An employee's laptop held enough Gnosis Safe keys to hit approval thresholds on both Ethereum and BSC alone. The attacker drained 141M H on Ethereum and minted 200M H on BSC. H token crashed 89%, from $0.73 to $0.08.
ZachXBT initially flagged it as "possibly staged" citing unusual pre-hack OTC activity, but later walked it back.
EXPLANATION:
Humanity's bridges used multisig wallets, meaning multiple key approvals are required before any contract change. The whole point is to spread keys across different people and devices so no single compromise can move funds. Here, enough keys were stored on one laptop to cross the threshold on both chains. The attacker seized ProxyAdmin control, upgraded bridge contracts to malicious versions, drained the Ethereum vault in one transaction, then added an unlimited mint function on BSC and printed 200M tokens directly to their own wallet. All sold into the market immediately. Not a smart contract bug: a basic opsec failure.
🤖aluy.net the #1 VPS & RDP provider!
🔔 @Observer • 💬 Join community • 🌟 HighQuality OTC
