control of bridges on Ethereum and BNB Chain.

Why it matters

Humanity has halted deposits and withdrawals on the affected bridges and said it is working with exchanges and police to recover funds. The project, which raised $20 million last year at a $1.1 billion valuation, also faces market scrutiny after H fell sharply during the attack and remained well below its reported pre-breach level.

Humanity Protocol said a hacker stole more than $36 million worth of its H token after compromising an employee laptop that contained multiple keys for the project’s token bridges. The bridges, which move H and other assets between blockchains, were controlled by multisignature wallets, but the compromised device held enough keys to meet the approval threshold on both Ethereum and BNB Chain.

The incident matters because multisig wallets are supposed to reduce single points of failure by spreading signing authority across different people and devices. In this case, Humanity said the keys were stored or backed up in one place, turning what should have been a layered security setup into a concentrated risk for a project backed by Pantera Capital and Jump Crypto.

On Ethereum, the attacker obtained three of six admin keys, transferred ownership to their own wallet, replaced bridge code with a malicious version and drained about 141 million H in one transaction, according to the project’s update cited by CoinDesk. On BNB Chain, the attacker used three of five keys and installed code with an unlimited mint function, creating about 200 million new H directly to their wallet.

Humanity founder Terence Kwok told CoinDesk the team had initially set up a multisig across four individuals, but the project suspects some keys were accidentally backed up to the compromised device during setup. He said Humanity uses a licensed custodian for most of its token treasury and MPC for operations treasury, while some contract multisig keys were set up together and then dispersed.

Humanity has halted deposits and withdrawals on the affected bridges and said it is working with exchanges and police to recover funds. The project, which raised $20 million last year at a $1.1 billion valuation, also faces market scrutiny after H fell sharply during the attack and remained well below its reported pre-breach level.

Source: CoinDesk

Keep exploring

Related stories

Bitget to Leave Japan and Close Remaining Positions by Year-End

Bitget to Leave Japan and Close Remaining Positions by Year-End

Bitget plans to exit the Japanese market and close all remaining positions by the end of the year. The move adds to ongoing shifts among crypto companies navigating Japan’s regulatory environment.

Read
State of Crypto countdown highlights key industry developments

State of Crypto countdown highlights key industry developments

CoinDesk’s State of Crypto coverage counts down recent developments shaping the crypto policy and market landscape. The report frames these changes as important for how companies and participants navigate the sector.

Read
Strategy Keeps STRC Dividend at 12%

Strategy Keeps STRC Dividend at 12%

Strategy said it is holding the dividend on its STRC preferred stock at 12%. The decision keeps the payout unchanged for investors in the company’s yield-focused security.

Read