Refreshed 3h ago· updates every 6h

Humanity Protocol (2026) — Crypto Hack

Exploited
Jun 9, 2026·
EthereumBNB Chain
Amount Stolen
$36.0M
141M H on Ethereum + 122B+ H minted on BSC
Recovered
$0

DPRK-linked attacker phished a director via email, installed remote-access malware, stole 7 multisig keys from one compromised laptop, seized ProxyAdmin on both chains, upgraded the bridge to a malicious contract, and drained 141M H on Ethereum and 122B+ H on BSC.

Summary

DPRK-linked attacker phished a director via email, installed remote-access malware, stole 7 multisig keys from one compromised laptop, seized ProxyAdmin on both chains, upgraded the bridge to a malicious contract, and drained 141M H on Ethereum and 122B+ H on BSC.

How It Was Compromised — Key Compromise via Phishing / Multisig Key Theft / ProxyAdmin Upgrade

Key CompromisePhishing / Multisig Key Theft / ProxyAdmin Upgrade

On June 9, 2026, a DPRK-linked attacker phished director Chong Yee Wai via an email impersonating a Korean exchange, installed remote-access malware (hncagent.exe signed with a Hancom certificate), and stole 7 multisig keys from one compromised laptop (3-of-6 ETH Safe, 3-of-5 BSC Safe). The attacker seized the ProxyAdmin on both chains, upgraded the bridge to a malicious contract, drained 141M H on Ethereum, and minted 122B+ H on BSC. The attacker sold the tokens on Uniswap and PancakeSwap, crashing the H price 89%. There was no timelock on the ProxyAdmin. Humanity Protocol was backed by Pantera and Jump Crypto.

Fund Flow & Laundering Analysis

Drained H tokens sold on Uniswap (Ethereum) and PancakeSwap (BSC), crashing the H price 89%. No recovery reported at time of writing.

Related Incidents

For educational and transparency purposes only. Not financial advice. Data compiled from public sources and may contain approximations.