The H token lost about 85% in a few hours after reports of private key compromise within the Humanity Foundation structure. Preliminary estimates suggest the attacker withdrew assets worth more than $30 million and began moving them through decentralized platforms.
The asset’s price dropped from around $0.70 to $0.08, according to CoinGecko. For a project building a digital identification system with palm biometrics, this incident was a blow not only to the market but also to trust in the infrastructure.
Users Asked Not to Touch the Bridge and Liquidity
Project founder Terence Kwok reported that the team had identified an incident related to access to the keys of one of the foundation’s members. After this, users were warned: until the investigation is complete, they should not interact with the bridge or liquidity pools.
There are few details so far. Developers said they are working with security specialists and studying the scale of the attack. Such a response shows that the situation is not fully resolved and the movement of funds remains under observation.
This is the main practical takeaway for users. Until there is separate confirmation of security, any operations through the bridge or related pools carry increased risk—especially if some access rights or related wallets may have fallen under the attacker’s control.
Stolen Tokens Started to Be Swapped Through DEX
On-chain analysts estimate the damage at more than $30 million. According to Specter, the attack may have affected addresses linked to the project or previously interacted with it.
Arkham also recorded asset withdrawals exceeding $30 million. According to the platform, the attacker began swapping tokens through Kyber Network, PancakeSwap, and other decentralized exchanges.
This worsens the situation for the team. When stolen assets quickly enter trading routes, they are harder to block or recover. At the same time, such sales create direct pressure on the price, which may have intensified the H crash.
This Does Not Look Like a Typical Contract Hack
According to preliminary reports, the problem is not a smart contract bug but the compromise of private keys. This scenario is especially dangerous because transactions appear properly signed.
If an attacker gains access to a key, they effectively act as the wallet owner. The network does not see a “hack” in the usual sense but simply executes operations signed with the correct data.
That is why the team’s response in such cases is always more complicated. It is necessary to quickly understand which addresses are affected, what rights they had, whether keys can be replaced, routes blocked, and exchanges warned.
The Project Operates in a Sensitive Identification Niche
Humanity Protocol is developing decentralized identification based on zkEVM. The project uses Proof of Humanity and palm biometrics, trying to confirm that a real person is behind the account without disclosing unnecessary data.
That is why the reputational risk here is higher than for a typical DeFi token. Identification services must convince users that the system is secure at the level of data, contracts, wallets, and governance structures.
So far, there is no confirmation that biometric data or user privacy has been affected. The main public risk now is related to tokens, the bridge, pools, and the foundation’s keys.
The Market Punished the Token Before the Investigation Concluded
An 85% drop shows how quickly investors exit an asset when information is lacking. When the team reports a key compromise and on-chain data shows stolen funds moving, the market does not wait for a final report.
In such a situation, the price reacts to the worst-case scenario. Investors factor in the risk of further sales, bridge problems, and the possible spread of the attack to other related addresses.
To recover, the project will have to provide more specifics. The market needs to know which keys were affected, what measures have been taken, where the stolen funds are, and whether it is safe to return to the bridge and liquidity.
Key Compromises Have Become a Systemic Problem
The incident continued a series of attacks where the weak point was not contracts but access to wallets and management keys. In such cases, the damage can be comparable to major exploits, but the mechanism is simpler: the attacker gains control over a critical address.
There have already been several similar episodes this year. One of the largest was linked to an attack on Drift Protocol, where the damage was estimated in the hundreds of millions of dollars. Other incidents mentioned in this context include Step Finance, Resolv, Volo Vault, Echo Bridge, Bankr, StablR, Stake DAO, Gravity Bridge, and other projects.
According to CertiK, in May, wallet and private key compromises became one of the most expensive types of attacks. Losses in this area totaled $13.7 million. The new case shows that the problem remains one of the main issues for the entire industry.
What Is Next?
The team needs to quickly localize the incident and explain which infrastructure elements are already protected. Without this, the token may remain under pressure even after a sharp drop.
The main question for the market is not just the amount of damage. It is more important to understand whether other wallets were affected, whether the movement of stolen funds can be stopped, and when it will be safe for users to work with the bridge and pools again.
This case once again highlights the weak point of crypto projects. Even if smart contracts work correctly, private keys and access rights can become a point of failure. For a digital identification project, such a risk is especially painful because trust is part of the product itself.
Read More: ZachXBT Accused the FCA of Overstepping Authority After Sanctions Against HTX
