H Token Recovery Program
On June 8–9 2026, Humanity suffered a coordinated exploit. We are relaunching $H and ensuring existing holders are made whole.
The Incident
01
The admin hot wallet had its key stolen and drained ~30M $H.
02
The BSC Bridge ProxyAdmin was seized and 141M $H swept in one transaction.
03
The same pattern on BSC resulted in 200M $H minted by the attacker.
All team wallets are publicly verifiable on-chain. The exploit was external. Full post-mortem and all transaction hashes are on our transparency page.
View full transparency report →The Recovery
01
Existing $H holders receive new $H 1:1. All wallets holding $H at the time of the new token launch are eligible automatically.
02
All addresses linked to the attack are permanently excluded from the airdrop. The exploit supply will not be honoured.
03
We are working with all major exchanges to perform automatic swaps for their users. If you hold $H on an exchange, no action is required.
04
Bought $H from an attacker-linked address? Your tokens are excluded from the 1:1 swap through no fault of your own. Submit a claim and we will make you whole.
New Token
The new $H token launches on Ethereum with a clean supply. The same token, rebuilt on a secure foundation. BSC bridge will follow after independent audit.
All wallets holding $H at the time the new token launches will receive new $H at a 1:1 ratio. Attacker addresses are excluded. CEX balances will be swapped automatically by each exchange.
Excluded Addresses
Any wallet that received $H from an attacker-linked address — directly or through any number of subsequent transactions — is excluded from the new $H distribution. On-chain forensics are ongoing; the exclusion list will expand as the investigation progresses.
| Address | Chain | Reason |
|---|---|---|
| 0xD1ea823D421E0c829ee11F772AF487fd352678EA | ETH | Attacker wallet — received 141M H bridge drain |
| 0x6Aa22CB8420E94Fc2119364b4c7885710aE753bB | BSC | Attacker wallet — minted 200M H |
| 0x9e995952ef7665b243eeef0693acd7fed7150504 | ETH | Aggregation wallet — received stolen funds |
Recovery Fund
The 1:1 swap excludes addresses directly linked to the attack. If you purchased $H on the open market from one of those addresses — on a DEX, via OTC, or through any secondary transaction — your tokens are excluded from the airdrop through no fault of your own. Submit a claim and eligible claimants will receive new $H from the recovery fund.
Security Commitments
We already operate with licensed custodians for treasury and MPC wallets for operations. This incident revealed gaps in hot wallet discipline. Here is what we are implementing immediately.
01
All operational wallets will require multi-sig or MPC approval. Every outbound transfer above 10,000 H now requires two independent signers.
02
Transfers above 500,000 H will be subject to a minimum 24-hour time-lock enforced at the smart contract level.
03
New operational keys are generated and stored exclusively in Hardware Security Modules. Private key material never exists in plaintext.
04
Automated alerting on all operational address clusters. Unexpected outbound transactions trigger an immediate page with a 60-second SLA.
05
All operational keys are rotated quarterly, or immediately following any team member departure. Ceremonies are documented and witnessed.
06
A full infrastructure audit from a top-tier Web3 security firm before the new $H launches. Reports published in full. Bug bounty expanded.
Additionally in progress
Detected
Placeholder date
Scope
Limited subset of wallets
Status
Contained · Patched
A vulnerability in a third-party integration allowed an attacker to interact with a small number of wallets connected through Humanity. The affected surface was isolated within hours. No core Humanity identity data was exposed. We are reimbursing eligible users in full and publishing a full post-mortem alongside the program close.
01
Check your wallet address against the affected list. Most users are not impacted.
02
Enter your wallet address in the claim modal to begin.
03
We'll send a message to sign with the affected wallet. No funds move, ever.
04
Once verified, access and any eligible reimbursement is processed within 14 days.
Day 0
Anomaly detected
Day 0 + 4h
Affected surface contained
Day 1
Patch deployed and audited
Day 2
Recovery program opens
Day 30
Recovery program closes
Reach a human at support@humanity.org. Replies come only from that address.