Humanity Protocol Drained After Multisig Keys Shared One Laptop

Humanity Protocol was drained on June 9 after an attacker got hold of the private keys behind the project's multisignature wallets, the arrangement in which a set number of separate keyholders must sign before funds can move. The size of the loss is disputed. CoinDesk reported it at $36 million; PeckShield, the blockchain security firm, logged $31 million. Neither account confirms the other, and we could not establish which figure supersedes which. Founder Terence Kwok said keys intended for four separate people had been "accidentally backed up to a compromised device during setup." The project's H token fell from about $0.67 to as low as $0.05 before recovering to roughly $0.20.
Two chains, two sets of keys
The attacker did not break the wallets so much as operate them. On Ethereum, three of six keys signed off on draining about 141 million H. On BNB Chain, three of five were used to mint about 200 million new tokens, creating supply rather than merely moving it. Every transaction was valid on its face. The required number of signatures was present, and the contracts executed exactly as written. The two legs of the attack, and the disputed loss figure, break down as follows:
- Ethereum: three of six keys, roughly 141 million H drained.
- BNB Chain: three of five keys, roughly 200 million H minted.
- Total loss: $36 million by CoinDesk's count, $31 million by PeckShield's.
A threshold is a claim about people
Requiring three signatures out of six is meant to guarantee that no single person, and no single machine, can move funds alone, and that guarantee rests entirely on the keys living apart from one another: different holders, different devices, different failure modes. Once keys meant for four people were copied onto one laptop, the threshold reduced to whatever protected that laptop. An attacker reaching the device did not have to defeat three independent custody setups. One was enough. It cleared the threshold on both chains at once. The wallet's configuration never changed, and that is the hard part. On-chain, a 3-of-6 wallet whose keys sit in one folder looks identical to one whose keys sit in six safes on three continents.
The token: a $1.1 billion valuation meets a five-cent print
H's fall from about $0.67 to as low as $0.05 erased the large majority of the token's value. Buyers took it back to roughly $0.20, still well below where it traded before the exploit. Humanity Protocol raised $20 million from Pantera and Jump Crypto at a $1.1 billion valuation in 2025, and that backing did nothing to prevent an error in how keys were stored. The roughly 200 million tokens minted on BNB Chain also sit on the price as unbacked supply, a problem separate from the funds taken on Ethereum and one that recovering the stolen assets would not by itself resolve.
The step nobody audits
Smart contract code gets audited, often repeatedly. The ceremony in which keys are generated, distributed and backed up usually does not. It happens once, early, frequently under launch pressure, and it leaves no record on-chain, so no user, exchange or auditor can verify from the chain that a published threshold corresponds to genuinely separated custody. That gap is what this incident exposes, and raising the threshold does not close it: a 5-of-9 wallet on one laptop is no safer than a 3-of-6. PeckShield counted $75.87 million stolen across 40 incidents in June, down 7.13% from $81.7 million in May, and on the firm's own figure this single failure accounts for roughly two-fifths of the month's total. Whether teams begin publishing verifiable attestations of where keys are held, and not only how many are required, is the practical test of whether the lesson lands.
Read also: Polymarket Users Lose $3.1M in a Frontend Supply-Chain Attack