Humanity Protocol
Biometric identity network with real category optionality, a major post-hack trust discount, and still-opaque economics.
Humanity Protocol has real identity-market optionality and live token-market relevance, but the 2026 exploit and missing financial disclosure keep the call at research-more and the current sub-$1B FDV only conditionally fair.
Cover facts
Company profile
Humanity Protocol is a Hong Kong-based biometric identity network led publicly by founder and CEO Terence Kwok. Its product story spans palm-based proof-of-humanity verification, reusable credentials, developer-facing identity rails, and partner-led distribution across education, events, institutional crypto workflows, and anti-fraud use cases. Public evidence supports meaningful funding momentum and top-of-funnel adoption, but the operating business remains financially under-disclosed and governance confidence was damaged by the June 2026 exploit.
- Website
- www.humanityprotocol.com
- Founders
- Terence Kwok
- Headquarters
- Hong Kong
- Product
- Humanity sells a proof-of-humanity stack built around palm biometrics, decentralized identifiers, verifiable credentials, developer APIs and SDKs, and a tokenized network that supports validators and ecosystem participation.
- Customers
- End users creating Human IDs, developers integrating identity checks, education and event ecosystems, and institutional or financial-distribution partners rather than a disclosed base of direct enterprise payers.
- Business model
- Public materials imply a mix of token incentives, validator economics, developer and ecosystem activity, and future enterprise credential or verification services, but the exact fee model remains undisclosed.
- Stage
- Series A / token-network private company
- Funding status
- Humanity disclosed a $30M 2024 round at a $1B valuation and a January 2025 $20M Series A at a $1.1B fully diluted valuation; public capital raised is at least about $50M.
Executive summary
Top strengths
- Humanity operates in a real and growing identity, anti-bot, and credential-verification category with visible urgency from fraud and AI abuse.
- The product surface is broader than a single token, spanning palm-biometric uniqueness, reusable credentials, developer tooling, and institution-facing rails.
- Public evidence shows multiple named partner and distribution lanes across education, events, wallets, treasury workflows, and open-finance ambitions.
- Live token-market pricing gives investors current valuation discovery rather than only stale private-round marks.
Top risks
- The June 2026 privileged-key exploit introduced a durable trust and governance discount that any future valuation must absorb.
- Public financial disclosure is weak: no reliable revenue, margin, retention, treasury, or cash-runway view is available.
- Customer quality remains under-proven because most strong public proof is partner-led rather than direct contracted-revenue proof.
- Token valuation is highly sensitive to dilution, supply governance, and recovery narrative rather than to observable cash-flow fundamentals.
- Biometric data handling and cross-border privacy obligations create legal and reputational exposure beyond a typical crypto token project.
Open gaps
- Current revenue, gross margin, and whether any enterprise or institutional workflows generate meaningful recurring cash revenue.
- Treasury composition, unlock policy, token sale governance, and any reserves or liabilities still tied to the June 2026 recovery.
- Post-hack control redesign, including independent evidence on key management, signer policy, and privileged-access hardening.
- Direct customer conversion, retention, and contract depth behind the named partner and integration announcements.
- Reliable 2026 headcount, organization chart, and governance-rights map across company and foundation entities.
Contents
01Company Overview
1.1 Identity, product scope, and why Humanity exists
Humanity Protocol presents itself less as a single app than as a trust infrastructure layer. Its current home page says the network lets institutions, brands, developers, and users verify claims without storing sensitive user data, while its protocol and documentation pages define Humanity as a scalable EVM-based proof-of-humanity system built around biometric identity and zero-knowledge proofs. The product positioning spans both sides of the market: enterprises and brands get privacy-preserving KYC, loyalty, access, and fraud tools, while developers get a sybil-resistant identity layer and users get a portable Human ID. The technical differentiator is the palm-based approach. Official and executive materials repeatedly argue that palm prints and palm-vein signals are less invasive and easier to scale than iris-based alternatives, especially when combined with smartphone capture, scanner hardware, and self-sovereign identity design. In practical diligence terms, that means Humanity is trying to win the proof-of-personhood category by promising lower friction than Worldcoin while still claiming stronger privacy than centralized KYC stacks.[CO001, CO002, CO003, CO004, CO005, CO006]
| Metric | Value / status | Date | Confidence | Gap / notes |
|---|---|---|---|---|
| HQ / operating base | Hong Kong-rooted; launch and funding materials referenced Hong Kong, Dubai, and New York | 2024-2026 | medium | Public materials support Hong Kong as the clearest base, but the operating footprint is broader than a single-city startup profile. |
| Public emergence | Emerges from stealth in 2024 | 2024 | medium | Retained public sources clearly document 2024 launch/stealth emergence; they do not cleanly prove a 2022 formal founding date. |
| Latest disclosed valuation | 1100 | 2025-01 | high | Fully diluted valuation in USD millions from the January 2025 round; later token-market signals are discussed in the valuation chapter. |
| Disclosed capital raised | 50 | 2025-01 | high | At least $30M in May 2024 plus $20M in January 2025; open sources do not prove additional equity capital beyond these rounds. |
| Human IDs milestone | ~7,000,000 | 2025 | medium | Official testnet-beta post reported close to 7M Human IDs; later palm-scan post cited over 8M reservations, which are not identical to verified humans. |
| Wallet addresses | ~10,000,000 | 2025 | medium | Official testnet-beta post reported nearly 10M wallet addresses. |
| Mainnet status | Live with zkTLS credential proofs | 2025-2026 | medium | Launch reporting confirms mainnet availability and early travel/hospitality integrations. |
| Headcount | null | 2026 | low | The retained open record does not provide a reliable current employee count, so staff scale remains a diligence gap rather than a reportable KPI. |
Monetary values are shown in USD millions. Null headcount indicates an unresolved public-data gap, not zero employees.
[CO008, CO009, CO012, CO013, CO019, CO020]Humanity’s logic stack connects identity enrollment, stronger biometric verification, zk credential proofs, developer and enterprise applications, and tokenized validator/community incentives.
This is an architectural abstraction of the product stack rather than an exact data-flow diagram from source code.
[CO003, CO004, CO005, CO021, CO022, CO029]1.2 Leadership, funding history, and who matters economically
The company’s public leadership story is concentrated around founder and CEO Terence Kwok. Retained interviews and launch materials consistently identify him as the founder, public strategist, and chief explainer of Humanity’s privacy and biometrics thesis, while the earliest launch announcement also highlights Yat Siu and Sandeep Nailwal as influential founding-human and ecosystem backers rather than operating executives. Capital formation has been fast and highly crypto-native. Humanity’s May 2024 seed round brought in $30 million at a $1 billion valuation led by Kingsway Capital with participation from Animoca Brands, Blockchain.com, Hashed, Shima Capital, and other investors; the January 2025 round then added $20 million led by Pantera Capital and Jump Crypto at a $1.1 billion fully diluted valuation. Those two financings alone establish at least $50 million of publicly disclosed capital. They also show that investors were underwriting Humanity on protocol ambition and network effects rather than on disclosed revenue. The canonical stakeholder map is therefore less about board governance than about founder centrality, strategic Web3 backers, validator/community alignment, and the still-opaque control rights around the Humanity Foundation and token infrastructure.[CO007, CO008, CO010, CO011, CO012, CO013]
| Person | Role | Background | Founder-market fit / functional coverage | Key-person dependency |
|---|---|---|---|---|
| Terence Kwok | Founder and CEO | Technology entrepreneur and the public architect of Humanity Protocol’s privacy-first identity thesis | Combines category narrative, fundraising credibility, biometrics positioning, and protocol roadmap ownership | High |
| Yat Siu | Founding Human / strategic backer | Animoca Brands co-founder and chairman, highlighted in launch materials as a key ecosystem supporter | Adds Web3 distribution, token-economy credibility, and strategic investor access rather than day-to-day operating control | Medium |
| Sandeep Nailwal | Founding Human / strategic backer | Polygon co-founder cited in the launch materials as an early guide to the protocol | Strengthens chain-design and ecosystem credibility, especially around Polygon CDK and growth into Web3 applications | Medium |
This table captures the visible human leadership layer in public sources; it is not a full board, management, or foundation-governance roster.
