Humanity Loses $31 Million, a Private Key Causes Token Price to Plunge 90%

Foresight NewsPublicado em 2026-06-09Última atualização em 2026-06-09

Resumo

On June 9th, the digital identity project Humanity Protocol suffered a major security breach resulting in over $31 million stolen from hundreds of wallets holding its H token. The attack was caused by the compromise of a private key belonging to a foundation member, leading the team to advise users against interacting with its bridge or liquidity pools. Following the incident, the price of the H token plummeted by over 90%, from around $0.70 to a low of $0.052, wiping out a significant portion of its market capitalization. The attacker allegedly minted 100 million new H tokens and began selling them for BNB. Humanity Protocol, founded in 2024, aimed to verify human users through palm-print biometrics and zero-knowledge proofs on Polygon CDK. Despite raising $50 million across two funding rounds and achieving a unicorn valuation, the project faced prior controversies. Shortly after its June 2025 token launch, reports emerged that only about 1 million of its 9 million registered IDs had completed biometric verification, suggesting 88% might be bots. Furthermore, allegations surfaced that the project might be a rebranded "shell" of a Chinese access control company, raising concerns about data privacy and authenticity. The project's founder, Terence Kwok, has a controversial business history. His previous venture, Tink Labs, burned through $170 million in funding before collapsing in 2020. The breach highlights the persistent critical risk of private key management in crypto....


Author: ChandlerZ, Foresight News


On June 9, according to on-chain analyst Specter's monitoring, wallets that have interacted with the digital identity project Humanity are under sustained attack. Hundreds of addresses holding H tokens have been compromised so far, with total losses exceeding $31 million. Approximately $9 million has been swapped for ETH, with another $9.9 million still held in the form of H tokens.



Humanity founder Terence Kwok subsequently confirmed the security incident, involving the leakage of a private key belonging to a foundation member. As a precaution, he advised users to temporarily refrain from interacting with the Humanity cross-chain bridge or any liquidity pools until further safety confirmation. The team is working with security experts and exchange partners to handle the situation and will continue to update the community on the progress.



The price of the H token plummeted from around 0.7 USDT to a low of 0.052 USDT, a drop of over 90% within 24 hours. At the time of writing, H is trading at 0.1368301 USDT, with its market capitalization falling from around $2 billion to approximately $35.7 million.


As of 11:00 AM on June 9, the attacker is suspected of minting 100 million new Humanity Protocol H tokens and is currently selling them off for BNB.




A Project That Never Truly 'Proved Humanity'


Humanity Protocol was founded in 2024, positioning itself as a decentralized digital identity network. Its core selling point was using palm print biometrics and zero-knowledge proofs to verify whether a user is a real human. Built on Polygon CDK (zkEVM), the project claimed to solve issues like Sybil attacks, fake accounts, and AI-generated identities without exposing personal information.


This narrative attracted significant capital attention in 2024. Humanity Protocol completed two rounds of funding totaling $50 million. A $30 million seed round at a $1 billion valuation included investors like Kingsway Capital, Animoca Brands, Blockchain.com, and Shima Capital. In January 2025, another $20 million round led by Pantera Capital and Jump Crypto raised the valuation to $1.1 billion.


The Humanity Foundation also assembled numerous well-known figures, led by Animoca Brands Chairman Yat Siu. Co-founders included Mario Nawfal, founder of the international blockchain consulting firm, and Yeewai Chong, a senior investment expert from Morgan Stanley and Ortus Capital.


On June 25, 2025, the H token launched via a Fairdrop mechanism, touted as the first-ever token distribution in Web3 history exclusively to verified humans. However, two days after launch, DL News reported leaked conversations from the founder. In the dialogue, Kwok admitted that out of the 9 million Human IDs created on the network, only about 1 million had completed biometric verification, implying that up to 88% of users might be bots.


Furthermore, according to revelations from X platform users SCoin (@ LianFang _) and AB Kuai . Dong (@_FOR AB ), Humanity Protocol (H) might be a "repackaged domestic project," with APP code material libraries still containing images from Shenzhen access control manufacturer Zhangteng Information, raising doubts about its authenticity. Netizens claimed much of its social media hype was self-generated by project-side accounts, with actual user participation questionable.



AB Kuai.Dong stated that those who previously completed verification with Humanity should be cautious. Zhangteng Information is allegedly backed by a Shanghai-based outsourcing company specializing in full identity recognition outsourcing. Additionally, whistleblower SCoin claimed the project collected large amounts of users' palm print data, raising privacy and security concerns.


This was fatal for a project whose core value proposition was "proving humanity." The H token fell over 61% within two days of launch, from around $0.05 to a low of $0.018.


