Humanity Loses $31 Million in Attack, Token Price Plummets 90% Due to a Single Private Key

marsbit2026-06-09 tarihinde yayınlandı2026-06-09 tarihinde güncellendi

Özet

On June 9th, the digital identity project Humanity Protocol suffered a major security breach resulting in over $31 million in losses. According to on-chain analyst Specter, hundreds of wallets holding the project's H token were drained. The attack was confirmed by founder Terence Kwok to be caused by the compromise of a foundation member's private key. As a precaution, users are advised to avoid interacting with Humanity's cross-chain bridge or liquidity pools. The incident caused the H token price to crash over 90%, from around $0.70 to a low of $0.052, wiping its market cap from $2 billion to approximately $35.7 million. The attacker allegedly minted 100 million new H tokens and is selling them for BNB. This breach adds to existing controversies surrounding Humanity Protocol. Founded in 2024, it aimed to verify human users via palm-print biometrics and zero-knowledge proofs. However, a leaked conversation in 2025 revealed that only about 1 million of its 9 million claimed Human IDs had completed biometric verification, suggesting 88% might be bots. Furthermore, the project has faced allegations of being a repackaged product from a Chinese access control vendor, raising privacy and authenticity concerns. Founder Terence Kwok's previous venture, Tink Labs, a hotel smartphone startup that raised $170 million, failed and entered bankruptcy in 2020 after burning through its funding. The current attack highlights the persistent critical issue of private key management in cryp...

On June 9th, according to on-chain analyst Specter's monitoring, wallets that have interacted with the digital identity project Humanity are under sustained attack.

So far, hundreds of addresses holding H tokens have been stolen, with total losses exceeding $31 million. Approximately $9 million has already been converted to ETH, and about $9.9 million remains in the form of H tokens.

Humanity founder Terence Kwok later confirmed the security incident, which involved the leak of a private key belonging to a foundation member.

As a precautionary measure, he advised users to temporarily avoid interacting with the Humanity cross-chain bridge or any liquidity pools until further safety confirmation. The team is working with security experts and exchange partners to address the issue and will continue to update the community on progress.

The H token price plummeted from around 0.7 USDT to a low of 0.052 USDT, a drop of over 90% in 24 hours. As of the time of writing, H is trading at 0.1368301 USDT, with its market capitalization falling from around $2 billion to approximately $35.7 million.

As of 11:00 on June 9th, the attacker allegedly newly minted 100 million Humanity Protocol H tokens and is dumping them in exchange for BNB.

A Project That Hasn't Truly "Proven Humanity"

Humanity Protocol was founded in 2024, positioning itself as a decentralized digital identity network. Its core selling point is verifying users as real humans using palm print biometrics and zero-knowledge proofs. The project is built on Polygon CDK (zkEVM), claiming to solve issues like Sybil attacks, fake accounts, and AI-generated identities without exposing personal information.

This narrative attracted significant capital attention in 2024. Humanity Protocol completed two rounds of funding totaling $50 million. A $30 million seed round valued the project at $1 billion, with investors including Kingsway Capital, Animoca Brands, Blockchain.com, and Shima Capital, among others.

In January 2025, a round led by Pantera Capital and Jump Crypto raised $20 million, increasing the valuation to $1.1 billion.

The Humanity Foundation also gathered many prominent figures, led by Animoca Brands Chairman Yat Siu. Co-founders include Mario Nawfal, founder of the international blockchain consulting firm, and Yeewai Chong, a senior investment expert from Morgan Stanley and Ortus Capital.

On June 25, 2025, the H token launched via a Fairdrop mechanism, touted as the first token distribution in Web 3.0 history exclusively for verified real humans. However, two days after launch, DL News reported leaked conversations from the founder. Kwok admitted in the dialogue that out of the 9 million Human IDs created on the network, only about 1 million had completed biometric verification, meaning up to 88% of users could be bots.

Furthermore, according to claims by users like SCoin(@ LianFang _) and AB Kuai . Dong(@_FOR AB) on platform X, Humanity Protocol (H) might be a "re-packaged Chinese project," with its app's code asset library still containing images from the Shenzhen access control manufacturer Zhang Teng Information, raising authenticity doubts. Netizens alleged that its social media hype was largely orchestrated by the project's own sock puppet accounts, with actual user engagement being questionable.

