Crypto projects lost $65.9 million across 20 security incidents in June, with the month’s biggest breaches stemming from compromised credentials, excessive administrative privileges and bridge validation flaws rather than previously unknown software vulnerabilities, according to Hacken, a blockchain cybersecurity and smart contract auditing company.
- Crypto projects lost $65.9 million across 20 security incidents in June, according to Hacken.
- Nearly half of the losses came from compromised access controls rather than flaws in blockchain code.
- Researchers say the industry's recurring failures point to operational security problems that remain unresolved.
Hacken’s June Pulse report said only $2.5 million was recovered from two incidents. The firm’s researchers estimated that the three largest attacks accounted for more than 85% of all losses during the month. “The industry isn’t facing a shortage of warnings — it’s facing a shortage of fixes,” Hacken wrote.
Humanity Protocol Recorded the Largest Loss
The biggest incident involved Humanity Protocol, a decentralized identity project building proof-of-humanity infrastructure for blockchain applications. Malware on a foundation team member’s device exposed private keys controlling wallets on multiple blockchains, Hacken said. The attacker drained funds from more than 17 wallets and also gained proxy administrator privileges, allowing roughly 100 million unbacked H tokens to be minted.
The token fell between 80% and 90% within hours after the additional supply entered the market, according to the report.
Hacken said the incident resulted from shared operational access rather than a flaw in the protocol’s smart contracts. The firm recommended separating custody keys from upgrade authority and protecting administrative functions with dedicated hardware wallets, air-gapped systems and timelocks.
Have a development worth tracking?
Share product launches, funding announcements, partnerships, research findings and market developments with The Grey Terminal's readership.
→ Submit a Press ReleaseApproval Abuse Cost MEV Bot Operator $15M
The second-largest incident targeted JaredFromSubway, an operator known for Ethereum-based maximal extractable value (MEV) trading bots. Attackers deployed 66 counterfeit token wrappers and liquidity pools that manipulated the bot’s automated approval process before draining Wrapped Ether (WETH), USD Coin (USDC) and Tether (USDT) worth about $15 million, Hacken said.
The operator later offered a $1 million bounty for information leading to the recovery of the funds, but no reward was claimed, according to the report. Hacken said automated approval systems should restrict permissions to verified contracts, limit approval scopes and revoke approvals once transactions are completed.
Bridge Validation Flaw Led to Syscoin Exploit
The third-largest breach affected the Syscoin Bridge, part of Syscoin, a blockchain network focused on interoperability. According to Hacken, a validation flaw allowed attackers to create roughly 5 billion SYS tokens on the bridge’s UTXO chain without locking equivalent assets on the corresponding blockchain.
Syscoin paused the bridge before the full amount could be withdrawn, limiting realized losses to about $10 million, the report said. Hacken said the flaw resembled the Verus-Ethereum bridge exploit disclosed in May because both incidents validated each side of a transfer independently without verifying that the transferred amounts matched.
The three incidents together represented more than 85% of June’s reported crypto losses. It Underscores how compromised credentials, administrative controls and transaction validation remained central attack vectors during the month, according to Hacken.
“In May the offensive-defensive AI gap inverted. In June it widened. Attackers are using AI to manufacture malware at scale. Defenders are still running one-time audits. That mismatch is now showing up in the loss data, Hacken noted.
Activate Terminal Layer
Structural analysis of the systems, pressures, and stakeholders behind this story.