The Founder's Previous Unicorn Burned Through $170 Million


Terence Kwok's personal resume added a footnote of risk to the project. In 2012, 20-year-old Terence Kwok dropped out of the University of Chicago and, inspired by a $900 roaming bill received during a trip, founded Tink Labs. The company provided free smartphones (branded Handy) to hotel rooms for guests to use abroad, replacing expensive roaming fees. This concept once captivated the capital market. Tink Labs raised $170 million successively from Foxconn, SoftBank, Innovation Works, and the founder of Meitu, reaching a valuation of $1.5 billion and becoming Hong Kong's first unicorn. At its peak, Handy devices covered 600,000 hotel rooms across 82 countries.


However, Kwok's aggressive expansion strategy soon met reality. Global roaming fees continued to decline, hotels were unwilling to pay for Handy devices, and the company began losing money from 2017. According to the Financial Times, SoftBank cut off funding for a key project after discovering that Tink Labs might have diverted funds from its Japanese joint venture to other loss-making markets. In July 2019, over 100 employees from its European, Middle Eastern, and African offices did not receive their salaries. Laid-off employees smeared cake on the walls and floors as they left the Oxford office. On August 1, Tink Labs officially shut down, entering bankruptcy proceedings in January 2020. A former HR director told the FT that Kwok only cared about "making money," and the entire $170 million investment evaporated.


Six years later, Kwok returned to the market with Humanity Protocol, once again securing a unicorn valuation from Pantera Capital and Jump Crypto.


Private Key Management: An Old Problem, a New Cost


Based on current information, this attack does not involve smart contract vulnerabilities or protocol-level security flaws. The attacker obtained a private key belonging to a foundation member, representing a failure in the most traditional security management.


The security landscape for the crypto industry in 2026 was already severe. According to CCN statistics, losses from DeFi hacks in the first four months of 2026 exceeded $1 billion, with most stolen funds still unrecovered. The $286 million attack on Drift Protocol on April 1 was the largest single incident of the year. Attackers are increasingly targeting validators, RPC nodes, and governance systems, not just smart contract vulnerabilities. However, private key leaks remain one of the most devastating attack types because they bypass all on-chain security mechanisms, directly granting control of assets.


For a project already burdened with the controversy of 88% bot users and a token down over 90% from its peak, a $31 million private key leak could be the final blow to trust. As of the time of writing, Kwok stated in his declaration that the team is working with security experts and exchange partners to handle the situation but did not mention any user compensation plan or explain why the foundation member's private key lacked basic protections like multi-signature or hardware isolation.

Perguntas relacionadas

QWhat was the total estimated loss in the Humanity Protocol security incident, and what were the main assets stolen?

AThe total estimated loss exceeded $31 million. Approximately $9 million was converted to ETH, and about $9.9 million remained in the form of H tokens.

QAccording to the article, what was the specific cause of the Humanity Protocol security breach?

AThe security breach was caused by the private key of a foundation member being compromised.

QWhat was a major controversy regarding Humanity Protocol's user verification process that was reported before the hack?

AA leaked conversation revealed that out of 9 million created Human IDs, only about 1 million had completed biometric verification, suggesting around 88% of users might be bots.

QWhat previous venture of Humanity Protocol's founder, Terence Kwok, failed after burning through $170 million in funding?

ATerence Kwok's previous venture was Tink Labs (branded Handy), which provided free smartphones to hotel rooms and failed after reportedly burning through $170 million in funding.

QHow did the article characterize the nature of the attack on Humanity Protocol in relation to common DeFi security failures?

AThe article characterized the attack not as a smart contract vulnerability, but as a traditional security management failure involving private key compromise, bypassing all on-chain security mechanisms.

Leituras Relacionadas

human.tech Launches Clean SDK for Privacy-First Web3 Apps

human.tech has launched the Clean SDK, a toolkit enabling developers to build privacy-first Web3 applications with transparent accountability. Released alongside Aztec's version 5, the SDK provides components for integrating zero-knowledge identity verification, sanctions screening, and private transactions, without developers handling sensitive user data or building compliance infrastructure from scratch. It uses zero-knowledge proofs and programmable verification to allow apps to confirm user legitimacy and sanctions compliance while keeping identities confidential. The first application built on the SDK, Shield, a privacy bridge to Aztec, also launched. It allows users to transfer assets privately while proving a unique human is behind each transfer and that funds have passed sanctions checks, as verified by a May 2026 audit. The SDK offers three core verification techniques: Proof of Innocence (sanctions screening against 23 sources), Proof of Personhood (simpler verification via Human Passport), and Proof of Clean Hands (higher-assurance zero-knowledge government ID checks). This allows apps to authenticate users and transactions without exposing personal data. Designed for Aztec builders, the SDK lets developers add programmable privacy to decentralized apps, eliminating the need to create their own verification and ZK infrastructure. Shield demonstrates its practical use for private bridges, but the SDK aims to enable a wider ecosystem of private, accountable financial apps and services. The launch addresses growing demand for infrastructure that balances privacy and accountability. The SDK avoids traditional identity databases, storing encrypted data off-chain, screening at both entry and exit points, and including a gated disclosure mechanism for legal requests. human.tech's products, including the Clean SDK, focus on using zero-knowledge technology to enable verifiable personhood and privacy in digital systems.

