Humanity Protocol exploited for $36M via compromised employee laptop; attackers seized bridges and minted tokens, crashing the token 73%.
Security & Exploits ·
Humanity Protocol's H token collapsed more than 80% after attackers exploited a compromised employee laptop to seize control of bridge infrastructure and drain approximately $36 million across Ethereum and BNB Chain. The attackers gained access to three of six Gnosis Safe keys on Ethereum and three of five on BSC, enabling them to drain roughly 141.2 million H tokens and mint an additional 200 million H through malicious contract upgrades. The token plummeted from $0.73 Monday to $0.20 by Tuesday, representing a 73% single-day decline.
Security analysts characterized the incident as an operational security failure rather than a smart-contract vulnerability. The attacker leveraged admin-level access tied to a Humanity Foundation member to abuse the mint function and consolidate stolen and newly created tokens across multiple wallets after exchanging them for ETH and BNB. The breach reflects a structural flaw: a single key granted both fund control and the ability to modify protocol rules.
The incident ranks among 2026's largest DeFi exploits, occurring within a year in which protocols have already sustained hundreds of millions in losses to similar attacks. Humanity Protocol has halted bridge deposits and withdrawals while coordinating with exchanges and police on recovery efforts. Whether the attackers retain the ability to further exploit the protocol or fully liquidate remaining holdings remains unconfirmed.