[CO007, CO008, CO030, CO031]| Stakeholder | Role | Control or economic importance | Diligence ask |
|---|---|---|---|
| Terence Kwok / founding team | Strategic and product control core | Founder narrative, roadmap authority, and public trust are heavily concentrated around Kwok and a small founding nucleus | Request founder vesting, control rights, and succession planning. |
| Kingsway Capital | Lead investor in May 2024 seed round | Anchored the first disclosed $1B valuation and helped validate the protocol before public testnet scale | Request cap-table ownership, pro-rata rights, and any governance covenants from the seed round. |
| Pantera Capital and Jump Crypto | Lead investors in January 2025 round | Defined the last disclosed $1.1B fully diluted valuation and reinforced the protocol’s crypto-native institutional backing | Request exact security purchased, token/equity mix, unlock terms, and side-letter rights. |
| Animoca Brands and Polygon ecosystem | Strategic backers and distribution validators | Provide ecosystem reach, credibility, and access to builders, gaming, and broader Web3 integration surfaces | Request commercial obligations, validator roles, and any preferential token access. |
| Humanity community / validators / $H holders | Network participation base | Token launch and fairdrop structure make community incentives central to growth and security claims | Request staking concentration, validator distribution, and fairdrop retention behavior. |
| Humanity Foundation / issuer infrastructure | Operational and control layer | Post-hack discourse suggests foundation-level key management and bridge control are economically material to risk | Request legal-entity map, custody policies, and privileged-key governance. |
The map emphasizes parties that matter economically or structurally from open evidence; it is not a substitute for the actual cap table, foundation documents, or token-distribution schedule.
[CO010, CO011, CO012, CO013, CO019, CO021]The best-supported public metrics emphasize financing and top-of-funnel identity growth, while employee scale remains unresolved.
Identity and wallet figures come from official community updates and should not be read as equivalent to paying customers or verified biometric enrollments.
[CO012, CO013, CO019, CO020, CO031, CO032]1.3 Rollout, traction, and the milestone sequence that later chapters should reuse
Humanity’s strongest open evidence is not financial disclosure but network-onboarding velocity. The May 2024 round announcement said the project had already collected more than half a million waitlist signups within a month of emerging from stealth. By late 2024 Humanity said the September 2024 testnet had reached one million Human IDs, and later official updates stepped that figure up to over five million Human IDs, then to close to seven million Human IDs, nearly ten million wallet addresses, and more than five million RWT holders. The phase-two palm-scan rollout then claimed more than eight million reserved Human IDs before biometric verification moved from reservation into actual human authentication. In parallel, the protocol launched $H in June 2025, used the fairdrop concept to frame bot-resistant token distribution, and later pushed mainnet live with zkTLS-backed credential proofs. This sequencing matters because it shows Humanity’s operating model: capture identities first, deepen verification second, then layer tokens, attestations, and real-world integrations on top. For later chapters, the milestone table here should be treated as the single chronology of record.[CO015, CO016, CO017, CO018, CO019, CO020]
| Date | Event | Type | Amount / valuation / status | Participants | Implication |
|---|---|---|---|---|---|
| 2024-Q1 | Public emergence from stealth on Polygon CDK | founding | Protocol unveiled | Human Institute; Animoca Brands; Polygon Labs | Established the project’s public identity and palm-based proof-of-humanity positioning. |
| 2024-05-15 | Seed financing announced | financing | $30M at $1B valuation | Kingsway Capital; Animoca Brands; Blockchain.com; Hashed; Shima Capital | Funded hiring and product development ahead of testnet and proved early investor appetite. |
| 2024-09 | Testnet launched | product | Human ID reservation phase begins | Humanity Protocol community | Started the first phase of the network-growth engine. |
| 2024-12 | 1 million Human IDs on testnet | scale | 1M Human IDs | Humanity Protocol users | Showed early top-of-funnel identity demand. |
| 2025-01-28 | Series A / strategic funding announced | financing | $20M at $1.1B FDV | Pantera Capital; Jump Crypto | Raised the last publicly disclosed round and funded protocol expansion. |
| 2025-Q1 | Over 5 million Human IDs referenced in official roadmap update | scale | 5M+ Human IDs | Humanity Protocol users | Signaled acceleration beyond the initial testnet-launch milestone. |
| 2025-Q2 | Testnet beta update published | product | ~7M Human IDs; ~10M wallets; 5M+ RWT holders | Humanity Protocol users | Established the strongest public set of pre-mainnet usage metrics. |
| 2025-06-25 | $H fairdrop and token launch | product | $H live on exchanges | Humanity Protocol community and validators | Introduced network incentives, governance, and staking economics. |
| 2025-2026 | Mainnet live with zkTLS credential proofs | product | Mainnet live | Humanity Protocol; travel and hospitality partners | Shifted the protocol from waitlist/testnet narrative toward practical credential use. |
| 2026 | Palm scan app rollout begins | product | Phase 2 biometric verification | Humanity Protocol users | Moved the system from ID reservation into actual biometric proof-of-humanity. |
| 2026-06-09 | Security incident and token crash | adverse | ~86% token drawdown reported | Humanity Foundation; token holders | Introduced material trust and governance overhang for all later diligence chapters. |
Dates mix exact dates, quarter markers, and year-only references where the retained public record is directional rather than precise. This is the canonical chronology for the report.
[CO009, CO010, CO012, CO015, CO016, CO017]Humanity progressed from stealth launch to financing, testnet scale, tokenization, mainnet activation, palm-scan rollout, and then a major security setback within roughly two years of public visibility.
Quarter markers are used where the retained public record is milestone-oriented rather than calendar-precise.
[CO009, CO012, CO017, CO021, CO035, CO037]1.4 Governance, adverse signals, and what remains materially unverified
The open record is materially thinner where investors most need underwriting evidence. Humanity’s official communications are rich on community growth, identity reservations, and ecosystem aspirations, but sparse on current employee count, legal-entity map, board composition, customer concentration, and revenue conversion from its large top-of-funnel ID base. The trust narrative also weakened sharply in June 2026, when a widely cited exploit report described unauthorized minting and selling of $H across Ethereum and BNB Chain, an ~86% token collapse, and public accusations that insider controls or privileged-key management were too concentrated. Even if the company’s preferred framing is an external key compromise rather than a protocol design failure, the incident still undercuts the cleanest version of Humanity’s pitch: that a privacy-first identity network should be structurally safer than incumbent alternatives. The right overview conclusion is therefore balanced. Humanity has built a compelling category narrative, shown unusual onboarding momentum, and attracted elite crypto investors, but it has not yet provided enough open evidence to treat Human ID growth as proof of durable monetization or mature governance.[CO027, CO031, CO034, CO035, CO036, CO037]
1.5 Exhibits
02Market Analysis
2.1 Market boundary: Humanity is selling a proof-and-credential layer, not the whole identity stack
The cleanest way to frame Humanity’s market is as the overlap between identity verification, proof-of-personhood, biometric assurance, and reusable digital credentials. Official Humanity materials do not describe a narrow crypto-only niche. They talk about KYC, loyalty, access control, fraud reduction, credential portability, and sybil-resistant application design. That means the included spend is not just blockchain identity wallets; it also includes liveness and biometric proofing, credential issuance and reuse, and selected anti-bot or anti-fraud workflows where proving a unique human matters. The excluded spend is just as important. Humanity is not addressing the whole IAM stack, password management, generic security operations, or every outsourced KYC workflow. The status quo remains fragmented: centralized KYC vendors, social-logins, manual document review, CAPTCHAs, and adjacent proof-of-personhood systems like World ID all solve slices of the same job. This boundary logic matters because it prevents investors from treating the full biometrics market or the full identity-verification market as Humanity’s realistic serviceable market. The right question is which subset of that spending values privacy-preserving, reusable human uniqueness enough to adopt a new networked protocol rather than a cheaper incumbent point solution.[CM001, CM002, CM003, CM004, CM019, CM028]
| Segment / category | Included spend | Excluded spend | Buyer / payer | Relevance |
|---|---|---|---|---|
| Identity verification platforms | Document proofing, liveness, biometrics, fraud orchestration, reusable credentials | Broader IAM, endpoint security, generic cyber tooling | Compliance, fraud, risk, and platform teams | Closest broad public market proxy for Humanity’s enterprise side. |
| Biometric assurance | Palm, face, fingerprint, iris, hardware scanners, matching engines | Commodity sensors with no identity workflow or credential layer | Governments, enterprises, access-control operators | Important enabling layer, but much broader than Humanity’s actual protocol wedge. |
| Decentralized digital identity / verifiable credentials | Wallets, credential issuance, issuer registries, privacy-preserving proofs | Pure token speculation or non-credential consumer wallets | Governments, ecosystems, credential issuers, platform operators | Closest architectural peer set for Humanity’s reusable identity thesis. |
| Proof-of-personhood / anti-sybil | Bot resistance, fairdrop gating, governance integrity, community verification | Generic captcha-only spam control without persistent identity | Protocol foundations, growth, trust & safety teams | Near-term Web3 wedge where Humanity is most directly differentiated. |
| Travel / loyalty / credential reuse | Portable loyalty, account linking, education and professional proofs | Traditional CRM systems that do not require reusable trust credentials | Partnership, product, and operations owners | Represents the real-world bridge from crypto-native identity to consumer utility. |
| Status-quo substitutes | Centralized KYC vendors, social login, manual review, CAPTCHAs, government IDs | — | Incumbent budget owners across identity workflows | These substitutes cap pricing power and slow protocol migration. |
The table defines Humanity’s market by job-to-be-done. Included and excluded spend are analytical judgments derived from the retained source set, not management guidance.
