Hacker Attack or Rug Pull? Analysis of the $30 Million Humanity Protocol Security Incident and Tracking of Stolen Funds
On June 9, the decentralized identity project Humanity Protocol experienced an anomaly, resulting in losses to multiple Ethereum network wallets/contracts holding $H tokens associated with Humanity Protocol. The $H tokens held in these addresses were transferred to addresses controlled by the attacker, followed by exchange and further transfers. Additionally, the attacker minted additional $H tokens on the BNB Chain and sold them, resulting in total profits exceeding $30 million.
Security Incident Analysis
Ethereum Network:
As an example of the largest loss, the proxy contract 0x44f161ae29361e332dea039dfa2f404e0bc5b5cc transferred 141,182,632.22 $H tokens to the attacker’s address 0xd1ea823d421e0c829ee11f772af487fd352678ea, valued at approximately $16.45 million.
Reviewing the historical activity of this proxy contract reveals that it underwent a contract upgrade prior to this large transfer:
By decompiling the upgraded contract (0xee1bd9356Fe66591F600d5769F3e0e03F012CaFa), we can see that its execution function requires the account address triggering the smart contract call to be the attacker’s address, 0xd1ea823d421e0c829ee11f772af487fd352678ea, enabling the transfer of tokens through the upgraded malicious contract.
Re-analyzing the on-chain records of the $H token, the token contract was also upgraded at the time of the security incident:
Reviewing the transaction for this contract upgrade (transaction hash: 0x726f6b24c36104963e19648f5ed165b9f869744e501d27588ab24d7a4f9c53b6), you can find the multisig address 0x7BbC0d5167017092e2ba599dE6062080b891f645, which operates as a 4/7 multisig but successfully signed the malicious contract upgrade transaction.
BNB Chain:
The attacker initiated a transaction that successfully changed the owner of the $H token contract's ProxyAdmin (0xd73Cd1117646625FFE23a55860035aC62fa8720D) to the attacker's address, 0x6Aa22CB8420E94Fc2119364b4c7885710aE753bB.
The original owner address was a 3/5 multisignature address:
After gaining owner privileges, the attacker address upgraded the $H token contract and minted over 400 million $H tokens for sale:
Fund Flow Analysis
The actual losses from this incident have exceeded $30 million, and the attacker's address continues to mint new tokens to realize profits. Through analysis of the attacker-related addresses using Beosin Trace, the following flow diagram can be obtained:
Ethereum Network:
The attacker converted the majority of the $H tokens acquired on the Ethereum network into ETH via decentralized exchanges, primarily consolidating them at the address 0x59eff548cd9bcfbc169b6340f734e442c764a814, which currently holds 4,763.67 ETH (valued at approximately $7.95 million). Additionally, the upstream address 0x9e995952ef7665b243eeef0693acd7fed7150504 holds 21,739,098.74 $H tokens (valued at approximately $3.37 million), and 0xbeef02961503351625926ea9a11ae13b29f5c555 holds approximately $260,000 in ETH.
BNB Chain:
Tokens labeled $H minted on the BNB Chain have been exchanged for BNB via decentralized exchanges. The majority of the funds (approximately $16.1 million) remain held at 0x6aa22cb8420e94fc2119364b4c7885710ae753bb, while the downstream address 0xad7baae94959317929723a277694f3ecbd7358e1 holds approximately $880,000 in BNB with no further transfers detected.
As of the time of this report, the minting of $H tokens on BNB Chain has not ceased, and Humanity Protocol has not provided further explanation regarding the malicious upgrade signed by the 4/7 and 3/5 multisig wallets. Beosin Trace has added the relevant addresses to its monitoring system and is continuously tracking the attacker’s fund movements.
Beosin, among the world’s first blockchain security companies specializing in formal verification, offers a comprehensive “Security + Compliance” ecosystem. With offices in over ten countries and regions, Beosin provides end-to-end blockchain compliance and security services, including pre-launch code audits, real-time security monitoring and threat blocking, asset recovery, virtual asset anti-money laundering (AML), and regulatory-compliant assessments tailored to local requirements. Contact us today.


