Multisig hack timeline

Humanity Protocol2026-06 $36M

3-of-6 and 3-of-5 keys were all on one laptop; attacker built an offline Safe transaction for a malicious bridge upgrade.

What happened

3-of-6 and 3-of-5 keys were all on one laptop; attacker built an offline Safe transaction for a malicious bridge upgrade.

Transaction-level mechanics

Public post-incident disclosures do not include full transaction calldata or execution traces for this incident.

TODO: Add exact Safe transaction hash, decoded actions, and the on-chain state changes once verified primary sources are available. For now, the attack vector summary above is derived from public reporting.

What independent decoding / hash verification / config scanning would have caught

Tool can't detect key co-location, but transaction/implementation drift monitoring would surface the malicious bridge upgrade and implementation change — with alerting, possibly in time to react.

Verdict

Could have helped partially