[CM001, CM002, CM003, CM004, CM028, CM030]Humanity’s plausible market sits inside several broader adjacencies, with proof-of-personhood and reusable credentials forming the narrower serviceable wedge.
Upper layers use reported market totals; the lower layers are intentionally qualitative because the retained source set does not support a clean public SOM for Humanity’s exact wedge.
[CM001, CM005, CM006, CM018, CM028, CM034]2.2 Sizing lenses: broad adjacencies are large, but the usable wedge is much narrower
Open market sizing supports only a layered approach. Mordor Intelligence places the 2026 identity-verification market at $15.78 billion, growing to $26.8 billion by 2031 at roughly 11.2% CAGR, while the broader biometrics market is far larger at $67.86 billion in 2026 and forecast at $136.86 billion by 2031 at roughly 15.1% CAGR. Those figures show that buyers already spend real money on identity proofing and biometric assurance, but they do not prove that Humanity can address all of it. Humanity’s nearer wedge is smaller because many biometrics deployments are physical access or state-run systems that do not need decentralized credentials, while many document-centric KYC flows do not need persistent proof-of-personhood. Geography also matters. Mordor shows North America leading current spend while Asia-Pacific posts the fastest growth in both identity verification and biometrics. That is directionally favorable for Humanity because the company’s public footprint is Asia-linked and its early growth narrative is internet-native rather than branch-banking-native. Still, the strongest serviceable market lens is not a single top-down TAM number; it is a stack of adjacent markets anchored by identity verification, biometrics, and digital-credential reuse, with the proof-of-personhood layer treated as a narrower but faster-evolving subsegment.[CM005, CM006, CM007, CM008, CM009, CM010]
| Publisher | Year | Geography | Value | CAGR / growth | Methodology lens | Confidence | Limitation |
|---|---|---|---|---|---|---|---|
| Mordor Intelligence – Identity Verification Market | 2026 | Global | 15.78 USD B in 2026; 26.8 USD B by 2031 | 11.18% CAGR 2026-2031 | Broad identity verification software and services market | Medium | Useful top-down market, but much broader than Humanity’s narrower proof-of-personhood wedge. |
| Mordor Intelligence – Biometrics Market | 2026 | Global | 67.86 USD B in 2026; 136.86 USD B by 2031 | 15.07% CAGR 2026-2031 | Broad biometrics market across hardware, software, and public-sector use cases | Medium | Too broad to treat as directly addressable by Humanity because much of spend is outside decentralized credentials. |
| World Economic Forum – Digital ID inclusion lens | 2023 cited in 2026 context | Global | 850M people without legal ID | Not a revenue CAGR source | Unmet-need lens for digital identity and inclusion | Medium | Population need is not the same as monetizable enterprise spend. |
| FATF digital ID guidance | 2020 official guidance still active in 2026 | Global / regulated finance | No market value quoted | Digital transactions estimated at 12.7% annual growth; 60% of GDP digitized by 2022 | Regulatory demand lens for customer due diligence | Medium | Guidance is regulatory and qualitative; it is not a company-market revenue forecast. |
| Entrust / LexisNexis / ID.me fraud reports | 2025-2026 | Global | Threat-volume lens, not market size | Deepfakes, synthetic identities, and bots all rising sharply | Demand-side urgency lens for proof and verification | Medium | Shows pain intensity, not directly what buyers will spend on Humanity-like solutions. |
This chapter intentionally uses multiple sizing lenses instead of one inflated TAM. Humanity’s true serviceable market is a subsegment sitting inside these broader categories.
[CM005, CM006, CM014, CM015, CM018, CM022]Current-to-forecast ranges show that adjacent identity markets are growing, but also how wide the gap is between Humanity’s narrow wedge and the broader biometrics universe.
Low values are the 2026 market-size estimates and high values are the 2031 forecasts from the same publisher; this is a time-horizon range, not a bull/base/bear scenario.
[CM005, CM006, CM034]2.3 Buyers, users, payers, and the adoption path differ by segment
Humanity’s buyer map is heterogeneous. In Web3, the near-term buyer is usually a protocol foundation, growth team, or ecosystem operator trying to block sybil farming, improve fair token distribution, or increase trust in governance and community incentives. In regulated onboarding, the buyer is more often a risk, compliance, fraud, or platform-security team that cares about lower false positives, better liveness, and reduced synthetic identity losses. In travel, hospitality, education, and professional credentials, the user may be the consumer, but the payer is more likely to be a platform, issuer, or partnership owner seeking lower onboarding friction and portable trust signals. Humanity’s own mainnet positioning around travel loyalty, financial credentials, and educational or professional proofs fits that model. The adoption path is therefore multi-step: users must enroll, stronger verification must be completed, issuers and platforms must recognize the credential, developers must integrate the tooling, and regulators or enterprise risk teams must accept the assurance model. That makes network effects possible but not automatic. A protocol like Humanity can become more valuable as more issuers and applications recognize a single Human ID, yet it can also stall if portable credentials are not standardized enough or if users do not progress beyond low-friction reservation into higher-assurance verification.[CM015, CM016, CM017, CM028, CM029, CM030]
| Segment | Buyer | User | Payer | Workflow | Budget owner | Adoption trigger |
|---|---|---|---|---|---|---|
| Web3 protocols / ecosystems | Foundation, growth, community, governance team | Wallet holder or community participant | Foundation / protocol treasury | Fairdrops, governance, sybil resistance | Growth / ecosystem / foundation ops | Bot abuse, farmer leakage, and governance integrity pressure. |
| Crypto exchanges / wallets | Risk, trust & safety, platform security | Trader, depositor, or account holder | Risk / platform / compliance budget | Onboarding, account recovery, abuse prevention | Risk / trust & safety | Synthetic identity, fake-account, or rewards abuse losses. |
| Fintech / neobank / regulated onboarding | Compliance, fraud, or identity lead | Customer undergoing KYC | Compliance / fraud / onboarding budget | Account opening, ongoing verification, fraud review | Risk / compliance / operations | Rising deepfakes, liveness spoofing, and KYC cost. |
| Travel / hospitality / loyalty | Product partnership or loyalty operator | Traveler / loyalty member | Product / partnership / operations budget | Linking and reusing trusted credentials | Loyalty / product / ops | Desire to reduce repeat onboarding and add verified perks or gated access. |
| Education / employment credentials | Institution or credential issuer | Student, worker, or applicant | Issuer / platform / institution budget | Portable proof of degree, role, or eligibility | Digital transformation / registrar / HR tech | Need for portable, user-controlled proof without exposing full records. |
| Government / public-sector identity services | Agency or digital-identity program office | Citizen or resident | Public-sector digital-service budget | High-assurance identity, authentication, federation | Government IT / identity program | Policy mandates, fraud reduction, and inclusion objectives. |
Buyer, user, and payer diverge across segments. Humanity’s Web3 roots do not eliminate adjacent enterprise or public-sector demand, but they imply different sales motions and assurance requirements.
[CM007, CM008, CM015, CM017, CM029, CM030]Different segments demand different mixes of assurance, credential portability, and growth-oriented consumer activation, which changes both sales motion and market readiness.
Cells are ordinal evidence-backed judgments about where each segment feels the most urgency or value, not measured market-share statistics.
[CM028, CM030, CM032, CM036, CM038]Category adoption compresses from broad curiosity about digital identity into a much smaller pool of users and issuers willing to complete higher-assurance verification and reuse the resulting credentials.
Values are ordinal adoption-step weights that illustrate funnel compression rather than measured conversion percentages.