TheNewsCryptoHá 20m

human.tech Launches Clean SDK for Privacy-First Web3 Apps

TheNewsCryptoHá 20m

Unlocking $100 Million in Liquidity? Pump.fun's New Policy Tests the 5-Minute Pump Technique

Pump.fun, a popular meme coin launchpad, has introduced a new standard mechanism called BOOST. It aims to address a significant capital efficiency issue: when a newly launched token graduates from its initial bonding curve to a liquidity pool (LP), roughly 20% of its liquidity becomes permanently locked as "dead liquidity," estimated to waste over $100 million annually. Instead of locking these funds permanently, BOOST repurposes them. Upon a token's migration, approximately 20% of the settlement funds (e.g., 17.6 SOL or ~$2516 USDC) are used to buy back the token on the open market over a 5-minute period via a Time-Weighted Average Price (TWAP) mechanism. All purchased tokens are immediately burned. This creates a brief, systematic buy pressure immediately after migration, potentially generating a short-term price surge ("pump") while permanently reducing the token's circulating supply. The goal is to enhance the immediate post-launch trading experience, potentially increasing trader retention and sustainable protocol revenue, which funds ongoing token buybacks. However, concerns exist that this artificial 5-minute boost could lower the barrier for launching low-quality tokens and lead to steeper price crashes once the buy pressure stops, if followed by large sell-offs. The feature automatically applies to tokens migrating after July 21, 2024, but not to previously migrated tokens or those launched via the Mayhem AI Agent lab.

marsbitHá 27m

Unlocking $100 Million in Liquidity? Pump.fun's New Policy Tests the 5-Minute Pump Technique

marsbitHá 27m

Podcast Notes | Conversation with GSR Asset Management Head: To Determine if This Crypto Rally is Real, Just Watch the Lending Rates on Aave

Podcast Summary: Dialogue with GSR's Head of Asset Management: To Determine if This Crypto Rally is Real, Just Check Lending Rates on Aave Andy Baehr, Managing Director of Asset Management at GSR, discusses the current crypto market, characterizing it as stuck in a state of "ambivalence" with short-lived, unsustainable rallies. He outlines a simple framework: the market moves between "ambivalence" and "conviction" (sustained upward momentum). Currently, every rally resembles a single-stage rocket booster that quickly fizzles out. Baehr identifies three key signals to watch: 1) DeFi lending rates, 2) the potential passage of the CLARITY Act, and 3) the market forming a consensus on the "Fed hawkish peak." He emphasizes that the most immediate indicator for the sustainability of the recent CPI-triggered rally is the USDC borrowing rate on Aave, currently around 3.75%—close to U.S. Treasury yields. The absence of a credit spread indicates low leverage demand and a lack of market energy. He explains that a healthy, sustained rally requires layered buying pressure. Last year's rally progressed from an ETH short squeeze to crypto-native trader influx and finally to ETF inflows. Currently, this structure is missing. Other potential structural buyers like Digital Asset Treasury (DAT) companies are absent, and ETF flows have proven transient. Baehr notes that while small-cap crypto tokens outperformed large caps in Q2—a potential sign of capitation in major assets—capital is also flowing to more exciting opportunities like AI stocks and tech IPOs, leaving crypto sidelined. Regarding DeFi, he highlights that platforms like Aave provide a clear, real-time signal of leverage demand through their supply/demand-driven interest rates. A significant, sustained rate increase would signal genuine market conviction. He also observes the quiet emergence of fixed-income-like products and vaults in DeFi. On regulation, the probability of the CLARITY Act passing before the August 7th deadline has dropped linearly from 75% to below 40% on Polymarket. Baehr suggests its passage would be treated as a bullish surprise, a potent driver for price movement. However, political hurdles, including ethical clause debates and disclosures about the First Family's crypto profits, remain significant obstacles. Ultimately, the market awaits clarity on the Fed's terminal rate under Chair Warsh. Until the "Fed Solstice"—the point where the market collectively understands the peak of hawkish policy—sustained conviction will be difficult to achieve.

marsbitHá 58m

Podcast Notes | Conversation with GSR Asset Management Head: To Determine if This Crypto Rally is Real, Just Watch the Lending Rates on Aave

marsbitHá 58m

Trading

Spot
活动图片