Humanity-linked H token plunges after private-key leak, wallet drain and heavy selling

Humanity-linked H token plunges after private-key leak, wallet drain and heavy selling

Humanity says a June 8-9 attack came from malware on a developer machine that exposed seven private keys and production signing keys, leading to more than $36 million in stolen and sold H tokens.

ETH
BNB
GNO

Fact Check
Multiple independent sources corroborate the claim. The originating on-chain analyst @SpecterAnalyst reported wallets linked to Humanity Protocol being compromised; Wu Blockchain, PANews, CoinPost, and Odaily aggregated and reported the 17+ wallets, $19M+ losses, and ~85.6% H token price drop to ~$0.10. CoinPost specifically confirms the 85.6% 24h drop figure. Note an evolving loss estimate: Specter's initial post said $5M+, later reports cite $19M+, and a subsequent Odaily report cites $31M+ as the attack progressed.
Summary

Humanity Protocol said a June 8-9 security incident that sent its H token sharply lower was caused by malware on a developer machine and leaked production signing keys, not vulnerabilities in its smart contracts, bridge, token or Safe system. In its investigation, the project said the attacker gained full root access to one compromised device and obtained seven private keys, including an admin hot wallet private key and six Gnosis Safe signer keys. Humanity said more than $36 million in H on Ethereum and BNB Chain was stolen and sold after attackers transferred about 141.2 million H on Ethereum and minted 200 million H on BSC, while retaining ProxyAdmin control over the ETH bridge and the BNB Chain token. Deposits and withdrawals for affected bridge services were suspended as external security firms conduct forensics and the team prepares user recovery or compensation plans and token contract updates.

Terms & Concepts
  • Gnosis Safe signer keys: Private keys held by authorized signers of a multi-signature wallet, where several approvals are needed to execute transactions.
  • ProxyAdmin: An administrative control contract that can manage or upgrade certain proxy-based smart contract systems.
  • root access: Highest-level control over a device, allowing an attacker to control the system and extract sensitive data such as private keys.