Overview
- On June 8 and 9, malware on a Humanity Protocol developer’s laptop reportedly exposed seven private keys that allowed attackers to take bridge admin control, drain hot wallets, and mint hundreds of millions of H tokens.
- PeckShield and on‑chain analysis put June’s total losses at about $75.9 million across 40 incidents, with Humanity Protocol accounting for roughly $31 million to $36 million of that sum.
- The exploiter laundered proceeds across Ethereum, BNB Chain, Bitcoin, Solana and Hyperliquid and commingled funds with proceeds tied to the KelpDAO exploit, which makes tracing and recovery harder.
- Humanity Protocol paused affected bridge operations, published attacker wallet trackers, offered a bounty, engaged security firms and exchanges, and floated recovery options such as a possible 1:1 airdrop or new token.
- The event underscores a broader pattern this quarter: private‑key and endpoint compromises drive many large losses, Q2 2026 logged nearly $775 million in hack damage, and investigators have publicly downplayed an insider theory while reporting links to actors tied to the Lazarus Group.