Foto: persoon achter laptop in het donker — symbolisch bij een crypto-hack en gestolen privésleutels
Speciale editieSpecial edition  ·  Editie #005Edition #005  ·  Exploit / Hack

De Humanity Protocol-hack: hoe gestolen sleutels een token in één dag 88% deden kelderenThe Humanity Protocol hack: how stolen keys crashed a token 88% in a single day

Boven: Hackers bemachtigden de privésleutels van een lid van de Humanity Foundation, dumpten het H-token en haalden meer dan $30 miljoen weg. De koers viel in 24 uur met 88%.Above: Hackers obtained the private keys of a Humanity Foundation member, dumped the H token and drained more than $30 million. The price fell 88% in 24 hours.
Home Scam van de Week Editie #005Edition #005

Gestolen sleutels, een gedumpt token en $30 miljoen weg: zo werkt een private-key-hackStolen keys, a dumped token and $30 million gone: how a private-key hack works

Het H-token van Humanity Protocol stond begin juni op recordhoogte. Toen bemachtigden hackers de privésleutels van een lid van de foundation — geback-upt op een computer die besmet was met malware. Ze dumpten het token, wisselden het om naar Ethereum en haalden meer dan $30 miljoen weg. Binnen 24 uur was de koers 88% lager. Geen klik-scam, maar een les die elke belegger raakt: als een paar sleutels alles kunnen bewegen, is dat één zwakke plek.Humanity Protocol’s H token was at a record high in early June. Then hackers obtained the private keys of a foundation member — backed up on a malware-infected machine. They dumped the token, swapped it for Ethereum and drained more than $30 million. Within 24 hours the price was down 88%. Not a click scam, but a lesson every investor should heed: if a handful of keys can move everything, that is a single point of failure.

Feiten op een rijKey facts
~$0,60
Koers vóór de hack (circa)Price before the hack (approx.)
$0,072
Laagste koers na hackLowest price after hack
−88%
Koersval in 24 uurPrice drop in 24h
>$30M
GestolenStolen
17+
Wallets leeggehaaldWallets drained

Wat is er precies gebeurd?What exactly happened?

Humanity Protocol is een project dat mensen een digitaal “bewijs van mens-zijn” wil geven (proof of humanity). Het bijbehorende token heet H. Begin juni 2026 zat H in een sterke opmars en bereikte het een recordkoers. Precies op dat moment ging het mis.Humanity Protocol is a project that aims to give people a digital “proof of humanity”. Its token is called H. In early June 2026 H was on a strong run and hit a record high. That is exactly when things went wrong.

Hackers kregen de privésleutels in handen van een lid van de Humanity Foundation. Een privésleutel is als de hoofdsleutel van een kluis: wie hem heeft, kan alles verplaatsen. Volgens onderzoekers stonden die sleutels als back-up op een computer van een ontwikkelaar die besmet was met malware. Zo lekten ze naar buiten.Hackers got hold of the private keys of a member of the Humanity Foundation. A private key is like the master key to a vault: whoever holds it can move everything. According to researchers, those keys had been backed up on a developer’s computer that was infected with malware. That is how they leaked.

Met die sleutels haalde de aanvaller meer dan 17 wallets leeg. On-chain speurders zoals Lookonchain zagen live hoe het gestolen H werd verkocht en omgewisseld naar Ethereum (ETH). Door die verkoopgolf stortte de koers in 24 uur met 88% — van ongeveer $0,60 naar een dieptepunt rond $0,072. De totale schade liep op tot meer dan $30 miljoen. Oprichter Terence Kwok bevestigde de hack en waarschuwde mensen om niet met de bridge of de liquidity pools te interacteren.With those keys the attacker drained more than 17 wallets. On-chain sleuths such as Lookonchain watched in real time as the stolen H was sold and swapped into Ethereum (ETH). That wave of selling crashed the price 88% in 24 hours — from about $0.60 to a low near $0.072. Total damage rose to more than $30 million. Founder Terence Kwok confirmed the hack and warned people not to interact with the bridge or the liquidity pools.