AB Kuai.Dong warned that those who previously did verification with Humanity should be careful. Zhang Teng Information is backed by a Shanghai outsourcing company specializing in full-service identity recognition outsourcing. Additionally, whistleblower SCoin claimed the project collected large amounts of user palm print information, raising privacy and security concerns.

This was fatal for a project whose core value proposition is "proving humanity." The H token fell over 61% within two days of launch, from around $0.05 to a low of $0.018.

The Founder's Previous Unicorn Burned Through $170 Million

Terence Kwok's personal history adds a risk footnote to this project. In 2012, 20-year-old Terence Kwok dropped out of the University of Chicago. After receiving a $900 roaming bill during a trip, he founded Tink Labs, which provided free smartphones (branded Handy) in hotel rooms for guests to use abroad to avoid high roaming fees.

This concept once captivated the capital market. Tink Labs raised $170 million in total from Foxconn, SoftBank, Innovation Works, and the founder of Meitu, reaching a valuation of $1.5 billion and becoming Hong Kong's first unicorn. At its peak, Handy devices covered 600,000 hotel rooms across 82 countries.

However, Kwok's aggressive expansion strategy soon met reality. Global roaming fees continued to fall, hotels were unwilling to pay for Handy devices, and the company began losing money from 2017. According to the Financial Times, after discovering that Tink Labs might have diverted funds from its Japanese joint venture to other loss-making markets, SoftBank cut off funding for the key project.

In July 2019, over 100 employees in European, Middle Eastern, and African offices did not receive their salaries. Laid-off employees smeared cake on the walls and floors as they left the Oxford office. On August 1st, Tink Labs officially shut down, entering bankruptcy liquidation in January 2020. A former HR executive told the FT that Kwok only cared about "making money," and the entire $170 million investment was lost.

Six years later, Kwok returned to the market with Humanity Protocol, securing a unicorn valuation once again from Pantera Capital and Jump Crypto.

Private Key Management: An Old Problem, A New Price

From the current information, this attack does not involve smart contract vulnerabilities or protocol-level security flaws. The attacker obtained a private key from a foundation member, representing a failure of the most traditional security management.

The security situation in the crypto industry was already severe in 2026. According to CCN statistics, losses from DeFi hacks in the first four months of 2026 exceeded $1 billion, with most stolen funds still unrecovered. The $286 million attack on Drift Protocol on April 1st was the single largest event this year.

Attackers are increasingly targeting validators, RPC nodes, and governance systems, not just smart contract vulnerabilities. However, private key leaks remain one of the most devastating attack types, as they bypass all on-chain security mechanisms and directly obtain asset control.

For a project already burdened with the controversy of 88% bot users and a token down over 90% from its high, a $31 million private key leak could be the final blow to trust.

As of the time of writing, Kwok stated in a declaration that the team is working with security experts and exchange partners, but did not mention any user compensation plan or explain why the foundation member's private key lacked basic protections like multi-signature or hardware isolation.

İlgili Sorular

QWhat is the main cause of the $31 million hack in the Humanity project according to the article?

AThe hack was caused by the compromise of a private key belonging to a foundation member, leading to unauthorized access and asset theft, not a smart contract vulnerability.

QHow did the price of the H token react immediately after the security incident?

AThe price of the H token plummeted from around $0.7 USDT to a low of $0.052 USDT, representing a drop of over 90% within 24 hours.

QWhat was a major controversy surrounding the Humanity Protocol's user verification prior to this hack?

AA leaked conversation revealed that only about 1 million out of 9 million created Human IDs had completed biometric verification, suggesting that up to 88% of the users might have been bots.

QWhat is the background of Humanity founder Terence Kwok's previous venture, Tink Labs?

ATerence Kwok's previous venture, Tink Labs (which provided Handy smartphones in hotel rooms), raised $170 million and reached a $1.5 billion valuation before collapsing in 2019, with the investment reportedly completely lost.

QWhat action did the attacker reportedly take with the stolen assets, and what precaution did the founder advise users to take?

AThe attacker reportedly converted about $9 million into ETH and was selling newly minted tokens for BNB. The founder advised users to temporarily avoid interacting with the Humanity cross-chain bridge or any liquidity pools until safety is confirmed.

İlgili Okumalar

U.S. Tech Momentum Stocks Post Largest Single-Day Gain Ever, But Is the Plunge Over?

