Humanity Protocol suffers $30 million security breach, funds traced on Ethereum and BNB Chain

iconMetaEra
Share
AI summary iconSummary
On-chain news reveals a major security breach at Humanity Protocol on June 9, 2026, with over $30 million in $H tokens stolen. Attackers exploited a malicious smart contract upgrade on Ethereum, draining funds from multiple wallets and selling the tokens via decentralized exchanges. On BNB Chain, the attackers minted 400 million $H tokens and liquidated them for profit. Funds have now been traced to several addresses across both chains. The project has yet to explain how multi-signature approvals were bypassed.

Hacker Attack or Rug Pull? Analysis of the $30 Million Humanity Protocol Security Incident and Tracking of Stolen Funds

On June 9, the decentralized identity project Humanity Protocol experienced an anomaly, resulting in losses to multiple Ethereum network wallets/contracts holding $H tokens associated with Humanity Protocol. The $H tokens held in these addresses were transferred to addresses controlled by the attacker, followed by exchange and further transfers. Additionally, the attacker minted additional $H tokens on the BNB Chain and sold them, resulting in total profits exceeding $30 million.

Security Incident Analysis

Ethereum Network:

As an example of the largest loss, the proxy contract 0x44f161ae29361e332dea039dfa2f404e0bc5b5cc transferred 141,182,632.22 $H tokens to the attacker’s address 0xd1ea823d421e0c829ee11f772af487fd352678ea, valued at approximately $16.45 million.

Reviewing the historical activity of this proxy contract reveals that it underwent a contract upgrade prior to this large transfer:

By decompiling the upgraded contract (0xee1bd9356Fe66591F600d5769F3e0e03F012CaFa), we can see that its execution function requires the account address triggering the smart contract call to be the attacker’s address, 0xd1ea823d421e0c829ee11f772af487fd352678ea, enabling the transfer of tokens through the upgraded malicious contract.

Re-analyzing the on-chain records of the $H token, the token contract was also upgraded at the time of the security incident:

Reviewing the transaction for this contract upgrade (transaction hash: 0x726f6b24c36104963e19648f5ed165b9f869744e501d27588ab24d7a4f9c53b6), you can find the multisig address 0x7BbC0d5167017092e2ba599dE6062080b891f645, which operates as a 4/7 multisig but successfully signed the malicious contract upgrade transaction.

BNB Chain:

The attacker initiated a transaction that successfully changed the owner of the $H token contract's ProxyAdmin (0xd73Cd1117646625FFE23a55860035aC62fa8720D) to the attacker's address, 0x6Aa22CB8420E94Fc2119364b4c7885710aE753bB.

The original owner address was a 3/5 multisignature address:

After gaining owner privileges, the attacker address upgraded the $H token contract and minted over 400 million $H tokens for sale:

Fund Flow Analysis

The actual losses from this incident have exceeded $30 million, and the attacker's address continues to mint new tokens to realize profits. Through analysis of the attacker-related addresses using Beosin Trace, the following flow diagram can be obtained:

Ethereum Network:

The attacker converted the majority of the $H tokens acquired on the Ethereum network into ETH via decentralized exchanges, primarily consolidating them at the address 0x59eff548cd9bcfbc169b6340f734e442c764a814, which currently holds 4,763.67 ETH (valued at approximately $7.95 million). Additionally, the upstream address 0x9e995952ef7665b243eeef0693acd7fed7150504 holds 21,739,098.74 $H tokens (valued at approximately $3.37 million), and 0xbeef02961503351625926ea9a11ae13b29f5c555 holds approximately $260,000 in ETH.

BNB Chain:

Tokens labeled $H minted on the BNB Chain have been exchanged for BNB via decentralized exchanges. The majority of the funds (approximately $16.1 million) remain held at 0x6aa22cb8420e94fc2119364b4c7885710ae753bb, while the downstream address 0xad7baae94959317929723a277694f3ecbd7358e1 holds approximately $880,000 in BNB with no further transfers detected.

As of the time of this report, the minting of $H tokens on BNB Chain has not ceased, and Humanity Protocol has not provided further explanation regarding the malicious upgrade signed by the 4/7 and 3/5 multisig wallets. Beosin Trace has added the relevant addresses to its monitoring system and is continuously tracking the attacker’s fund movements.

Beosin, among the world’s first blockchain security companies specializing in formal verification, offers a comprehensive “Security + Compliance” ecosystem. With offices in over ten countries and regions, Beosin provides end-to-end blockchain compliance and security services, including pre-launch code audits, real-time security monitoring and threat blocking, asset recovery, virtual asset anti-money laundering (AML), and regulatory-compliant assessments tailored to local requirements. Contact us today.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.