Humanity Protocol to tighten operational security after $36 million exploit

Founder Terence Kwok said compromised production keys on an employee laptop exposed admin hot wallet and multisig access, underscoring a broader shift toward phishing and staff-level crypto attacks.

Summary

Humanity Protocol is overhauling its cybersecurity focus after a June exploit drained $36 million in Humanity (H) tokens through a compromised employee laptop rather than a flaw in smart contract (self-executing blockchain code) code. Founder Terence Kwok said production keys from last year’s mainnet launch had been inadvertently backed up to the device, including admin hot wallet keys and a quorum of multisig (shared wallet approval system) owner keys across both chains. He said, “The hard lesson here is that operational security is as critical as smart-contract security, and we’re rebuilding accordingly.” The incident adds to evidence that attackers are increasingly targeting human behavior and internal operational weaknesses. Quantstamp linked the phishing campaign to North Korea-linked threat actors, saying a malicious attachment disguised as a token lockup schedule update from Bithumb installed malware and gave attackers remote access. The $36 million theft hit a token with a current market cap of roughly $211 million, according to CoinMarketCap. The breach came as phishing drove $508 million of crypto losses in the first quarter and wallet compromises led the second quarter with $807 million in losses, according to CertiK. Although total hack losses fell 46.8% year-on-year to $1.32 billion in the first half of 2026, CertiK said that comparison was distorted by the $1.4 billion Bybit hack in early 2025 and warned that North Korean actors remain a major threat.

Terms & Concepts
  • smart contract: Self-executing code on a blockchain
  • multisig: Shared wallet requiring multiple approvals
  • operational security: Protection of staff, devices and internal processes