Cryptocurrencies,  Security

Humanity Protocol Exploited for $36M

Multisig wallets were compromised, allowing attacker to mint $H tokens

Humanity Protocol said poorly protected multisignature wallet keys have been exploited to the tune of $36 million, driving the proof-of-humanity protocol’s $H token down as much as 85% today.

The hack was first spotted Monday evening by onchain analyst Specter, who initially reported that 17 wallets holding the $H token had been drained of $5 million. Several hours later that total had grown to hundreds of wallets, Specter reported.

Humanity protocol is a Worldcoin competitor, using privacy-preserving palm prints (instead of Worldcoin’s retina scans) to allow people to prove they are humans rather than bots or AI agents.

“We’ve detected a security incident involving the compromise of private keys belonging to a member of the Humanity Foundation,” Humanity Protocol founder and CEO Terence Kwok said on X. “As a precaution, please do not interact with the bridge or any liquidity pools until we confirm it’s safe. We’re already working with security experts and our exchange partners on resolution. We’re deeply sorry — protecting this community is our responsibility, and we’ll keep you updated every step of the way.”

Kwok told CoinDesk that one of the six multisig signature holders laptops apparently had several other signatures accidently backed up on it. That allowed hackers who compromised the laptop to get three of the six signatures needed to both seize control of token bridges and mint $H tokens. Multisig wallets are supposed to prevent this type of hack by requiring several people to act in concert to access and move funds.

Well-known crypto investigator and on-chain analyst ZachXBT cast some doubt on that explanation, saying “the ‘incident’ seems possibly staged I am not buying the teams story it’s a convenient way for the active MM [market maker] to have exited.”

He had earlier said that “it seems the H team was possibly working with an active MM given supply concentration.”

Others are taking the exploit as real. Crypto security firm Arkham refers to the “Humanity Protocol Exploiter” having stolen a little over $36 million in $H and having converted it into ether and BNB tokens.

It’s not the first or the biggest multisig exploit this year. On April 1, the Drift Protocol was exploited to the tune of $230 million in a multisig wallet attack. Stablecoin issuer Circle was sued for refusing to freeze stolen USDC tokens in the eight-hour period in which they could have been recovered.

 You May Also Like

Leo Jakobson, Modern Consensus editor-in-chief, is a New York-based journalist who has traveled the world writing about incentive travel. He has also covered consumer and employee engagement, small business, the East Coast side of the Internet boom and bust, and New York City crime, nightlife, and politics.