Humility Protocol Reports $36 Million Theft via Bridge Exploits

iconKuCoinFlash
Share
Share IconShare IconShare IconShare IconShare IconShare IconCopy
AI summary iconSummary

expand icon
Humility Protocol announced a security breach following a $36 million theft via bridge exploits. Attackers used compromised private keys from a Gnosis Safe and BSC Safe wallet to gain control of the Hyperlane Bridge ProxyAdmin. Malicious contracts were deployed to drain 141.2 million and 200 million H tokens from the Ethereum and BSC chains. The project has paused operations on the affected bridge and is collaborating with exchanges and authorities to recover funds. A protocol update is expected as the investigation continues.

Odaily Planet Daily report: Humility Protocol has issued a security incident update on X, stating that yesterday, the H token suffered a coordinated attack on the Ethereum and BSC chains, with over $36 million in assets confirmed stolen and sold.

Preliminary investigations indicate that the incident originated from a compromised employee computer, leading to the exposure of private keys for the multisignature wallet controlling the Hyperlane Bridge ProxyAdmin. The attacker obtained the private keys of three out of six owners of the Gnosis Safe on Ethereum, transferred ownership of the ProxyAdmin to a wallet under their control, upgraded the bridge contract to a malicious implementation, and subsequently transferred approximately 141.2 million H tokens in a single transaction.

Meanwhile, the attacker also gained control of three out of five private keys associated with the Safe wallet on the BSC chain, took over the ProxyAdmin in the same manner, and deployed a malicious contract with infinite minting capabilities, minting 200 million H tokens to their own wallet in two transactions.

Humility stated that all deposit and withdrawal operations for the affected bridge service have been suspended, and it is collaborating with exchanges and other relevant partners to minimize losses, while cooperating with law enforcement on the investigation and attempting to recover some of the stolen funds.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.