[CM029, CM030, CM032, CM036, CM038]2.4 Growth drivers are obvious; regulatory and trust constraints are equally real
The demand drivers behind Humanity’s category are unusually visible. Entrust, LexisNexis, and ID.me all describe an identity-fraud environment where deepfakes, injection attacks, synthetic identities, and increasingly agentic or human-like bots are scaling faster than legacy verification controls were built to handle. In that environment, proof-of-personhood and reusable trust signals become more economically valuable. Regulatory context supports the need for stronger infrastructure as well. FATF says robust digital ID can lower cost, improve due diligence, and expand inclusion; NIST’s 2025 update to SP 800-63-4 reinforces the importance of proofing, authentication, and federation; and the European Commission’s digital identity initiative shows that portable credentials are becoming a policy objective, not just a crypto experiment. But the same environment creates constraints. Biometric systems face privacy, consent, and fairness scrutiny, and World Economic Forum materials emphasize that decentralized digital ID still needs fit-for-purpose policy, standards, and governance to avoid reproducing new forms of surveillance or misuse. For Humanity, that means the market is growing for the right reasons, but adoption will reward vendors that combine low friction with credible assurance, interoperability, and trust after incidents—not vendors that only show rapid user acquisition.[CM015, CM016, CM017, CM018, CM020, CM021]
| Driver / constraint | Direction | Timing | Implication | Diligence ask |
|---|---|---|---|---|
| Deepfakes and injection attacks | Driver | Now | Raise urgency for stronger human-verification layers beyond static docs or passwords | Can Humanity’s assurance model resist deepfake and injection bypass at scale? |
| Synthetic identity growth | Driver | Now | Makes continuous verification and higher-assurance onboarding more valuable | Where does Humanity outperform document-only vendors on synthetic identity? |
| Agentic bot traffic and human-like automation | Driver | Now | Supports demand for proof-of-personhood in community, gaming, and account-creation flows | How much of Humanity’s current traction comes from anti-bot demand versus speculative token demand? |
| EU digital identity and reusable credential policy | Driver | Medium term | Improves the policy case for portable credentials and cross-platform trust | Can Humanity interoperate with enterprise and regulatory wallet standards? |
| FATF / NIST assurance expectations | Driver | Medium term | Favors vendors that can explain identity proofing, authentication, and governance clearly | Does Humanity’s model map cleanly onto mainstream assurance frameworks? |
| Privacy and biometric-consent law | Constraint | Now | Raises legal and reputational cost of biometric identity systems | What jurisdictions can Humanity enter without major redesign or local storage controls? |
| Standards fragmentation / issuer acceptance | Constraint | Medium term | Network effects fail if credentials are not accepted across issuers and relying parties | Which external issuers or institutions have already accepted Humanity credentials? |
| Trust damage after security incidents | Constraint | Now | Makes buyers more cautious about protocols with concentrated key or token controls | What concrete post-incident controls can management show to enterprise buyers? |
This register treats growth and friction symmetrically. The same AI-fraud wave that creates demand also raises assurance expectations and punishes governance weaknesses.
[CM015, CM016, CM017, CM021, CM022, CM023]2.5 Exhibits
03Competitors
3.1 Direct proof-of-personhood rivals split by hardware, social graph, vouching, and aggregation
The closest direct rivals are other systems built to prove a unique human rather than merely validate a government document. World ID is the most obvious comparator: it markets universal proof of human, consumer sign-in use cases, and a growing toolkit around deepfake defense, credentials, and rewards, but it still depends on Orb-based verification and carries baggage from the iris-scan debate. BrightID and Proof of Humanity sit at the other end of the design spectrum. BrightID is a public-good, open-source social identity network that avoids personally identifying information and relies on social graph analysis, while Proof of Humanity uses profiles, deposits, vouching, and challenge processes to maintain a sybil-resistant list of humans. Human Passport is the strongest non-biometric aggregator competitor: it packages proof-of-personhood, ZK KYC, and data services for airdrops, governance, spam prevention, and online communities. Against that set, Humanity’s central bet is that palm biometrics plus reusable credentials can deliver lower friction than social or vouching models without inheriting the same hardware friction as World’s Orb system. Another way to say this is that direct rivals disagree on the source of truth for “humanness”: World trusts dedicated hardware, BrightID trusts social connections, Proof of Humanity trusts community vouching and challenge incentives, and Human Passport trusts composable signal aggregation. Humanity is asking the market to trust biometrics plus reusable credentials.[CP001, CP002, CP003, CP004, CP005, CP006]
| Competitor | Category | Scale / funding | Target segment | Differentiation | Limitation |
|---|---|---|---|---|---|
| World ID / World | Biometric proof-of-personhood network | Consumer-scale network ambitions; exact current verified-user count not established in retained set | Consumer apps, rewards, social, gaming, live events | Orb-verified unique human proof, credentials, rewards, deepfake tools | Hardware dependency and heavier privacy/regulatory baggage around iris verification |
| BrightID | Social-graph proof-of-uniqueness | Community-led public good; team roster visible on site | Web3 communities, voting, fair access | Nonintrusive, open-source, no PII, social recovery | Social graph onboarding can be slower and less enterprise-friendly |
| Proof of Humanity | Vouching and challenge registry | Open human registry model; no disclosed enterprise scale in retained set | Governance, airdrops, social, certifications | Deposit, vouch, and challenge mechanics emphasize sybil resistance | Higher friction and slower enrollment than mobile-first systems |
| Human Passport | Aggregator / anti-sybil data layer | 2M+ passports, 120+ partners, 43M+ credentials, $512M+ airdrops secured | Airdrops, governance, communities, spam prevention | Composable stamps, hashed signals, strong web3 distribution | Less differentiated on biometric uniqueness because it aggregates many signals instead |
| Persona | Enterprise identity-verification platform | Mainstream customer roster and 2026 Gartner / 2025 Forrester recognition highlighted publicly | Fintech, marketplaces, crypto, government, education, workforce | Broad workflow breadth across IDV, KYB, KYA, reverification and risk | Not a purpose-built decentralized proof-of-personhood network |
| Humanity Protocol | Palm-biometric credential network | $50M+ disclosed capital and strong Human ID growth, but enterprise scale not publicly proven | Web3 identity, anti-sybil, credential reuse, selected real-world integrations | Palm print plus palm-vein strategy aims to balance accessibility, privacy, and uniqueness | Must prove trust, issuer acceptance, and revenue conversion against more mature rivals |
Scale fields mix directly disclosed metrics and clearly marked unknowns; many competitors do not publish directly comparable user, revenue, or contract counts.
[CP001, CP004, CP006, CP008, CP009, CP011]| Buying criterion | Humanity | World ID | BrightID | Proof of Humanity | Human Passport | Persona |
|---|---|---|---|---|---|---|
| Biometric uniqueness proof | High | High | Low | Low | Low | Medium |
| No-PII / privacy-first narrative | High | Medium | High | Medium | High | Medium |
| Low-friction self-serve consumer onboarding | Medium | Medium | Low | Low | Medium | Medium |
| Enterprise KYC / compliance fit | Medium | Low | Low | Low | Low | High |
| Airdrop / governance / anti-sybil fit | High | High | Medium | High | High | Low |
| Reusable credential / cross-app ambition | High | High | Medium | Low | Medium | Medium |
Cells are evidence-backed ordinal judgments derived from public product positioning, not benchmarked performance test results.
[CP001, CP002, CP004, CP006, CP008, CP010]The direct field clusters into a consumer-biometric corner, a privacy/community corner, an aggregator/distribution corner, and an enterprise-compliance corner.
Axes are ordinal evidence-backed scores summarizing privacy comfort versus assurance / enterprise readiness, not measured benchmark outputs.
[CP019, CP021, CP022, CP023, CP024, CP025]3.2 Adjacent enterprise incumbents may matter more than some web3 peers
The competitive story changes when the buyer is a regulated enterprise rather than a token-driven community. Persona’s public site shows why: it now markets itself as a flexible and secure way to verify real people and businesses online, displays blue-chip customer logos, and highlights recognition from Gartner and Forrester. Its product footprint spans government ID, document AI, selfie recognition, digital ID, KYB, KYA, reverification, and risk reports, which is much broader than Humanity’s current public product proof. Onfido and Jumio remain important substitutes even though their public pages were access-constrained in this run, because they represent the mainstream category of incumbent KYC and liveness vendors that many buyers will reach for first. Civic is instructive for a different reason: its public website now centers AI-agent integration, GTM workflows, and auth tooling, implying that a once-better-known identity brand has shifted strategic focus away from this exact arena. Fractal ID is harder to assess because its site was unavailable during retrieval, but that lack of visibility itself is a competitive signal. The biggest substitute, therefore, may be a hybrid stack: an incumbent KYC vendor for regulated assurance plus a separate anti-sybil layer such as Human Passport, BrightID, or internal heuristics.[CP011, CP012, CP013, CP014, CP015, CP016]
| Competitor | Price / unit / contract model | Included capabilities | Discounts or unknowns | Implication |
|---|---|---|---|---|
| Humanity Protocol | No public list pricing in retained set; economics tied to protocol adoption and tokenized participation | Human ID, palm verification rollout, credentials, fairdrop / staking ecosystem | Commercial package terms for enterprise buyers remain undisclosed | Buyers cannot easily benchmark TCO versus enterprise incumbents yet. |
| World ID | No public self-serve enterprise price in retained set | Proof of human, deep face, face auth, credentials, rewards | Commercial terms not public; hardware footprint is material | World may monetize through ecosystem/network effects rather than simple SaaS. |
| BrightID | Community / public-good model; no standard enterprise pricing in retained set | Social-graph uniqueness, social recovery, fair-access proofs | Monetization appears less standardized than SaaS IDV | Appeals to privacy-minded communities more than procurement-led buyers. |
| Proof of Humanity | Registry / challenge / vouch mechanics; no clear SaaS pricing in retained set | Verified human registry, airdrops, governance, certifications | Economic model is not positioned as classic enterprise software | Useful for governance contexts but harder to benchmark financially. |
| Human Passport | API / data-service style positioning; no transparent public rate card in retained set | Real-time sybil checks, data services, ZK KYC, partner integrations | Likely package- and volume-dependent | Competes on web3 distribution and composability more than on list-price transparency. |
| Persona / enterprise incumbents | Demo-led enterprise contracts, not simple public pricing | IDV, KYB, KYA, risk reports, reverification, case management | Public list prices remain limited or custom | Enterprise buyers may still prefer incumbents because opaque pricing is normal in compliance software. |
The market is overwhelmingly opaque on pricing. Unknowns are explicit rather than guessed.
