VERSE PRESS

Crypto News, Global First.

Crypto Losses Dip 7% in June, But Humanity Protocol's $31M to $36M Collapse Exposes a Deeper Problem

Crypto platforms lost $75.87 million to hacks and exploits in June 2026, a modest improvement over May, but the month's largest incident reveals how a protocol built to serve the world's unbanked failed its users through a basic security lapse.

|

PeckShield, the blockchain security firm, tracked 40 major incidents across June totaling $75.87 million in losses, a 7.13% decline from May's approximately $81.7 million. CertiK recorded a higher tally, roughly $81.7 million across 67 incidents (coincidentally matching May's figure), reflecting differences in how each firm counts smaller exploits.

Either way, the monthly figure lands against a grim quarterly backdrop. The first five months of 2026 alone saw more than $840 million in crypto losses, a 70% year-over-year increase. Q2 2026 saw approximately $775 million in total crypto losses across 83 exploits, making it the worst quarter on record. April 2026 alone accounted for $635 million, the worst single month in DeFi history, driven by the KelpDAO ($293 million) and Drift Protocol ($280 million) incidents.

Humanity Protocol: A $1.1 Billion Project That Stored Its Keys on One Laptop

The largest incident in June was the Humanity Protocol exploit, with losses estimated between $31 million and $36 million depending on the source and timing of the report. The protocol, which uses palm biometric scanning and zero-knowledge proofs (a cryptographic method to verify information without revealing the underlying data) to create on-chain digital identities, was valued at $1.1 billion as recently as January 2025 after raising a combined $50 million across two rounds, including a $30 million seed round in May 2024 and $20 million from Pantera Capital and Jump Crypto.

Animoca Brands and Polygon Labs also backed the project.

The root cause was not a sophisticated cryptographic flaw. An attacker gained access to an employee laptop storing multiple admin keys for both the protocol's Ethereum and BNB Chain multisig wallets. A multisig wallet requires several keyholders to authorize transactions, a security model designed specifically to prevent single points of failure. In this case, multiple keys were stored together on one compromised machine. On Ethereum, the attacker used three of six keys to deploy a malicious contract and drain approximately 141 million H tokens in a single transaction. On BNB Chain, three of five keys were enough to install an unlimited token minting function, producing roughly 200 million H tokens sent directly to the attacker's wallet.

Founder Terence Kwok acknowledged the failure in a public statement: "Some of the keys were accidentally backed up to a compromised device during setup." The team had intended to distribute key custody across four people. The backup process defeated that design entirely.

The H token crashed approximately 80% to 90% on the day of the exploit.

On-chain data shows 15,403 ETH (approximately $23.6 million) was subsequently moved to a new Ethereum address and bridged to Bitcoin, where it commingled with funds from the April 2026 Kelp DAO hack. The laundering trail extended further across Solana, Hyperliquid, and BNB Chain, a pattern consistent with sophisticated, multi-chain fund concealment. Security firm Quantstamp assessed the attack as "characteristic of DPRK intrusions," pointing to a phishing email that impersonated South Korean exchange Bithumb to compromise a company director, identified in subsequent reporting as Chong Yee Wai.

Chainalysis has attributed roughly 76% of 2026 hack losses overall to state-backed actors linked to North Korea's Lazarus Group. On-chain investigator ZachXBT initially suggested the incident may have been staged by insiders, but later ruled out insider theft based on subsequent on-chain evidence, shifting the prevailing assessment toward an external, state-linked threat actor.

Phishing losses in June totaled $12.7 million across the broader ecosystem, a reminder that social engineering remains as exploitable as any smart contract bug. The Bithumb impersonation that compromised Humanity Protocol's director illustrates how targeted phishing campaigns can unravel even carefully designed security architectures.

Other June Incidents: A Whitehat Return and Two Legacy Exploits

The Syscoin Bridge exploit, second on June's list at approximately $10 million, followed a different arc. A parsing error in the bridge's proof validation code allowed an attacker to submit a malformed proof, minting roughly 5 billion unauthorized SYS tokens without a corresponding burn on the other side of the bridge. The attacker subsequently made contact with the Syscoin team and returned the funds to a posted recovery address, consistent with a whitehat or bounty resolution.

Two legacy Aztec contracts, the Aztec Bridge and Aztec Connect, dating to 2022 and 2023 and no longer actively maintained, were also exploited for a combined $4.26 million, part of a broader 2026 pattern of attackers targeting deprecated contracts with dormant funds. Rounding out June's five largest incidents, a JaredFromSubway.eth MEV bot exploit resulted in losses of approximately $7.5 million, and a Secret Network drain cost users around $4.67 million, according to BanklessTimes, BeInCrypto, and PeckShield.

Who Gets Left Behind

Humanity Protocol was explicit about its target markets: Kenya, Nigeria, and Vietnam were among the early adoption hubs the team identified for its palm-scan identity product. The stated goal was to provide verifiable digital IDs to populations without reliable access to traditional identity systems, the kind of infrastructure that unlocks financial services for people excluded from the formal banking sector. Sub-Saharan Africa is the third-fastest growing crypto region globally, with 52% year-over-year growth, according to CryptoRank. Asia-Pacific is the fastest-growing region at 69% year-over-year growth, a figure that encompasses Vietnam, one of the protocol's named target markets. These users are not speculating on tokens; they are using crypto for payments, savings, and cross-border transfers.

The threats facing retail users in these markets extend well beyond protocol hacks. In 2026, the Treasure NFT scheme cost users in India and Pakistan approximately $800 million, and the CBEX scheme drained roughly $250 million from users in Nigeria, according to the TRM Labs 2026 Crypto Crime Report. These losses compound the trust deficit that legitimate infrastructure projects were trying to overcome.

The exploit froze a protocol that had registered more than 6 million testnet user IDs and 9.7 million wallets, with 443 million transactions recorded in 200 days, by mid-2025.

The subsequent removal of the team page from the project's website added another credibility blow in markets where trust in crypto infrastructure is already difficult to build and easy to lose.

The Humanity Protocol failure illustrates a risk pattern that extends across the sector: even well-funded projects with institutional backing can treat key management as an operational afterthought. Humanity Protocol carried a $1.1 billion valuation and roughly $50 million in raised capital, yet a single compromised laptop undid its multisig security model entirely. Smaller, less-resourced projects face the same class of vulnerability with even fewer safeguards in place.

With annualized hack losses projected between $2.5 billion and $3 billion based on current pace, according to AltFins, a 7% monthly dip offers little comfort. The questions worth watching in the coming months include how Humanity Protocol rebuilds its key management infrastructure, whether Chainalysis and Quantstamp advance their DPRK attribution with additional on-chain evidence, and how regulators in Kenya, Nigeria, and Vietnam respond to the failure of a protocol that explicitly targeted their citizens. The projects promising the most to the most vulnerable users still need to protect what they build.