Three keys out of six. That was all it took, on June 8, 2026, to seize control of Humanity Protocol and walk away with over $36 million. Token H crashed nearly 90% within hours. The absurd part is that the heist did not exploit a bug in the code. It exploited a laptop.
Humanity Protocol is no ordinary project. It is a layer-2 blockchain for decentralized identity, a rival to Sam Altman's World, which scans the palm of the hand instead of the iris using zero-knowledge proofs. It had raised $50 million at a $1.1 billion valuation, with Pantera Capital and Animoca Brands among its backers. A week earlier H was trading near its all-time high. Then, nothing.
What actually happened
The team's reconstruction is almost embarrassing in its simplicity. The laptop belonging to a member of the Humanity Foundation held multiple bridge admin keys, all on the same device. Once that device was compromised, the attacker held three of the six keys on Ethereum and three of the five on BNB Chain.
He transferred ownership of the contract to his own wallet, replaced the bridge code with a malicious version, drained 141.2 million H in a single transaction, and minted another 200 million tokens out of thin air. Most of the haul, around $23.7 million, was immediately converted into Ether and sold on decentralized exchanges such as KyberSwap and PancakeSwap.
We're aware of a security incident involving the compromise of private keys belonging to a member of the Humanity Foundation. The safety of our community is our top priority, and we want to be fully transparent about what we know.
— Humanity (@Humanityprot) June 9, 2026
As a precaution, please do NOT interact with the…
Founder Terence Kwok confirmed the breach on X, called community security the top priority, and urged users not to interact with the bridges while the team works with security firms and exchanges.
Here the story splits in two, and the second version is more uncomfortable than the first. On-chain investigator ZachXBT does not buy the team's account. He notes that all the H was sold on DEXs rather than centralized exchanges, an atypical pattern for a genuine theft, and points to the concentration of the supply in a few hands.
The “incident” seems possibly staged I am not buying the teams story it’s a convenient way for the active MM to have exited https://t.co/rLrVCaB01u pic.twitter.com/lDMkylj4jE
— ZachXBT (@zachxbt) June 9, 2026
"I am not buying the team's story," he wrote, calling it a convenient way for the active market maker to exit. He also asked the project to disclose any agreements with a market maker. The timing does not help: the hack landed just weeks before a token unlock scheduled for June 25. External theft or orchestrated exit, for H holders the outcome is identical. On the trust side, though, everything changes.
What really changes
The number that matters is not the amount, it is the pattern. In 2026, DeFi hacks have already topped $885 million in six months, and the biggest hits are not born from flawed code but from stolen keys. Drift lost around $285 million in April, Kelp DAO around $292 million that same month. Multisig in DeFi exists precisely to prevent all this: spreading keys across different people and devices, so that no single machine can move the funds on its own.
Keeping them on a single laptop defeats the entire purpose, just as we saw with crypto bridges under siege. It is the same weak human link that keeps showing up in the new AI-assisted exploits and in Anthropic's tests on smart contracts, and that weighs on tokens built around the identity and artificial intelligence narrative.
The frontier of risk has shifted. It is no longer about code quality. It is about the habits of whoever holds the keys. Code improves every year. Procedures, too often, do not.



