JUST IN: Humanity Protocol: Attacker Obtained Seven Private Keys from a Committed Device
Humanity Protocol ethereum:0xcf5104d094e3864cfcbda43b82e1cefd26a016eb stated in an investigative report that the June 8 attack was due to a security vulnerability after a developer's computer was infected with malware, allowing the attacker full root access. Several private keys were inadvertently backed up to the device during the project's mainnet launch around June 2025, including the administrator hot wallet key, three ETH Safe owner keys, and three BSC Safe owner keys, allowing the attacker to obtain all seven keys from a single point of entry. The report stated that this incident was not a smart contract exploit, as there were no flaws in the bridge, token, or Safe, and the attacker's transfers, Safe transactions, and proxy upgrades were all authorized using valid private keys. Prior to this, the protocol had already suffered losses of over $31 million in this attack.