Humanity Protocol was hit by a severe security breach after a foundation member’s private key was compromised on June 9. According to statements from the project and onchain data cited in the source material, the attacker gained administrative control over the H token on BSC, drained 17 related wallets, stole more than $32 million in assets, and minted 100 million H tokens before selling them onchain. The token fell from about $0.67 to an intraday low of $0.05.
Compromised key gave the attacker control of the token contract
Founder Terence Kwok confirmed on X that the incident began with the leak of a private key belonging to a Humanity Foundation member. After obtaining that key, the attacker secured administrative permissions tied to the H token contract on BSC, including the ability to mint tokens and alter contract parameters.
CoinDesk’s review of onchain data, as cited in the source, showed H dropping from roughly $0.67 before the incident to around $0.13, with the price at one point touching $0.05. That put the deepest one-day decline near 90%. At the time referenced in the report, the token was still trading around $0.13, down about 82% on the day.
Wallet drain and fresh token minting intensified the sell-off
Onchain Lens said addresses linked to the attacker had already taken more than $31 million from wallets connected to the protocol, and the theft was still ongoing when the report was published. At the same time, the attacker was swapping stolen H tokens into ETH while using the newly obtained mint authority to issue 100 million additional H tokens on BSC and dump them into the market.
The combined pressure from stolen-token sales and newly minted supply drove the collapse in price. Humanity Protocol urged users not to interact with its bridge or any liquidity pools until security checks are complete, and said it was working with security firms and exchange partners on the response.
A palm-scan DID project that had drawn attention in the sector
Humanity Protocol is a decentralized identity, or DID, protocol built around palm-scan biometric verification. It uses zero-knowledge proofs, or ZKP, to verify personhood while aiming to preserve user privacy. Unlike World, which uses iris scanning, Humanity Protocol focuses on palm vein patterns and presents smartphone-based scanning as a lower-barrier approach that does not rely on expensive dedicated hardware.
The source notes that the project had previously received backing from several well-known venture investors and had attracted attention in the DID segment. The breach now shows how a failure in foundation-level key management can quickly turn into a loss of treasury assets and token control.
No recovery or compensation plan announced yet
As of publication, Humanity Protocol had not released a detailed asset recovery plan or any compensation arrangement for users. H remains highly volatile, and the next steps from the team are still pending.