US tech momentum stocks staged a sharp rebound on Tuesday (July 21st). Morgan Stanley's TMT Momentum Factor surged over 12%, marking its largest single-day gain on record, exceeding even peaks from the 2000 dot-com bubble. Key momentum indices from Goldman Sachs also posted their strongest daily performances in years. The rally was led by semiconductors, with the Philadelphia Semiconductor Index jumping 4.6%. This rebound followed three consecutive down days and a cumulative 33% plunge in momentum stocks, one of the steepest drawdowns since the dot-com era. Analysts attribute the surge largely to a short squeeze. Heavy selling had pushed high-beta momentum stocks into deeply oversold territory, forcing many short sellers, particularly in Asia, to cover their positions, creating a self-reinforcing buying spiral. However, the rebound's internals appear weak. Trading volume was notably low, and advancing stocks still lagged decliners on the S&P 500, indicating a narrow, concentrated rally rather than broad market participation. Diverging views emerge on the outlook. BTIG warns the bounce has hit key resistance and recommends selling into strength, citing extreme volatility and historical parallels to past market tops. Conversely, Goldman Sachs and UBS believe the momentum unwind is nearing its end, suggesting it may be time to gradually add exposure, as positioning has been significantly reduced. They caution, however, that high volatility warrants a measured approach, potentially using defined-risk strategies. The upcoming earnings season, particularly reports from major tech firms like Alphabet, is seen as a critical test for the rally's sustainability. Simultaneously, bond markets flashed a warning, with yields rising partly due to spiking oil prices. Analysts note that if long-term Treasury yields break decisively higher, it could pose a significant headwind for equities, especially growth stocks.

marsbit5 dk önce

U.S. Tech Momentum Stocks Post Largest Single-Day Gain Ever, But Is the Plunge Over?

marsbit5 dk önce

U.S. Tech Momentum Stocks Record Largest Single-Day Gain Ever, but Has the Rout Ended?

U.S. tech momentum stocks staged a dramatic rebound on Tuesday, July 21st. Key momentum indices like the Morgan Stanley TMT Momentum Factor and Goldman Sachs' High Beta Momentum Long Index posted historic or near-historic single-day gains, fueled largely by semiconductor stocks. This sharp rally followed a severe three-day sell-off that saw momentum stocks plunge 33%, marking one of the steepest pullbacks since the dot-com bubble. Analysts attribute the bounce primarily to a short squeeze, as forced covering from over-leveraged traders, particularly in Asia, created a buying spiral. However, the rally's health is questioned due to weak market breadth—overall trading volume was low, and decliners outnumbered advancers in the S&P 500 despite the index's gain—suggesting a narrow, concentrated surge rather than broad recovery. Opinions on the sustainability diverge. BTIG strategists warn the rebound has hit key resistance levels, citing extreme volatility and historic stock dispersion as signs of an ongoing broader correction, and recommend selling into strength. Conversely, Goldman Sachs and UBS view the aggressive momentum unwinding as nearing its end, noting reduced positioning and a lack of new fundamental catalysts. They suggest the sell-off presents a selective opportunity to add exposure, albeit cautiously and gradually using defined-risk strategies. The immediate trajectory hinges on the ongoing earnings season, with market focus on Alphabet's capital expenditure guidance for AI investment clarity. Meanwhile, bond markets present a risk, with rising Treasury yields—potentially heading toward 5.5%—and widening credit spreads for mega-cap tech companies posing a threat to equity valuations. The combination of technical factors, earnings results, and macro conditions leaves the durability of the rebound in doubt.

链捕手8 dk önce

U.S. Tech Momentum Stocks Record Largest Single-Day Gain Ever, but Has the Rout Ended?

链捕手8 dk önce

Long-Divided Must Unite, Long-United Must Divide: When L1 Becomes Its Own Rollup, What Is Ethereum's Endgame?

