H Token Recovery Program

Humanity is rebuilding.
Your $H will be honoured.

On June 8–9 2026, Humanity suffered a coordinated exploit. We are relaunching $H and ensuring existing holders are made whole.

Read the incident report

The Incident

A coordinated attack, not a rug.

01

Private key theft

The admin hot wallet had its key stolen and drained ~30M $H.

02

Bridge exploit

The BSC Bridge ProxyAdmin was seized and 141M $H swept in one transaction.

03

Unlimited mint

The same pattern on BSC resulted in 200M $H minted by the attacker.

All team wallets are publicly verifiable on-chain. The exploit was external. Full post-mortem and all transaction hashes are on our transparency page.

View full transparency report →

The Recovery

Four pillars of recovery.

01

Token Swap

Existing $H holders receive new $H 1:1. All wallets holding $H at the time of the new token launch are eligible automatically.

02

Attacker Exclusion

All addresses linked to the attack are permanently excluded from the airdrop. The exploit supply will not be honoured.

03

Exchange Programme

We are working with all major exchanges to perform automatic swaps for their users. If you hold $H on an exchange, no action is required.

04

Recovery Fund

Bought $H from an attacker-linked address? Your tokens are excluded from the 1:1 swap through no fault of your own. Submit a claim and we will make you whole.

New Token

The new $H

The new $H token launches on Ethereum with a clean supply. The same token, rebuilt on a secure foundation. BSC bridge will follow after independent audit.

All wallets holding $H at the time the new token launches will receive new $H at a 1:1 ratio. Attacker addresses are excluded. CEX balances will be swapped automatically by each exchange.

Token
$H
Network
Ethereum
New contract
Coming soon
Eligibility
All $H holders at launch
Airdrop date
TBD
Old contract
0xcf5104D094e3864CfCBDa43B82e1cEFD26A016eB
Get notified when new $H launches

Excluded Addresses

Every address downstream of the attacker is excluded — not just these three.

Any wallet that received $H from an attacker-linked address — directly or through any number of subsequent transactions — is excluded from the new $H distribution. On-chain forensics are ongoing; the exclusion list will expand as the investigation progresses.

AddressChainReason
0xD1ea823D421E0c829ee11F772AF487fd352678EAETHAttacker wallet — received 141M H bridge drain
0x6Aa22CB8420E94Fc2119364b4c7885710aE753bBBSCAttacker wallet — minted 200M H
0x9e995952ef7665b243eeef0693acd7fed7150504ETHAggregation wallet — received stolen funds

Recovery Fund

Bought $H from a tainted source? We have you covered.

The 1:1 swap excludes addresses directly linked to the attack. If you purchased $H on the open market from one of those addresses — on a DEX, via OTC, or through any secondary transaction — your tokens are excluded from the airdrop through no fault of your own. Submit a claim and eligible claimants will receive new $H from the recovery fund.

Security Commitments

How we're hardening our infrastructure.

We already operate with licensed custodians for treasury and MPC wallets for operations. This incident revealed gaps in hot wallet discipline. Here is what we are implementing immediately.

01

No more single-key hot wallets

All operational wallets will require multi-sig or MPC approval. Every outbound transfer above 10,000 H now requires two independent signers.

02

Time-locks on large transfers

Transfers above 500,000 H will be subject to a minimum 24-hour time-lock enforced at the smart contract level.

03

HSM-backed key storage

New operational keys are generated and stored exclusively in Hardware Security Modules. Private key material never exists in plaintext.

04

Real-time on-chain monitoring

Automated alerting on all operational address clusters. Unexpected outbound transactions trigger an immediate page with a 60-second SLA.

05

Quarterly key rotation

All operational keys are rotated quarterly, or immediately following any team member departure. Ceremonies are documented and witnessed.

06

Independent security audits

A full infrastructure audit from a top-tier Web3 security firm before the new $H launches. Reports published in full. Bug bounty expanded.

Additionally in progress

  • — Air-gapped signing ceremonies for treasury operations
  • — Principle of least privilege across all key holders
  • — EIP-7702 delegation usage policy and review board
  • — Separate key sets for separate operational functions
  • — Incident response playbook (drafted during this event)

Detected

Placeholder date

Scope

Limited subset of wallets

Status

Contained · Patched

A vulnerability in a third-party integration allowed an attacker to interact with a small number of wallets connected through Humanity. The affected surface was isolated within hours. No core Humanity identity data was exposed. We are reimbursing eligible users in full and publishing a full post-mortem alongside the program close.

How recovery works.

01

Verify your wallet

Check your wallet address against the affected list. Most users are not impacted.

02

Submit a claim

Enter your wallet address in the claim modal to begin.

03

Sign a verification message

We'll send a message to sign with the affected wallet. No funds move, ever.

04

Receive restored access

Once verified, access and any eligible reimbursement is processed within 14 days.

Timeline.

  1. Day 0

    Anomaly detected

  2. Day 0 + 4h

    Affected surface contained

  3. Day 1

    Patch deployed and audited

  4. Day 2

    Recovery program opens

  5. Day 30

    Recovery program closes

Questions.

Still need help?

Reach a human at support@humanity.org. Replies come only from that address.

Email support