Go to app

The $31M Exploit: Official Narrative

Published 6/9/2026, 11:21:32 AM

On June 9, 2026, Humanity Protocol experienced a security breach resulting in the loss of approximately $31 million and a 90% collapse in the price of its native $H token. While the project officially attributed the incident to a private key compromise, on-chain investigator ZachXBT has publicly characterized the event as "possibly staged," suggesting it served as a mechanism for an active market maker to exit the project.

The $31M Exploit: Official Narrative

The Humanity Foundation reported that the exploit stemmed from a compromised private key belonging to a foundation member. This breach led to the following:

  • Wallet Drainage: Attackers gained access to at least 17 project-linked wallets, siphoning over $30 million in assets [Source: https://www.yellow.com/news/humanity-protocol-h-token-crashes-90-following-31m-exploit].
  • Unauthorized Minting: Security reports indicate that 100 million $H tokens were minted and subsequently dumped on the BNB Smart Chain (BSC) after the ownership of the token admin contract was transferred via a compromised multisig [Note: not independently confirmed].
  • Price Impact: The $H token plummeted from $0.78 to $0.052 within a 24-hour window following the dump.

ZachXBT’s "Staged Hack" Allegations

ZachXBT has challenged the official "hack" explanation, citing several operational red flags that suggest the event may have been orchestrated.

AllegationDetail
Market Maker ExitZachXBT suggested the breach was a "convenient way for the active MM [Market Maker] to have exited" [Source: https://www.bitget.com/news/detail/12560604115441].
Aggressive ShillingHe noted the team had been aggressively promoting the token for weeks despite "little underlying value" [Source: https://www.bitget.com/news/detail/12560604115441].
Transparency IssuesZachXBT called for the disclosure of agreements with a specific Hong Kong-based market maker [Source: https://www.bitget.com/news/detail/12560604115441].
Supply ConcentrationHe highlighted that the high concentration of token supply made the "security breach" narrative highly suspicious.

Supporting Evidence and Red Flags

The allegations are bolstered by existing controversies surrounding the protocol's decentralization and user metrics:

  • Multisig Centralization: Reports from social media (e.g., @moo on Warpcast) alleged that 3 out of 6 multisig key holders were actually the same individual, significantly weakening the "compromised multisig" defense.
  • Bot Activity: Prior to the crash, reports from June 2025 suggested that up to 88% of the 9 million "Human IDs" on the protocol were likely bots.
  • Founder Track Record: Critics have pointed to founder Terence Kwok’s history with Tink Labs, a unicorn startup that collapsed in 2020, resulting in a $170 million loss for investors [Source: https://www.yellow.com/news/humanity-protocol-h-token-crashes-90-following-31m-exploit].

Evidence Ledger Resolution

Conclusion: While Humanity Protocol maintains the loss was a theft due to a private key compromise, the "staged hack" theory is supported by ZachXBT and on-chain analysts who point to the suspicious timing of the market maker's exit, the centralized nature of the project's multisig, and the massive unauthorized minting of tokens.

Next Steps:

  • Would you like a deep dive into the on-chain movement of the stolen $31M to see if the funds are being laundered or sent to known exchange deposit addresses?
  • I can monitor the $H token's liquidity and social sentiment to see if there are any signs of a "dead cat bounce" or further team liquidations.