Humanity Protocol says it is redesigning its operational security setup after a breach last month led to the theft of $36 million worth of H tokens. The decentralized identity verification project said the incident began with the compromise of an employee laptop, turning attention to weaknesses outside smart contracts and on to the security of internal systems and staff devices.
Employee device compromise triggered theft
According to the project, the attack stemmed from a compromised employee computer. That access ultimately resulted in the loss of $36 million in Humanity tokens. The company has framed the incident as a lesson in the importance of operational security, arguing that protecting internal tools and credentials is just as important as auditing code and securing smart contracts.
In response, Humanity Protocol said it is rebuilding its security framework from the ground up. The statement indicates a broad restructuring rather than a limited patch to a single point of failure, though the project did not detail specific measures in the source report.
Quantstamp points to phishing and malware
Blockchain security firm Quantstamp said the attack may have involved a hacking group linked to North Korea. Its assessment suggests the intruders used phishing and malware to gain remote access, allowing them to reach a stolen admin hot wallet as well as multisig keys.
That account remains an assessment rather than a confirmed attribution. Still, the reported method fits a pattern that has become increasingly familiar in digital asset security incidents: rather than exploiting code directly, attackers target employees through deceptive messages, infected files, or compromised devices to capture privileged access.
Broader shift in crypto attack tactics
The Humanity Protocol breach comes as crypto security researchers describe a wider move toward social-engineering attacks. In these cases, the initial weakness is often human or operational rather than technical in the narrow sense of a smart-contract flaw.
CertiK said phishing was responsible for $508 million in losses in the first half of 2026. The firm also reported that wallet theft became especially notable in the second quarter, reaching a total of $807 million. Those figures suggest that attacks aimed at credentials, wallet access and internal operators are taking a larger share of overall losses.
Hack totals fell, but the picture is mixed
Across the crypto sector, total hacking losses in the first half of 2026 were reported at $1.32 billion, down 46.8% from a year earlier, according to CertiK. Even so, the source report cautioned against reading that decline as a simple sign of improvement.
The comparison is complicated by the Bybit hack in early 2025, which affected the prior-year baseline. As a result, lower aggregate losses do not necessarily mean the threat environment has eased. In Humanity Protocol's case, the breach underscores how a single compromised device can still lead to large losses even when the broader industry records a year-on-year decline.
The incident adds to evidence that crypto security risks are increasingly extending beyond protocol code and into the day-to-day security of employees, wallets and internal key management. For projects handling valuable on-chain assets, operational discipline is becoming a central part of defense rather than a secondary concern.
Source: en.bloomingbit.io