[CP022, CP028, CP029]Enterprise incumbents and web3-native competitors cover different slices of the identity job, creating room for hybrid stacks rather than a single winner.
Cells are ordinal judgments about product fit by workflow, designed to show stackability rather than raw feature counts.
[CP022, CP026, CP027, CP029, CP035, CP036]3.3 Moat durability depends on acceptance and trust, not on sign-up counts alone
No competitor in this market wins on every axis. World has stronger consumer awareness and a dedicated hardware moat but also more regulatory and privacy sensitivity. BrightID and Proof of Humanity appeal to privacy-oriented and governance-oriented communities but can feel slower or harder to scale to mainstream onboarding. Human Passport already has measurable web3 distribution and a composable multi-stamp model, which makes it a strong substitute for airdrop, governance, and community integrity use cases that do not want biometrics at all. Persona and enterprise incumbents are harder to displace in regulated onboarding because they already fit compliance workflows and have visible customer references. That leaves Humanity in an attractive but unstable middle ground. If palm-based verification truly proves easier to scale than Orb hardware and more usable than vouching-heavy systems while still supporting reusable credentials, Humanity can carve out a distinctive position. If not, buyers can multi-home, mix vendors, or default to whichever layer is most mature for their exact workflow. The key moat variables are therefore issuer acceptance, developer integration, post-incident trust, and whether Human ID becomes a credential other applications actually recognize. That also means competitive analysis cannot stop at product claims. It has to ask which systems get accepted by issuers, which are tolerated by regulators, and which survive real security or governance stress without losing buyer confidence.[CP019, CP021, CP022, CP023, CP024, CP025]
| Moat claim | Threat | Severity | Mitigation / diligence ask |
|---|---|---|---|
| Palm biometrics are lower friction than Orb hardware | World can still win on consumer awareness and a purpose-built hardware moat | High | Demand empirical conversion, dropout, and accuracy data by modality and geography. |
| Human ID can become a reusable credential layer | Buyers may multi-home and use separate KYC plus anti-sybil stacks instead | High | Request live issuer roster, repeat-usage data, and cross-app credential reuse rates. |
| Privacy-first biometrics beat social or vouching models | Privacy-minded communities may still prefer non-biometric systems like BrightID, PoH, or Human Passport | Medium | Prove adoption in communities that currently reject heavier biometric collection. |
| Rapid Human ID growth creates distribution advantage | Growth can commoditize if signups do not convert into trusted integrations or paid workflows | High | Request activation, verification completion, and monetization cohorts. |
| Web3 roots create defensibility in airdrops and governance | Human Passport already has deep distribution in those exact workflows | High | Show why palm uniqueness wins versus multi-stamp aggregation on fraud, UX, or retention. |
| Humanity can bridge web3 and enterprise identity | Persona and other incumbents already own enterprise trust and customer references | High | Request enterprise case studies, compliance controls, and referenceable production customers. |
This risk register focuses on durable competitive threats rather than feature gaps alone.
[CP021, CP022, CP025, CP026, CP027, CP028]Readiness today is strongest for Human Passport in web3 distribution, Persona in enterprise credibility, and World in consumer biometric brand awareness; Humanity remains the “prove-it” middle path.
KPIs are category markers drawn from retained source snippets rather than a normalized scoring model.
[CP009, CP012, CP021, CP023, CP028, CP032]3.4 Exhibits
04Financials
4.1 Public economics are token-first, while cash-revenue mechanics remain mostly opaque
Humanity does not present a conventional software price sheet. The clearest public economic artifact is the H token page, which describes a fixed-supply ERC-20 asset used to reward validators, power developers, and coordinate protocol participation. Fairdrop and staking materials reinforce the same picture: incentives and ecosystem growth sit at the center of the model. That is important because it changes what “financials” mean. The most visible value drivers are token issuance, supply unlocks, credential adoption, and treasury or ecosystem leverage rather than disclosed ARR or seat-based subscriptions. Public materials do imply multiple potential monetization paths — enterprise identity services, credential verification, developer tooling, treasury appreciation, and event or loyalty rails via Moongate — but none of the retained sources disclose contract pricing, realized take rates, or recognized revenue by line. The result is a real economic system with an unclear cash conversion path. Another way to frame the gap is that Humanity has published the supply-side logic of its network but not the income-statement logic of its business. Investors can see how tokens are allocated, when some buckets unlock, and why the community is supposed to care. They still cannot see how much of the resulting demand becomes fees, service revenue, or treasury value captured by the issuer rather than passed through to validators, users, or market traders.[CI001, CI002, CI003, CI004, CI005, CI006]
| Revenue stream | Mechanism | Unit | Current public status | Quality | Diligence ask |
|---|---|---|---|---|---|
| Token value / treasury exposure | Value accretion from the H token ecosystem and related treasury positioning | Token price, FDV, unlock path | Visible through public tokenomics and market data, but issuer economics are undisclosed | Medium strategic relevance, low accounting visibility | Disclose treasury holdings, token sale policy, realized gains/losses, and treasury wallet governance |
| Validator / staking economy | Staking and validation rewards align participation and verification work | Token rewards / staking participation | Publicly visible as product surface, but not as issuer revenue | Good ecosystem signal, weak revenue visibility | Provide staking volume, validator count, yield formula, and treasury capture rate |
| Developer / application activity | Developers use protocol identity and credentials to build apps | API usage, credential checks, integration contracts | Implied by official positioning, no public pricing disclosed | Potentially scalable, not yet proven as cash flow | Disclose paid developer plans, free-to-paid conversion, and contract sizes |
| Enterprise identity / credential services | Organizations could pay for reusable identity and financial or educational credential workflows | Per deployment / contract / verification volume | Use cases are public, monetization terms are not | Strategically important but unproven publicly | Show reference contracts, pilots vs production, pricing, and renewal terms |
| Moongate event and loyalty rails | Ticketing, access control, loyalty, and real-world onboarding via acquired platform | Campaign / event / access workflow | Acquisition broadens surface but no contribution numbers are public | Interesting adjacency, no financial proof yet | Disclose Moongate revenue, margin, customer count, and attach to Human ID growth |
| Fairdrop / community growth | Token emissions drive user acquisition and ecosystem engagement | Token allocation / campaign output | Clearly visible, but better viewed as incentive spend than earned revenue | Useful growth lever, not revenue quality | Quantify CAC-equivalent, fraud savings, and conversion from fairdrop user to retained user |
Rows distinguish possible value-capture surfaces from disclosed accounting revenue; Humanity has not published segment revenue.
[CI001, CI002, CI006, CI007, CI010, CI024]| Offer | Price / unit / contract | List vs realized pricing | Discounts / unknowns | Source note |
|---|---|---|---|---|
| Human ID / credentials | No public list price retained | Unknown | Enterprise contracts, if any, are undisclosed | Official pages discuss product scope, not rate cards |
| $H token | Market-traded token price rather than vendor list price | Public spot price, issuer realization unknown | Price is volatile and not equivalent to revenue | CoinGecko and CoinMarketCap provide market reference only |
| Staking | Yield exists as ecosystem incentive, not disclosed company price | Unknown | Reward formula and treasury capture remain unclear | Staking portal confirms feature presence but not economics |
| Fairdrop campaigns | Token allocation rather than direct cash pricing | N/A | Effective acquisition cost per retained user is undisclosed | Fairdrop is positioned as distribution mechanic |
| Moongate real-world activations | No public pricing retained | Unknown | Acquisition may involve bespoke event or partner terms | Moongate announcement broadens product surface, not price transparency |
Humanity does not currently disclose standardized commercial pricing in the retained public record.
[CI007, CI008, CI009, CI019, CI024, CI025]Humanity’s public revenue logic runs from identity growth into token incentives, integrations, and only then into potential cash monetization.
This bridge is reconstructed from public positioning and tokenomics, not from disclosed management accounting.
[CI001, CI006, CI010, CI015, CI025, CI033]The missing step in the public story is how identity verification and token incentives turn into durable gross profit.
Every step is publicly visible as a narrative, but the conversion rates and cost buckets are not disclosed.