"The Inevitable Cycle: When L1 Becomes Its Own Rollup – What is Ethereum's Endgame?" For years, the Ethereum community grappled with concerns that L2s were fragmenting the ecosystem and eroding L1's value. While L2s provided cheaper execution, they also splintered liquidity and the unified user experience of a single chain. This has prompted a fundamental reassessment of the relationship between L1 and L2. Ethereum's roadmap is evolving. The "Scale" initiative merges L1 and L2 expansion into a holistic framework. L1 itself is advancing with higher gas limits, statelessness, and zkEVM verification, no longer content to be just a low-throughput settlement layer. Consequently, the primary value proposition of L2s is shifting from merely providing cheap blockspace to offering L1 cannot easily provide: application-specific optimizations, privacy features, and flexible governance models. L2s are becoming a spectrum of execution environments with varying degrees of security inheritance from Ethereum. A critical challenge in this multi-chain future is interoperability. The vision is to make Ethereum "feel like one chain again." This relies on advancements in native account abstraction (like EIP-7702) and intent-based architectures (Open Intents Framework), where users declare desired outcomes, and solvers handle the complex cross-chain execution. Furthermore, shortening Ethereum's finality time from minutes to seconds is crucial, as it underpins trust between chains for bridges, stablecoins, and cross-chain applications. Perhaps the most provocative idea is that Ethereum L1 itself could become a form of "its own Rollup." As zkEVM and proof systems mature, high-performance nodes could execute transactions and generate validity proofs. Regular validators would then verify these proofs instead of re-executing all transactions. This blurs the traditional L1/L2 hierarchy, making "Rollup" more of a general execution-verification architecture. Native Rollup aims to integrate L2 validation more directly into the Ethereum protocol, allowing L2s to inherit L1's security more fully and move away from reliance on security councils. In the end, L2s are not destined to replace L1 or be made obsolete by it. The likely future is a unified system where diverse execution environments—each optimized for specific use cases like DeFi, gaming, or privacy—coexist. They will share a common foundation of security, liquidity, and verifiable state, seamlessly connected to restore a cohesive user experience. The next phase for Ethereum is not just about scaling through separation, but about intelligently reintegrating what was separated back into a coherent whole.

链捕手24 dk önce

Long-Divided Must Unite, Long-United Must Divide: When L1 Becomes Its Own Rollup, What Is Ethereum's Endgame?

链捕手24 dk önce

Agent Race Ends, Super Workbench Takes Over

The era of fragmented AI agents is ending. Over the past month, China's tech giants—Tencent, Alibaba, and ByteDance—have simultaneously shifted strategy: instead of launching new, standalone AI agents, they are consolidating their various agent projects into unified "super workbenches." Tencent integrated its QClaw teams into WorkBuddy, a strategic product hailed as a potential third flagship after QQ and WeChat. Alibaba is merging its QoderWork, Wukong, and MuleRun agents into a new "Qianwen Office" platform under DingTalk's leadership. ByteDance rebranded its TRAE SOLO coding agent to TRAE Work, signaling a broader focus on workflow collaboration. This convergence marks a pivotal industry consensus. The initial exploration phase, where companies rapidly built numerous overlapping agents for different scenarios, proved costly and inefficient. With open-source tools eroding technical barriers, competition has shifted from agent creation to resource consolidation and cost control. Historically, platform wars are won not by creating more products, but by simplifying them—as seen with browsers unifying web access and super-apps consolidating services. Now, the "super workbench" aims to become the unified AI entry point for work. This reflects a deeper market realization: the primary audience for AI is no longer just programmers (a market in the tens of millions) but all knowledge workers (a market of billions). The real opportunity lies in augmenting everyday tasks—managing emails, documents, data, and meetings—across the entire workday. The core battleground is becoming control over the primary AI entry point that employees use daily. Tencent's WorkBuddy leverages WeChat and Tencent Docs; Alibaba's Qianwen Office taps into DingTalk's organizational data; ByteDance's TRAE Work integrates with Feishu's workflows. Whoever owns this "super workbench" gains strategic control over orchestrating enterprise data and APIs. This shift is redefining enterprise software. Traditional SaaS applications, valued for their user interfaces, will recede into the background. Their core functionalities will be exposed as standardized "Skills" or APIs for the super workbench's agents to invoke. Software value will shift from selling user seats to charging based on API calls and outcomes delivered. The evolution of agents is moving through clear stages: first as novel standalone products, then as consolidated primary work entry points, and finally as pervasive, invisible capabilities embedded into the digital fabric. The recent moves by major tech firms signal the transition from the first stage into the second, accelerating toward the third. In the end, the most successful agent technology may become invisible—like electricity or the HTTP protocol—a fundamental, unnamed infrastructure powering work itself.

marsbit51 dk önce

Agent Race Ends, Super Workbench Takes Over

marsbit51 dk önce

İşlemler

Spot
活动图片