Humility Protocol Says Bridge Exploit Led to $36M Loss

Humility Protocol said on X that its H token was hit by a coordinated attack across Ethereum and BNB Smart Chain (BSC), with more than $36 million in assets confirmed stolen and sold. The team's initial findings point to a compromised employee computer that exposed private keys linked to the multisignature wallet controlling the Hyperlane Bridge ProxyAdmin. On Ethereum, the attacker obtained three of the six owner keys for the Gnosis Safe, transferred ProxyAdmin ownership to an address they controlled, upgraded the bridge contract to a malicious implementation, and moved about 141.2 million H tokens in a single transaction. On BSC, the attacker gained control of three of five keys tied to the Safe wallet, took over the ProxyAdmin through the same method, deployed a malicious contract with unlimited minting functionality, and minted 200 million H tokens to their own wallet in two transactions. Humility said deposits and withdrawals for the affected bridge service have been suspended. The project is working with exchanges and partners to limit losses, cooperating with law enforcement, and pursuing recovery of part of the stolen funds.