[CI007, CI015, CI017, CI019, CI024, CI035]4.2 Funding and token-market signals are strong enough to prove relevance, not enough to prove durable operating quality
The strongest public numbers are financing and token-market data. Multiple sources support about $50 million of disclosed capital raised across the 2024 round and the January 2025 Series A, while the latter was framed at a $1.1 billion fully diluted valuation rather than a traditional audited enterprise value. Token-market pages in August 2026 put the network at roughly $170 million of spot market capitalization and about $852 million of fully diluted value, which is still large but below the prior financing headline. Top-of-funnel usage metrics also look impressive: Humanity reported 1 million Human IDs, then roughly 7 million IDs and 10 million wallets. But those are adoption indicators, not proof of paid demand. They show that the network and token reached meaningful scale in the market’s imagination; they do not reveal how much revenue, margin, or net cash the system actually produces. That distinction matters more here than in a traditional startup because token networks can look very large on paper while still producing limited current cash generation for the operator. A buyer therefore has to discount valuation headlines until management opens the ledgers behind the narrative.[CI011, CI012, CI013, CI014, CI015, CI016]
| Item | Public evidence | Current value / status | Interpretation | Diligence ask |
|---|---|---|---|---|
| Disclosed capital raised | 2024 raise plus January 2025 round | ~$50M public total | Enough to fund meaningful buildout but not enough to infer current cash | Provide cap table, proceeds by round, and current cash |
| Latest financing benchmark | January 2025 Series A | ~$1.1B FDV | Token-network benchmark, not audited operating EV | Provide round docs and preference / token rights |
| Current token market value | CoinGecko August 2026 snapshot | ~$170M market cap / ~$852M FDV | Public market priced the network below the financing benchmark | Provide treasury mark-to-market exposure and token sale history |
| Runway | Not disclosed | Unknown | Cannot assess financing urgency | Provide monthly burn and 12-month cash plan |
| Debt / credit obligations | No retained evidence of project-finance or debt disclosures | Unknown / none publicly confirmed | Capital stack looks equity-and-token-led from retained set | Provide debt schedules, warrants, and off-balance-sheet obligations |
Round chronology is summarized only as needed for forward capital adequacy.
[CI011, CI012, CI014, CI021, CI022, CI023]The clearest public range today is not revenue but value: disclosed financing benchmark versus current token-market value.
These are source-backed valuation markers, not revenue forecasts or DCF outputs.
[CI012, CI013, CI021, CI022, CI023]4.3 Capital formation looks credible, but runway and unit economics are still hidden behind company-controlled disclosure
From a diligence perspective, Humanity is financeable but not fully underwriteable. It has clearly raised capital, launched token incentives, expanded into mainnet, and responded to a serious exploit with recovery and transparency surfaces. Yet none of that substitutes for the private metrics needed to judge runway or margin quality. The public record still does not disclose revenue, gross margin, burn, cash on hand, retention, customer concentration, CAC, payback, or verification cost per user. The exploit adds another layer of uncertainty because recovery obligations, operational remediation, and trust repair can all absorb resources without creating durable revenue. Compared with a public identity software company, Humanity’s disclosure set is exceptionally thin. The right financial conclusion is therefore cautious: the company has enough capital, product momentum, and token infrastructure to matter, but investors still need a data room before they can price revenue quality, capital adequacy, or post-incident resilience with confidence. This chapter therefore treats unknowns as real diligence blockers instead of smoothing them away with software-style heuristics. If Humanity eventually shows recurring revenue, attractive contribution margins, and controlled post-incident treasury exposure, the case can improve quickly. On the retained public record alone, though, the correct stance is still evidence-constrained rather than optimistic.[CI017, CI018, CI019, CI020, CI027, CI028]
| Metric | Value / status | Confidence | Why it matters | Diligence ask |
|---|---|---|---|---|
| Revenue / ARR | Not publicly disclosed | Low | Core scale metric for underwriting | Provide monthly revenue, ARR, and revenue by line |
| Gross margin | Not publicly disclosed | Low | Determines software vs services quality | Provide GAAP or management gross margin by segment |
| Customer acquisition cost | Not publicly disclosed | Low | Tests whether fairdrop-led growth is efficient | Provide CAC by channel including token-incentive spend |
| Payback period | Not publicly disclosed | Low | Shows efficiency of enterprise/customer acquisition | Provide payback by customer cohort |
| Net revenue retention | Not publicly disclosed | Low | Indicates durability beyond top-of-funnel identity counts | Provide NRR/GRR and churn by segment |
| Verification cost per active user | Not publicly disclosed | Low | Critical for biometric scaling economics | Provide unit cost per palm verification and ongoing credential update |
| Validator payout efficiency | Not publicly disclosed | Low | Shows how much network spend leaks before value capture | Provide validator-reward formula and aggregate payout ratios |
Nulls are deliberate; the public record does not support fabricating unit-economics metrics.
[CI017, CI019, CI031, CI035]| Missing private metric | Impact on underwriting | Exact diligence path |
|---|---|---|
| Revenue by product line | Cannot separate token narrative from cash business | Request board deck or management P&L split |
| Gross margin and hosting / verification cost | Cannot judge whether protocol usage is profitable | Request margin bridge and infra / biometric cost breakdown |
| Cash balance and monthly burn | Cannot assess next-round timing | Request latest balance sheet and 12-month operating plan |
| Retention and paid-customer cohorts | Cannot tell whether integrations expand into durable revenue | Request cohort tables for enterprise / developer customers |
| Treasury and unlock governance | Cannot price dilution and sell-pressure risk | Request treasury wallet mapping, unlock schedule, and token committee policy |
| Exploit remediation cost | Cannot size the economic damage from the June 2026 incident | Request incident cost ledger, legal reserve, and compensation plan |
These are the minimum missing data points required before producing an investment-grade financial model.
[CI017, CI028, CI029, CI030, CI032, CI036]Public evidence points to engineering, ecosystem incentives, and trust repair as the main cost buckets, while classical working-capital burdens remain unproven.
Cells are ordinal and source-backed; they rank visible cost pressure rather than invent precise expense amounts.
[CI020, CI028, CI029, CI034, CI036]4.4 Exhibits
05Product & Technology
5.1 The product now spans proof-of-humanity, portable credentials, and identity-aware applications
Humanity’s public surface has expanded meaningfully since the early “Worldcoin competitor” framing. The homepage, protocol page, and docs now present a broader trust layer: users reserve a Human ID, complete stronger palm-based verification, hold wallet-native credentials, and then reuse those credentials across applications that need proof of personhood, eligibility, or reputation. Mainnet and verifiable-credentials posts make the product ambition even clearer. Humanity is no longer selling only uniqueness proof. It is trying to become an identity graph where education, travel, employment, social, and financial facts can be selectively proven without surrendering raw personal data. That creates a bigger opportunity than one-time onboarding, but it also makes product execution harder because the company has to solve not just biometrics, but portability, developer ergonomics, issuance, revocation, and acceptance across many application contexts. The breadth is strategically attractive because it gives Humanity multiple wedges into the market: consumer identity, developer tooling, credential orchestration, and partner-mediated distribution. It also raises the bar for execution. A company can ship a compelling sign-up experience long before it proves that credential issuance, revocation, portability, and multi-app acceptance work reliably at scale. That is why the most important diligence question is not whether the product map is ambitious; it is whether the operational details behind that map are catching up quickly enough.[CE001, CE002, CE003, CE004, CE005, CE007]
| Module / asset | Primary user | Status / maturity | Differentiation | Diligence gap |
|---|---|---|---|---|
| Human ID | Consumers and ecosystem users | Live identity reservation and account layer | Portable identity anchor across apps | Public record does not quantify active versus dormant IDs |
| Palm verification | Consumers needing stronger uniqueness proof | Public rollout live in 2026 | Palm biometrics rather than Orb hardware or social-vouching models | No public accuracy or failure-rate benchmarks |
| Verifiable credentials | Users, communities, and partners | Live and expanding with mainnet | Wallet-held, selectively shared attestations | No public issuer / revocation performance metrics |
| SDK / API | Web2 developers and app teams | Live public docs plus GitHub repos | OAuth-like integration and preset verifications | No public rate-limit, SLA, or production-customer depth |
| Walrus storage layer | Developers and protocol operators | Live integration announced | Decentralized storage for claims, proofs, and receipts | No third-party audit in retained set |
| Fireblocks support | Institutional treasury and custody teams | Live support announced | Lets institutions operate H through existing custody workflows | Supports assets and treasury operations more directly than end-user identity UX |
Rows distinguish observable modules from missing benchmark proof.
