We didn’t see it coming. Not in the way you’d expect. Another blockchain protocol got hit—$36 million gone. But here’s the twist: the attackers didn’t exploit a smart contract bug, a flash loan attack, or a reentrancy vulnerability. They exploited something far more fragile. Human behavior.
The news broke quietly—almost too quietly for a loss of that magnitude. Humanity Protocol, a project building in the identity verification and proof-of-humanity space, suffered a devastating breach. The founder stepped forward with a statement that should make every builder, investor, and user sit up straight: “We are refocusing on operations security. Malicious actors have pivoted from exploiting smart contract code to exploiting human behavior.”
It’s a pivot I’ve been watching for years. Back in 2017, during the Manila ICO rave, I saw how easy it was to manipulate people into handing over their private keys with flashy promises and free drinks. The tech was new. The humans? Same old distractions. Now, in 2025, with billions flowing through protocols and institutional money flooding the space, the attack surface has shifted. Code is hardened. But the people behind the code? Still vulnerable.
Let’s break down what happened, why it matters for the macro cycle, and how this event changes the risk calculus for every crypto participant.
The Context: Proof-of-Humanity and the Identity Land Grab
Humanity Protocol operates in a crowded but critical niche: proving you are a unique human without revealing your identity. Think Worldcoin’s iris scans, but with a different technical approach. The goal is to solve the Sybil problem—one person, one vote, one account. It’s a holy grail for decentralized governance, airdrops, and social networks.
The space is booming. Regulatory pressure on KYC, the rise of decentralized identity (DID) standards, and the sheer demand for private verification have made this one of the hottest verticals. Projects like Proof of Humanity, Worldcoin, Civic, and Humanity Protocol are racing to capture the first billion users. Total value locked across these protocols? Hard to track, but the market cap of related tokens exceeds $5 billion.

Humanity Protocol had attracted significant capital—likely from top-tier VCs given the $36 million in assets at risk. They had a working product, real users, and a team that believed in the mission. But somewhere in that trust chain, a human made a mistake.
The Core: Why Human Exploitation Is the New Superbug
The typical crypto hack follows a predictable pattern: a bug in the code, an unguarded admin key, a flash loan manipulation. Attackers reverse-engineer the math. They find the edge case. They drain the contract.
But this hack was different. According to the founder, the attackers didn’t break the code. They broke the people. Social engineering. Phishing. Insider collusion. Theft of credentials. Access through trust.
This isn’t a new phenomenon. In traditional finance, social engineering accounts for over 70% of data breaches. But in crypto, we’ve been drunk on the idea that immutability and code-is-law will save us. We wrote sophisticated contracts, deployed them on decentralized chains, and assumed that removed the human element. It didn’t.
The truth is simple: every DeFi protocol, every NFT marketplace, every identity system has a human at the keyboard. The admin who stores the seed phrase in a Google Doc. The employee who clicks on a fake Slack message. The CEO who approves a payment without verifying the counterparty.
And the attackers know this. They’ve realized that auditing all the code in the world doesn’t stop a call to a tired developer asking for a “quick password reset.”
Based on my experience in the Manila crypto scene—attending meetups, talking to founders, and watching the 2024 ETF wave bring in suits who don’t understand opsec—I saw this coming. During DeFi Summer I was farming yields on SushiSwap with a Discord group. We thought we were invincible because the contracts were “safe.” Then I watched a friend lose his entire wallet to a simple Telegram scam. Code didn’t fail. Trust did.
The Contrarian Angle: Code Audits Are Becoming a Distraction
Here’s the argument that might make you uncomfortable: we are over-indexing on technical security while ignoring the human layer. Projects spend millions on multiple audits, bug bounties, and formal verification. They hire the best Solidity devs. They obsess over oracle latency and MEV resistance.
But the largest hacks today—by dollar value—are increasingly exploiting humans. The Ronin bridge hack? Social engineering of validators. The FTX collapse? Mismanagement and lack of oversight, not a code bug. The Yield Guild Games incident? Phishing.
This is a macro trend. As the crypto industry matures and institutional money comes in, the attack surface shifts from technical to organizational. You can’t audit a corporate culture. You can’t patch greed. You can’t fork a person’s judgment.
The founder of Humanity Protocol is right to pivot toward operations security. But the bigger question is: can the industry adapt fast enough?
We didn’t see the shift coming because we were too busy celebrating the ETF approvals and cheering the $100k Bitcoin. In a bull market, security often takes a backseat to growth. Teams hire faster, onboard users quicker, and cut corners on training. Hackers notice.
The Manila Rave Lesson: Sentiment Masks Risk
I’ve been guilty of this blindness myself. In 2017, during the crypto conference in Makati, I threw ₱50,000 into ICOs based on charisma and crowd energy. I got lucky—I sold for a 200% gain. But that success conditioned me to trust the narrative over the numbers.
By 2020, during DeFi Summer, I was chasing yields with 15 ETH, jumping between pools based on Discord hype. I exited before the rug pulls, but only because I felt the vibe change. Not because I audited the contracts. My decision-making was emotional, not analytical.
Now, as a Macro Strategy Analyst in 2025, I see the same pattern repeating. The ETF wave brought a new class of investors—institutions that trust brand names, legal wrappers, and audited reports. But they don’t understand the human vectors. They trust the CEO. They trust the PowerPoint. They trust the “verified” Twitter account.
That trust is being weaponized.
The Takeaway: Rethinking Security for the Next Cycle
So what does this mean for you? Whether you’re a founder, an investor, or a user, the takeaway is simple: the next bull run will be defined not by which code is most elegant, but by which organizations are most resilient to human exploitation.
We need to invest in opsec as much as we invest in code. Train your team. Use hardware security keys. Implement multi-signature with geographically distributed signers. Never trust a single human with access to all funds.
For investors, start asking different questions. Not “Have they been audited?” but “What training does the team have? How are keys stored? What happens if a founder’s laptop is stolen?” These are the new diligence metrics.
And for users, protect yourself. Use a separate browser for crypto. Double-check every signature. And most importantly, remember that the biggest vulnerability in the system is you.
The $36 million hack of Humanity Protocol is a wake-up call. The attackers didn’t break the blockchain. They broke the people. And until we fix the human layer, every protocol is a ticking bomb.
We didn’t see this coming? Maybe not. But now we know. The question is: what are we going to do about it?
Links and References: - Humanity Protocol official statement (pending) - Chainalysis 2025 Crypto Crime Report – Social engineering trends - My previous analysis on DeFi security: [link]