Humanity Protocol Founder Concedes $36M in Stolen Funds Is Likely Gone, Announces Enterprise AI Pivot
Terence Kwok, founder of the Hong Kong-based biometric identity project, told The Block on July 2 that the odds of recovering funds stolen in a June 8 exploit are low. The project has responded by relaunching its token and, separately, repositioning toward business-to-business AI infrastructure, a strategic shift that had already begun in February 2026, several months before the exploit.
Humanity Protocol lost an estimated $36 million worth of its native H token on June 8, 2026, after attackers used a phishing email impersonating South Korean exchange Bithumb to compromise a project director's laptop. The device stored enough private keys to control the project's bridges on both Ethereum and BNB Chain simultaneously, allowing attackers to drain 141.2 million H tokens from the Ethereum bridge and mint between 200 and 300 million unauthorized H tokens on BNB Chain. The stolen tokens were then sold off rapidly across decentralized exchanges Uniswap and PancakeSwap. Kwok acknowledged this week that the odds of recovering those funds are low.
One Laptop, Six Keys
The root cause of the breach was not a flaw in the protocol's smart contracts. It was a failure of basic operational security. Gnosis Safe, the multisig wallet system the project used, requires multiple private keys to authorize transactions as a safeguard against single points of failure. However, three of the six Ethereum bridge keys and three of the five BNB Chain bridge keys were all stored on a single project director's device. "Some of the keys were accidentally backed up to a compromised device during setup," Kwok said in a statement reported by CoinDesk on June 9. Attackers gained access on June 5 and waited three days before executing the theft, first deploying a malicious contract upgrade on Ethereum and then activating an unlimited token minting function on BNB Chain. Blockchain security firm Quantstamp attributed the attack to North Korea-affiliated threat actors, linking malware signatures to tactics consistent with those used by Lazarus Group, the same state-sponsored hacking operation implicated in the 2025 Bybit breach.
Token Collapse and Recovery Plan
The H token had reached an all-time high of approximately $0.85 on June 2, just six days before the attack. Within 12 hours of the exploit, the price fell between 80 and 90 percent, bottoming near $0.057. As of July 2, the token trades at approximately $0.07, roughly 92 percent below its peak, with a market capitalization near $139 million and 24-hour trading volume around $17.2 million (CoinMarketCap). Circulating supply stands at approximately 3.1 billion H tokens out of a total supply of 10 billion.
On June 17, Humanity Protocol launched a 1:1 swap of old H tokens for a new audited ERC-20 H token across six exchanges: Binance Alpha, MEXC, Bitget, KuCoin, Bybit, and Gate. Balances were calculated from chain snapshots taken at the moment before the attack, covering Ethereum block 25,274,179, BNB Chain block 103,071,069, and Humanity Mainnet block 24,247,803. A separate compensation fund was established for edge cases including liquidity pool positions, users who purchased tokens after the snapshot, and third-party protocol integrations. Because of the DPRK attribution, the project requires identity verification for compensation claims.
Strategic Repositioning
The hack accelerated a shift the project had already begun months earlier. In February 2026, Humanity Protocol formally moved away from its original "Proof-of-Personhood" model toward what it calls a "Proof-of-Trust" network, allowing enterprises to verify structured credentials including KYC and income data using zero-knowledge proofs, a cryptographic method that confirms information without exposing the underlying data. The project had also acquired on-chain ticketing and credentialing platform Moongate, launched developer APIs for non-blockchain applications, and in November 2025 partnered with Mastercard to let Human ID holders unlock credit and financial services using cryptographic income proofs.
Kwok framed the enterprise pivot in expansive terms. "The demand for privacy-preserving, portable trust primitives will expand across billions of users as synthetic identities become more prevalent," he said in a February 2026 statement cited by Biometric Update, made at the time of the Proof-of-Trust relaunch and predating the June exploit by roughly four months. The project has issued more than 8 million Human IDs, raised $20 million from Pantera Capital and Jump Crypto, and reached a peak valuation of $1.1 billion. It is now positioning its biometric identity infrastructure as anti-fraud tooling for an AI-saturated internet.
What This Means for Emerging Market Users
Humanity Protocol had made explicit inroads in Kenya, Nigeria, and Vietnam, marketing palm biometric onboarding as a practical identity solution for populations without reliable access to traditional KYC infrastructure. South Korea remained its single largest active market, which makes the use of a fake Bithumb email as the attack vector particularly pointed, since it exploited regional brand trust to gain access.
The shift toward enterprise contracts changes the project's relationship with those grassroots users. Earlier token incentives for signing up have been replaced by a platform fee model targeting business clients. Users in Nigeria, Kenya, or India who held H tokens outside the pre-hack snapshot window face losses with limited recourse, and the identity verification requirement for compensation claims adds friction in jurisdictions where formal ID infrastructure is inconsistent.
The broader lesson for developers building multisig-secured infrastructure across Africa and South Asia is straightforward: social engineering via trusted regional brands is increasingly the attack vector of choice. Code audits matter, but so does distributing private keys across separate physical devices and separate people, using hardware security modules, and ensuring geographic separation of signers.