FB pixel

Humanity Protocol key storage error, malware infection lead to massive token breach

Humanity Protocol key storage error, malware infection lead to massive token breach
 

There is no indication that the palm biometrics “Proof-of-Trust” nee “Proof-of-Humanity” startup Humanity Protocol uses for identity verification have failed. Instead, the company traces a massive breach it suffered this week resulting in 447 million H tokens worth an estimated stolen or illicitly minted to improperly stored private keys.

A developer’s computer infected with malware was storing backups of seven private encryption keys. The keys had been inadvertently backed up around when Humanity Protocol launched its mainnet last June, according to the company’s incident report.

Three coordinated attacks against Humanity Protocol were then carried out across two chains using the exposed keys on Monday and Tuesday. The attacks resulted in 300 million new H tokens being minted, plus an EOA direct theft and ETH bridge drain accounting for the stolen tokens.

Humanity Protocol described the incident as a “human and operational security failure.”

South Korea’s ChosunBiz reports that the biometric identity verification feature could be spoofed, but does not offer any evidence, and fails to acknowledge the actual attack vector used in the breach.

The response from Humanity Protocol includes the creation of a web page that tracks the wallet addresses controlled by the attacker and the movement of funds, as well as a $1 million USDT bounty for information that leads to the recovery of its tokens.

“We are still determining the full root cause of how the device was compromised and the exact timeline of when the attacker gained access,” the company said in its statement on the breach. “We have engaged external security experts to conduct a forensic investigation of the compromised devices. We will share further findings with the community as the investigation progresses. We are also working on recovery program for victims affected.”

The price of Humanity Protocol’s tokens fell from highs above $0.80 earlier this month to around $0.16 in Thursday trading, according to CoinMarketCap.

Humanity Protocol recently announced a shift in its focus to differentiating people from bots and AI agents to user attribute and identity verification.

Related Posts

Article Topics

 |   |   |   | 

Latest Biometrics News

 

WTTC puts biometrics, digital identity at center of travel agenda

The World Travel & Tourism Council (WTTC) has laid out eight strategic priorities to guide its decision making for the…

 

Digital trust under threat from advanced fraud, AI agents: BioCatch

The digital world has consumed us; “being online” is no longer optional. As such, the importance of digital trust has…

 

Ireland body camera bill prompts debate over use of recorded footage

Gardaí are preparing a €150 million nationwide rollout of body-worn cameras as the use of biometric data in day-to-day policing…

 

Wrongful arrest based on false FRT match sparks lawsuit from Florida man

Another case of wrongful arrest after a false match by facial recognition software has given more ammo to those fighting…

 

Report finds synthetic identity fraud becoming biggest fraud threat in 2026

Synthetic identity fraud is fast becoming one of the biggest threats facing financial institutions, according to new research from Mitek…

 

Africans’ identity security a key driver of economic development, democracy, livelihoods and dignity

By Nat Pisupati, regional sales director MEA at HID FARGO Africa’s development story will increasingly be shaped not only by…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events