Later bleek dat de buit werd witgewassen over meerdere netwerken — Bitcoin, Solana, Hyperliquid en BNB Chain. Beveiligingsbedrijf Quantstamp koppelde de gebruikte technieken aan hackersgroepen die vaak met Noord-Korea in verband worden gebracht. De hack kwam bovendien vlak vóór een geplande “token unlock” op 25 juni, een moment waarop extra tokens vrijkomen en er sowieso al verkoopdruk is.It later emerged that the proceeds were laundered across several networks — Bitcoin, Solana, Hyperliquid and BNB Chain. Security firm Quantstamp linked the techniques used to hacking groups often associated with North Korea. The hack also came just before a scheduled “token unlock” on 25 June, a moment when extra tokens are released and selling pressure is already high.

“Een recordkoers de ene week, 88% eronder de volgende. Niet omdat het project ‘nep’ was — maar omdat één set gestolen sleutels de hele voorraad kon bewegen.”“A record high one week, down 88% the next. Not because the project was ‘fake’ — but because one set of stolen keys could move the entire supply.”

De tijdlijn — stap voor stapThe timeline — step by step

📈begin juni 2026early June 2026
Het H-token op recordhoogteThe H token at a record high
Na een snelle rally bereikt het token van Humanity Protocol een recordkoers (circa $0,60). De hype is groot en veel beleggers stappen laat in.After a fast rally, Humanity Protocol’s token hits a record high (around $0.60). Hype is strong and many investors buy in late.
🔑8–9 juni 20268–9 June 2026
De privésleutels lekkenThe private keys leak
Sleutels van een lid van de Humanity Foundation — geback-upt op een met malware besmette computer van een ontwikkelaar — komen in handen van de aanvaller.Keys of a Humanity Foundation member — backed up on a malware-infected developer machine — fall into the attacker’s hands.
💸9 juni 20269 June 2026
17+ wallets leeggehaald, koers −88%17+ wallets drained, price −88%
De aanvaller dumpt het gestolen H en wisselt het om naar ETH. On-chain speurders slaan alarm. De koers valt in 24 uur met 88% naar een dieptepunt rond $0,072.The attacker dumps the stolen H and swaps it into ETH. On-chain sleuths sound the alarm. The price falls 88% in 24 hours to a low near $0.072.
📣9 juni 20269 June 2026
Oprichter bevestigt de hackFounder confirms the hack
Terence Kwok bevestigt het incident publiekelijk en vraagt mensen om niet met de bridge of liquidity pools te interacteren tot alles veilig is.Terence Kwok publicly confirms the incident and asks people not to interact with the bridge or liquidity pools until it is safe.
🌐eind juni 2026late June 2026
Schade >$30M, buit witgewassenDamage >$30M, proceeds laundered
De buit wordt verspreid over Bitcoin, Solana, Hyperliquid en BNB Chain. Quantstamp koppelt de technieken aan Noord-Koreaanse hackersgroepen; de buit vermengt zich met die van de KelpDAO-hacker.The proceeds are spread across Bitcoin, Solana, Hyperliquid and BNB Chain. Quantstamp links the techniques to North Korean hacking groups; the funds mix with those of the KelpDAO exploiter.

De rode vlaggen — waar je op moet lettenThe red flags — what to watch for

Een private-key-hack kun je als buitenstaander niet altijd zien aankomen. Maar deze signalen vergroten het risico bij een token of project — en die kun je wél checken:As an outsider you can’t always see a private-key hack coming. But these signals raise the risk around a token or project — and you can check them:

01
Eén nieuw, sterk gehypt token op recordhoogteA single new, heavily hyped token at a record high
Tokens die net parabolisch zijn gestegen, vallen ook het hardst als er iets misgaat. Wie op de top instapt, heeft de minste buffer. Hype is geen bescherming.Tokens that have just spiked parabolically also fall the hardest when something goes wrong. Whoever buys at the top has the least cushion. Hype is not protection.
02
Weinig sleutels beheren een groot deel van de voorraadA few keys control a large share of the supply
Als een handvol wallets of een “foundation” een groot deel van alle tokens kan bewegen, is dat één zwakke plek (single point of failure). Check de tokenverdeling: hoeveel houden de grootste adressen?If a handful of wallets or a “foundation” can move a large share of all tokens, that is a single point of failure. Check the token distribution: how much do the largest addresses hold?
03
Sleutels op internet-verbonden apparatenKeys on internet-connected devices
Hier lekten de sleutels via een back-up op een besmette computer. Voor jou geldt hetzelfde principe: grote bedragen horen niet op een telefoon of laptop, maar in een hardware wallet (offline).Here the keys leaked via a backup on an infected computer. The same principle applies to you: large amounts don’t belong on a phone or laptop, but in a hardware wallet (offline).
04
Een token unlock in aantochtA token unlock coming up
Rond een unlock komen extra tokens vrij en is de verkoopdruk hoog. Dat maakt zo’n periode extra riskant. Zoek vooraf op wanneer de unlocks van een project gepland staan.Around an unlock, extra tokens are released and selling pressure is high. That makes such a period extra risky. Look up when a project’s unlocks are scheduled.
05
Geld in bridges en liquidity poolsMoney in bridges and liquidity pools
Bridges en pools zijn een geliefd doelwit voor hackers. De oprichter waarschuwde er hier zelf voor. Laat niet meer in zulke contracten staan dan je kunt missen.Bridges and pools are a favourite target for hackers. The founder himself warned about them here. Don’t leave more in such contracts than you can afford to lose.
06
“Herstel”-hulp ná de hack“Recovery” help after the hack
Na elke grote hack duiken nep-“recovery”-diensten op die beloven je verlies terug te halen — tegen een voorschot. Dat is een tweede scam bovenop de eerste. Niemand kan gestolen crypto tegen betaling terughalen.After every big hack, fake “recovery” services appear promising to get your loss back — for an upfront fee. That is a second scam on top of the first. No one can recover stolen crypto for a fee.

Vijf gouden regels die je hiertegen beschermenFive golden rules that protect you

1Spreid je vermogen. Zet nooit een groot deel in één nieuw, gehypt token — hoe hard het ook stijgt.Spread your holdings. Never put a large share into one new, hyped token — no matter how fast it rises.
2Bewaar grote bedragen koud. Een hardware wallet (offline) is veel veiliger dan een app op je telefoon of laptop.Store large amounts cold. A hardware wallet (offline) is far safer than an app on your phone or laptop.
3Hype en bekende namen ≠ veiligheid. Ook een project met veel aandacht kan door één hack instorten.Hype and big names ≠ safety. Even a project with lots of attention can collapse from a single hack.
4Let op unlocks en bridges. Ken de risicomomenten van een project en volg alleen de officiële kanalen.Watch unlocks and bridges. Know a project’s risk moments and follow only official channels.
5Trap niet in “recovery”-scams. Niemand haalt gestolen crypto tegen betaling voor je terug.Don’t fall for “recovery” scams. No one recovers stolen crypto for you in exchange for a fee.

Had de scam checker dit gevonden?Would the scam checker have caught this?

Niet de hack zelf — die begon met gestolen sleutels, niet met een verdacht contract. Maar onze scam checker kijkt wél naar signalen die het risico rond een token vergroten, en een paar daarvan speelden hier mee.Not the hack itself — that started with stolen keys, not a suspicious contract. But our scam checker does look at signals that raise the risk around a token, and a few of those were in play here.

Doe vóór je in een token stapt deze drie checks:Before you buy a token, do these three checks:

Bekijk de tokenverdeling — houden een paar adressen een groot deel van de voorraad?
Check of het contract upgradebaar is — kan een eigenaar/“proxy” de regels of voorraad aanpassen?
Zoek de unlock-planning op — komen er binnenkort veel tokens vrij?
Look at the token distribution — do a few addresses hold a large share of the supply?
Check whether the contract is upgradeable — can an owner/“proxy” change the rules or supply?
Look up the unlock schedule — are lots of tokens about to be released?

De kern: concentratie is risico. Als weinig sleutels of adressen alles kunnen bewegen, kan één lek de hele koers meesleuren.The bottom line: concentration is risk. If few keys or addresses can move everything, a single leak can drag the whole price down.

Twijfel je over een token?Not sure about a token?

Plak het contract-adres in de gratis scam checker en krijg direct een risicoscore op basis van 20+ controles — inclusief tokenverdeling en of het contract upgradebaar is.Paste the contract address into the free scam checker for an instant risk score based on 20+ checks — including token distribution and whether the contract is upgradeable.

🔍 Open scam checker →

Bronnen:Sources: BeInCrypto — Kamina Bashir (9 jun. 2026)  ·  BeInCrypto — “Hackers Steal $75.87M in June 2026” (1 jul. 2026)

Volgende editieNext edition

Editie #006 verschijnt volgende maandag — elke week een nieuwe crypto scam geanalyseerd.Edition #006 arrives next Monday — a new crypto scam analysed every week.

← Alle edities bekijken← View all editions