[CE003, CE006, CE010, CE012, CE019, CE022]| User job | Current workflow | Humanity solution | Measurable benefit | Limitation |
|---|---|---|---|---|
| Prove a unique human online | Reserve ID, complete verification, present proof | Human ID plus palm verification | Sybil resistance without centralized identity handoff | No public completion-rate benchmark |
| Prove a reusable attribute | Link credential source and present selective proof | Wallet-held verifiable credentials | Portability across apps and ecosystems | Issuer coverage and revocation SLAs are unclear |
| Add human-aware login to a web app | Implement OAuth-like auth flow and preset checks | SDK/API integration | Faster developer integration than building from scratch | No public enterprise SLA |
| Prove web-native facts privately | Generate zkTLS proof from trusted website data | Mainnet plus Reclaim-based zkTLS | Proof without disclosing raw page contents | Early-stage technology with limited independent validation |
| Enable multi-chain / app verification | Anchor and verify credential data across apps | Walrus-backed storage and APIs | Broader interoperability and decentralized control | Architecture is vendor-described, not independently audited |
| Support institutional treasury operations | Custody and operate H inside existing operations | Fireblocks support for Humanity Mainnet | Lower operational friction for institutions | Treasury support does not itself prove enterprise identity adoption |
Benefits are product-level and directional, not KPI-audited.
[CE003, CE008, CE010, CE012, CE019, CE022]A typical product flow starts with identity enrollment, adds stronger proof and credentials, and then exposes those proofs to apps or partners.
The flow is product-level and generic; it is not a literal protocol sequence diagram.
[CE003, CE006, CE010, CE011, CE025]5.2 The strongest public technical proof is the documentation and SDK surface, not third-party benchmarking
The most persuasive evidence that Humanity is more than a story comes from its developer surface. The SDK/API docs explicitly frame the integration model as OAuth-like. The public TypeScript and React SDK repositories show concrete flows for auth URLs, token exchange, preset verification, credential polling, hooks, and testing mocks, which is far more specific than many private crypto identity projects publish. The GitHub organization also showed dozens of repositories and current August 2026 update activity, suggesting a live engineering cadence. On the architecture side, the public picture is layered: mainnet plus zkTLS for proving web-native facts, credentials that can be wallet-held and selectively shared, and APIs or smart-contract interfaces that can feed applications. Walrus adds a more explicit storage-and-verification architecture by describing decentralized nodes, encrypted-at-rest credential data, and verification receipts. Even here, however, the available proof is mostly self-described. The public record shows how the stack is supposed to work; it does not independently verify that the stack performs at enterprise grade. This is a meaningful advantage in diligence because repositories and docs create observable implementation detail. They reveal naming conventions, developer assumptions, supported presets, and the kinds of applications the team expects third parties to build. At the same time, they can also overstate maturity if they are not matched by production reference customers, performance telemetry, or formal assurance evidence.[CE008, CE012, CE013, CE014, CE015, CE016]
| Layer / component | Role | Dependency | Risk |
|---|---|---|---|
| Palm biometric layer | Proves uniqueness for stronger proof-of-humanity | User device capture plus biometric workflow | Accuracy, spoofing, and privacy controls are not independently benchmarked |
| Human ID / DID layer | Anchors user identity and links credentials | Protocol account model and wallet surfaces | Dormant IDs or low-quality enrollments could dilute usefulness |
| Credential issuance / storage | Stores and presents attestations privately | Wallets, credential formats, and Walrus-backed data plane | Revocation and portability performance are not publicly quantified |
| zkTLS / Reclaim layer | Turns web-native account facts into cryptographic proofs | Reclaim-style proof generation and trusted-site compatibility | Still early and dependent on partner / ecosystem support |
| SDK / API layer | Lets apps request auth and check credentials | Developer docs, hosted APIs, GitHub packages | Private rate limits, uptime, and API economics are undisclosed |
| Institutional operations layer | Lets institutions hold and operate H on mainnet | Fireblocks and related custody infrastructure | Treasury readiness may outpace end-user production adoption |
Architecture is reconstructed from docs, SDKs, and official posts rather than from a formal reference architecture document.
[CE008, CE012, CE014, CE019, CE020, CE022]| Date / stage | Feature / milestone | Status | Implication | Source |
|---|---|---|---|---|
| 2024 testnet | Human ID reservation and early ecosystem growth | Completed | Established the identity funnel before stronger biometrics | Official testnet posts |
| 2025-06 token launch | Fairdrop and staking economics | Completed | Added incentive layer around identity growth | Official fairdrop and big-moves posts |
| 2025-2026 mainnet | Mainnet plus zkTLS and richer credential use cases | Completed / live | Moved product from reservation narrative toward active credential workflows | Official mainnet and third-party coverage |
| 2026 palm rollout | Palm scanning begins | Completed / rolling out | Raised maturity above waitlist-only identity accounts | Official palm-scanning post |
| 2026 Walrus integration | Decentralized storage and multi-chain credential plumbing | Completed / live | Improved architecture story for developers and interoperability | Official Walrus post |
| 2026 Fireblocks support | Institutional custody and treasury operations | Completed / live | Improved operability for institutions holding H | Official Fireblocks post |
Status labels reflect retained public evidence as of 2026-08-07, not internal roadmap certainty.
[CE006, CE007, CE008, CE019, CE022, CE023]Publicly visible architecture runs from user verification upward into credentials, developer APIs, and partner infrastructure.
This stack is synthesized from docs, blogs, and SDK readmes rather than from an engineering blueprint released by the company.
[CE002, CE003, CE008, CE012, CE019, CE022]5.3 Product maturity is real, but trust, reliability, and dependency diligence are still unfinished
Humanity deserves credit for publishing a fairly legible trust narrative. Privacy-preserving verification, wallet-held credentials, zkTLS, encrypted-at-rest data on Walrus, and incident-response surfaces all suggest the team understands that identity products live or die on control over sensitive information. Fireblocks support also shows a willingness to integrate into more serious operational environments instead of remaining a purely speculative token app. But the limits of the public record are still obvious. Retained sources do not prove SOC 2, ISO 27001, uptime history, false-positive rates, liveness-test quality, or independent biometric-accuracy studies. The incident surfaces are useful, yet they also remind investors that privileged-access and operational-security failures can damage the whole stack. The best current read is that Humanity is maturing faster on ecosystem breadth, developer tooling, and partner integrations than on externally validated assurance. That is promising for adoption, but it is not enough to close a full enterprise diligence case. In practice, that means Humanity should be judged like an infrastructure product, not just a branding exercise. Infrastructure buyers care about fallback behavior, incident response, permission boundaries, revocation design, and partner dependency maps. The public materials hint at these topics, but they do not yet close them with the sort of test results or audit artifacts a risk-sensitive enterprise would expect.[CE022, CE023, CE026, CE027, CE028, CE029]
| Control / signal | Status | Scope | Gap |
|---|---|---|---|
| Privacy-preserving verification narrative | Publicly documented | Homepage, protocol, docs, blogs | Narrative is stronger than independent validation |
| Wallet-held credential model | Publicly documented | Verifiable credentials and SDK flows | No public production-scale audit retained |
| Encrypted-at-rest Walrus architecture | Publicly documented | Credential data and receipts on decentralized storage | No retained third-party security review |
| Incident recovery and transparency surfaces | Publicly visible | Claims portal and compromised-address tracker | Shows response capability but also reveals operational risk |
| Conventional enterprise certifications | Not evidenced in retained set | N/A | Need SOC 2 / ISO or equivalent proof |
| Uptime / performance metrics | Not evidenced in retained set | N/A | Need latency, throughput, failure-rate, and availability reporting |
This table separates real public controls from missing enterprise assurance proof.
[CE005, CE020, CE026, CE027, CE028, CE030]Humanity’s public stack depends on a handful of external technical and operational partners.
The DAG highlights disclosed dependencies, not every internal infrastructure component.
[CE008, CE019, CE021, CE022, CE029]Public evidence shows stronger maturity in docs, integrations, and product breadth than in third-party validation or enterprise assurance.
Cells are ordinal judgments backed by retained evidence rather than benchmark scores.
