Humanity Protocol tightens ops security after $36M hack
Attackers accessed production keys on a compromised employee laptop and withdrew $36 million in H tokens; the protocol plans to rebuild operational security.
Humanity Protocol was breached last month when attackers used production keys stored on a compromised employee laptop to steal roughly $36 million in H tokens. The keys were backed up to the device during the protocol’s mainnet launch last year and included admin hot wallet keys and a quorum of multisig owner keys across both chains, allowing the attackers to move funds once they had access.
Investigators traced the intrusion to a phishing email that carried a malicious attachment disguised as a token lockup schedule update from a South Korean exchange. The attachment installed malware that provided remote access to the laptop. Blockchain security firm Quantstamp linked the malicious file to threat actors associated with North Korea.
Founder Terence Kwok described the breach: “The hard lesson here is that operational security is as critical as smart-contract security, and we’re rebuilding accordingly.” Kwok added the team is reviewing key storage and access controls to reduce the risk of similar failures.
The H token’s market capitalization is about $211 million. Humanity Protocol has not published a detailed remediation plan or disclosed whether any of the stolen funds have been recovered.
Industry data show phishing and wallet compromises accounted for large losses in the first half of 2026. CertiK data put phishing-related losses at about $508 million in the first quarter and listed wallet compromises as the largest source of second-quarter losses at $807 million. In April, actors linked to North Korea were associated with roughly $578 million of the $634 million stolen that month.
Overall crypto-related hack losses fell 46.8% year-on-year to $1.32 billion in the first half of 2026, a comparison affected by a $1.4 billion exchange hack in early 2025. Security firms point to poor key management, exposed backups, weak endpoint defenses and successful phishing campaigns as leading causes of high-value breaches.
The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.








