Humanity Protocol
2026-06-16 • Rekt •
A spear-phishing email impersonating Bithumb reportedly led to malware infection on a Humanity Protocol director's Windows laptop, exposing MetaMask data and production signer keys in activity Quantstamp said was characteristic of DPRK intrusions. With three Ethereum Safe keys and three BSC Safe keys recoverable from one endpoint, the attacker crossed multisig thresholds, seized ProxyAdmin control without a timelock, drained bridge funds, and enabled unauthorized $H minting. Humanity Protocol acknowledged 447.227 million $H affected, while QuillAudits documented additional BSC mint transactions totaling about 1.64 billion $H in on-chain token activity. Researchers disagreed on whether unusual market-maker flows indicated a staged event, but the report's supported technical finding is a private-key leak and administrative takeover enabled by poor key custody and missing upgrade-delay controls.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| WALLET | 0x943839Ff3D418C1435d4458e533FD… | 2026-06-16 | 2026-06-16 |
| WALLET | 0xbaAb7211438F33bE0344d57978C75… | 2026-06-16 | 2026-06-16 |
| WALLET | 0x3dB75DF4104255528674f798DeC42… | 2026-06-16 | 2026-06-16 |
| WALLET | 0x0E0e9fE6B97c9d4EaF040A7365c78… | 2026-06-16 | 2026-06-16 |
| WALLET | 0x6E6a9fCC3A26aB1F85BF87fb8c544… | 2026-06-16 | 2026-06-16 |
| WALLET | 0x686d1d7B04e453dcdA68e6C003271… | 2026-06-16 | 2026-06-16 |
| WALLET | 0x365e14eDFC2D4F582c814C40162f3… | 2026-06-16 | 2026-06-16 |
| WALLET | 0xf3599f3C7dD37FF42B043A2945E90… | 2026-06-16 | 2026-06-16 |
| WALLET | 0xD1ea823D421E0c829ee11F772AF48… | 2026-06-09 | 2026-06-09 |
| WALLET | 0x9e995952eF7665B243eeEF0693acD… | 2026-06-09 | 2026-06-09 |