Had a quick look into the Humanity ($H) exploit today. Was running a 3/6 multisig, threshold was met as all keys lived on the same device. Had no timelock either. solgov tracks the Solana equivalent (program upgrade authority, timelock & multisig changes) and I've also added a Token Custody section today. This shows top holders, custody type and wallets that are potentially linked (first funder) Another example of how a timelock could have helped in this situation. solgov provides alerts within TG for governance changes on chain. All of this can be seen on the activity feed on the website The alert function could have highlighted the authority update equivalent. Team could have had chance to react by receiving a notification of weird activity, then they reject the transaction. Users are also made aware of the situation so they have time to react as well I'm aware there's talk about whether this hack was an inside job. Main actionable point I took from this was trying to add more preventative and safety measures on solgov for Solana protocols and users Welcome any feedback or new information as the Humanity exploit continues to surface

Jun 9, 2026 · 4:35 PM UTC

1
7
443
Sort replies: Relevant Recent Liked