Humanity Protocol Security Incident Escalates: More Than $31 Million Stolen From Related Addresses as Attacker Continues Selling H for ETH
Current public information shows the incident is still evolving rapidly. On-chain investigator ZachXBT said it is not yet possible to determine whether this was a typical external hack or whether malicious insider behavior may have been involved. Different sources have described the incident differently, and the relevant details still await official confirmation. Beyond the growing amount stolen, the on-chain sell-off has also quickly turned the incident from a pure security breach into a liquidity and market structure problem.
Based on developments disclosed so far, abnormal activity had already appeared in Humanity Protocol-related wallets at an earlier stage. Previous on-chain analysis said that more than 17 related wallets holding H were affected, with losses once exceeding $19 million; the latest monitoring now shows the scale of the theft has risen to more than $31 million. Additional follow-up on-chain reports also said the attacker minted another 1 billion H, implying the risk may not be limited to a wallet-level private key leak, but could also involve deeper permission control or token contract management issues. However, this has not yet been fully explained.
For the market, the attacker’s continued selling of H for ETH is directly increasing sell pressure on H and making any subsequent response by the project team more difficult. Key things to watch next include the scope of affected addresses, whether the token contract and related permissions have been further compromised, whether the project will implement freezing or suspension measures, and whether it will disclose a clearer attribution of the incident and a remediation plan.
## Why It Matters
The significance of this incident lies not only in the fact that losses have reached the tens of millions of dollars, but also in the fact that it simultaneously touches on on-chain security, token liquidity, and project governance. If the issue is only a single private key leak, the impact may be relatively contained; but if the reported “additional minting of H” is true, the nature of the incident could escalate from stolen assets to a token control risk, and the pricing logic in the secondary market would change accordingly.
For trading markets, the attacker’s continued conversion of H into ETH is essentially shifting the project’s native risk into public liquidity pools and trading pair depth. What the market will care more about is whether the current sell pressure comes from a one-off theft-driven dump or whether it will evolve into a longer-term loss of supply control. Because the official technical details have not yet been fully disclosed, the boundaries of the risk remain unclear.
## WEEX View
The core question is no longer simply whether funds were stolen, but whether H’s asset characteristics still hold. If only several operational or market-making addresses were compromised, then after CEX and on-chain liquidity absorb the sell-off, the market may still price it as a one-time risk event. But if the private key leak also exposes mint permissions, cross-chain bridge permissions, or failures in multisig control, then both the circulating supply and expectations around total supply for H could become distorted at the same time. Market makers would rapidly narrow their quotes and increase inventory protection, arbitrage capital would pull back, and the direct experience on the exchange side would quickly become “quotes exist, but there is no depth.”
A more immediate commercial conflict of interest is that the project team, market makers, early token holders, and secondary-market liquidity providers are no longer aligned. The project needs to stabilize the narrative and cut off permission-related risks as quickly as possible; market-making resources will prioritize protecting their own inventory; on-chain arbitrageurs will only watch for CEX/DEX price gaps to move liquidity; and whether Old Money stays in the market will depend on whether the team can provide a verifiable pause, recovery, snapshot, or restructuring plan. What is most worth watching next is not verbal explanations, but three hard indicators: whether a list of affected addresses and permissions is disclosed, whether the abnormal minting is formally confirmed, and whether major trading venues introduce deposit/withdrawal restrictions or adjust trading parameters.
## Timeline
- June 7, 2026: Humanity Protocol announced the launch of staking on Humanity Chain and introduced a reward pool of 30 million H.
- June 8, 2026: On-chain analysts reported that wallets related to or interacting with Humanity Protocol were attacked, affecting more than 17 wallets and causing losses of more than $19 million.
- June 9, 2026: Onchain Lens reported that the amount stolen from addresses linked to Humanity Protocol had exceeded $31 million, with the attacker continuously swapping H for ETH.
- June 9, 2026: Subsequent on-chain reports said the attacker minted an additional 1 billion H, suggesting the incident may have expanded from stolen assets to deeper permission control risks.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

New ARCA Limits: Monthly Billing Allowance for Each Monotributista by Category

The Macroeconomic Logic of the Artificial Intelligence Economy: K-shaped Recovery or a Historical Turning Point?

What Did Stripe See in OpenRouter for a $10 Billion Acquisition?

Bernstein says Core Scientific's AMD partnership could generate $14B over 15 years

The Federal Reserve is Never the Referee

Ripple takes center stage at Wyoming blockchain event

Forget ETF flows, Bitcoin's real threat is a hidden $39,900 liquidation wall

India Orders Removal of Offline Messaging App Bitchat

In-Depth Analysis of FWA: An Interesting Experiment Turning NFTs into "On-Chain Gacha"

Futu not under investigation as Hong Kong SFC freezes HK$125M client assets

Bitget Wallet turns cashback into Bitcoin and stocks

The Trust Trap of Open Protocols: Why Does x402 Need a Centralized Accountability Layer?

Welcome to the New Crypto World: This Time, the Losing Place is the Stock Market

Russia Issues Arrest Warrant for Telegram Founder Durov, Citing Abuse of Terrorism in Ukraine

Bitcoin Security: Is $1 Trillion Without Formal Defense a Fatal Break?

US 30-Year Treasury: Yield Reaches Highest Level Since 2007

Investment Plummeted 7.6% in the First Half of the Year with No Clear Signs of Recovery by Year-End

Why is ETH Price Continuing to Weaken Despite Wall Street's Interest in Ethereum?

Stocks Begin to Follow Cryptocurrency Market Rules: What Tokenization Changes

Why Did Bitcoin Initially Drop After the Fed Held Rates Steady?

The New Cold War is a Technological (Stock) War

$35.4 Million: A Report Card on El Salvador's 5-Year Bitcoin Experiment

Bernstein Analysis: Advertising Revenue Grows 27%, When Will Meta's Personal AI Monetize?

Bitcoin: A Major Advancement Could Simplify the Transition to the Post-Quantum Era

Taiwan Model and AI Agent: Insights from Audrey Tang at WebX2026

Crypto Market Accurately Prices China's Largest IPO 12 Days Early: CXMT's Opening Price Off by Just 1.4%?

Lazarus Moves 121.5 BTC: The North Korean Laundering Machine is Still Running

Telegram accused of leaving terrorist content online in Australian lawsuit

Bitcoin's Shallowest Bear Market: Market Silence, Spot Volume Hits New Low Since 2019