[CE012, CE017, CE022, CE026, CE027, CE028]5.4 Exhibits
06Customers
6.1 The customer story is broad across users, developers, institutions, and partners, but still light on direct payer disclosure
Humanity’s public record no longer supports a narrow reading of the customer base. The obvious user is the end consumer who creates a Human ID and later completes stronger verification. But the retained set also shows at least four additional segment classes: developers building on the identity rails, education or credential issuers using Open Campus, event or loyalty operators reached through Moongate, and institutions or financial distributors reached through Fireblocks and Mastercard-style integrations. This breadth matters because it shows Humanity can tell a many-sided platform story rather than a single-app story. It also creates a recurring diligence problem. The public materials rarely separate buyer, user, and payer. A student, attendee, wallet holder, institution, or developer may all use the system, but the sources do not consistently reveal who is signing a contract, whether that contract is production, or whether any disclosed logo reflects meaningful recurring spend. That ambiguity is especially important for Humanity because some of the strongest public proof is partner-led. In a normal SaaS company, a logo list may still imply a billing relationship. Here, a named counterpart may instead be a distribution ally, an ecosystem integrator, a wallet surface, or a use-case demonstrator. The customer chapter therefore has to stay disciplined about what each proof actually establishes.[CU001, CU002, CU013, CU014, CU020, CU021]
| Segment | Buyer / user / payer | Primary use case | Scale / strategic value | Gap |
|---|---|---|---|---|
| End users / Human ID holders | Users are visible; payer unclear | Reserve identity, prove humanity, hold credentials | Largest top-of-funnel base in retained set | User count is not revenue count |
| Developers / dApps | Developers integrate; payer unclear | Add human-aware auth or credential checks | Critical to ecosystem growth | Paid plan and retention not disclosed |
| Education ecosystem | Students, educators, and institutions via Open Campus | Issue and verify educational credentials | Shows non-crypto-native expansion path | No disclosed institutional contract count |
| Events / loyalty ecosystem | Event operators, communities, and attendees via Moongate | Ticketing, access control, rewards, identity-linked participation | Strongest real-world deployment proof | Revenue contribution undisclosed |
| Institutions / custody / treasury | Institutions reached through Fireblocks | Custody and operate H on mainnet | Improves operability and reach | Does not by itself prove Human ID usage |
| Financial services / open finance | Users and lenders / service providers via Mastercard thesis | Reusable financial eligibility and identity credentials | Potential bridge into real-world finance | Still announcement-level proof |
Segments separate visible users and partner channels from undisclosed direct payers.
[CU001, CU004, CU006, CU008, CU012, CU020]| Metric | Value | Date | Source | Confidence | Implication | Missing denominator |
|---|---|---|---|---|---|---|
| Human IDs | 1M+ | 2024-12/2025 | Official growth post | Medium | Shows early user adoption | Active vs dormant IDs unknown |
| Human IDs | ~7M | 2025-Q2 | Official beta update | Medium | Shows major funnel growth | Verified vs unverified split unknown |
| Wallets | ~10M | 2025-Q2 | Official beta update | Medium | Suggests large account-linked footprint | Paying user share unknown |
| Moongate tickets | 300,000+ | 2026 | Moongate acquisition post | Medium | Shows real-world event distribution base | Not equivalent to Humanity-native paying customers |
| Institutions reachable through Fireblocks | 2,400+ | 2026 | Fireblocks integration post | Medium | Shows broad institutional channel reach | Reach is not same as active use |
| Supported blockchain networks via Fireblocks | 130+ | 2026 | Fireblocks integration post | Medium | Signals distribution into existing ops stack | Does not measure actual customer adoption |
These are adoption or reach markers, not revenue KPIs.
[CU003, CU007, CU009, CU021, CU028]Humanity customer adoption often starts with a user or partner problem, then expands through identity, credentials, and ecosystem integrations.
Journey map summarizes the visible customer logic across multiple segments rather than one literal funnel for every buyer type.
[CU001, CU002, CU020, CU025]Public evidence is strongest at the top of the funnel and gets thinner as questions move toward monetization and retention.
Values are ordinal evidence weights, not actual customer counts.
[CU003, CU007, CU009, CU017, CU018, CU028]6.2 Named proof is strongest where Humanity plugs into existing ecosystems
The best customer evidence in the retained set is named and use-case specific. Open Campus gives Humanity a concrete education narrative around interoperable learner credentials and institution-facing adoption. Moongate gives it the clearest real-world access case, with ticketing, access control, and a disclosed 300,000-plus on-chain-ticket footprint that predates the acquisition. Fireblocks gives institutional operability rather than end-customer identity proof, but that still matters because it lowers workflow friction for institutions already active in digital assets. Walrus shows how developers on Sui-adjacent infrastructure can consume identity signals, while the Korea hackathon post shows that ecosystem builders are using the surfaces in practice. Mastercard adds a financial-services ambition layer around open-finance-powered Human ID. Together these named proofs show credible land-and-expand logic across multiple verticals. What they do not yet show is direct transparency on ACV, contract length, or renewal quality. The additional wallet, mobile-app, and institutional-distribution posts deepen that picture. D’CENT and Hex Trust extend the story into wallet and institutional-support surfaces, while the mobile-app launch suggests Humanity is trying to convert ecosystem awareness into a more repeatable consumer entry point. These are useful proof points, but they still sit closer to enablement and channel expansion than to disclosed contracted revenue.[CU004, CU005, CU006, CU007, CU008, CU009]
| Customer / partner | Segment | Deployment / use case | Production vs pilot | Outcome | Limitation |
|---|---|---|---|---|---|
| Open Campus | Education credentialing | Integrates Open Campus ID and achievements with Humanity credentials | Strategic integration / likely early deployment | Strongest education-sector proof in retained set | No public contract volume or institution count |
| Moongate | Events / access / loyalty | Ticketing, access control, loyalty, and identity-linked participation | Existing platform plus post-acquisition integration | 300,000+ on-chain tickets give unusually concrete distribution proof | Still no disclosed revenue or attach rate to Human ID |
| Fireblocks | Institutional custody / treasury | Supports Humanity Mainnet and H inside existing institutional operations | Production support on partner platform | Shows operational access to a large institutional channel | Treasury support does not prove direct identity-customer adoption |
| Mastercard | Financial identity / open finance | Links Human ID with reusable financial verification workflows | Strategic integration / early motion | Shows ambition to bridge into credit and lending access | Revenue, launch scale, and customer volumes not disclosed |
Named proofs are ranked by concreteness of deployment evidence rather than by publicity value alone.
[CU004, CU006, CU007, CU008, CU009, CU012]Named proofs vary meaningfully in deployment specificity and economic visibility.
Cells are ordinal judgments based on retained source detail rather than contractual disclosure.
[CU004, CU006, CU008, CU010, CU012, CU032]6.3 Durability, concentration, and monetization are still private
The customer chapter turns cautious once the question shifts from proof of existence to proof of durability. The public record does not disclose paying-customer counts, retention, net revenue retention, gross retention, churn, satisfaction, or customer concentration by revenue. It also leans heavily on ecosystem counterparties, which is useful for expansion but risky if partners do not convert into direct customer economics. Top-of-funnel user and wallet metrics are likewise easy to overread. They prove adoption interest, not contract quality. Adverse evidence matters here too. The June 2026 exploit and the resulting governance debate can weigh on trust-sensitive buyers, especially when the identity product is asking users and partners to depend on long-lived credentials. The right underwriting stance is therefore mixed: Humanity has stronger named proof than many early-stage identity protocols, but the public set is still too thin on renewals, ACV, and concentration to call the customer book durable. That gap matters because many early-stage crypto companies can demonstrate ecosystem enthusiasm without proving a durable book of business. Until Humanity discloses repeat usage, contract economics, and how many named partners are fully live in production, investors should treat the customer story as promising but still mediated by partnership narratives.[CU003, CU017, CU018, CU019, CU022, CU023]
| Metric | Value / null | Segment | Confidence | Diligence ask |
|---|---|---|---|---|
| NRR | All paying customers | Low | Request NRR by customer segment and by partner-led cohort | |
| GRR | All paying customers | Low | Request GRR and logo churn | |
| Contract length | Enterprise / partner channels | Low | Request standard term lengths and renewal mechanics | |
| Repeat usage rate | End users / credential holders | Low | Request MAU to credential-usage ratio | |
| Customer satisfaction / reviews | All segments | Low | Request reference calls, NPS, or external review evidence |
Nulls are intentional because the retained public record does not disclose durability metrics.
[CU017, CU018, CU031]| Expansion driver | Concentration risk | Impact | Diligence path |
|---|---|---|---|
| Education credentialing | Could remain a single flagship partnership | Limits proof of institutional repeatability | Request Open Campus rollout and institution count |
| Events and loyalty | May depend too heavily on acquired Moongate channel | Expansion looks partner-led rather than native | Request Moongate customer list and attach rates |
| Institutional ops through Fireblocks | Reach may not convert to active identity workflows | Could overstate enterprise traction | Request active institutional accounts using Humanity Mainnet |
| Financial identity through Mastercard | High publicity could mask low production scale | May remain an ambition rather than revenue driver | Request launch geography, partner funnel, and active-user metrics |
| Token-incentive growth loops | Fairdrop-led acquisition may not equal retention | Can inflate funnel metrics without durable customers | Request incentive cohort retention versus organic cohorts |
The biggest visible risk is dependence on intermediating partners for proof and scale.
[CU022, CU023, CU024, CU025, CU026, CU027]Public proof travels cleanly from partner announcement to visible use case, then weakens once the questions become renewals, ACV, and concentration.
The flow shows where evidence thins out in the retained customer set.
[CU014, CU017, CU019, CU023, CU034, CU035]6.4 Exhibits
07Risks
7.1 Biometric identity creates dense privacy, sanctions, and cross-border legal exposure
Humanity is not just another crypto token project. Its own terms and privacy policy make clear that palm-based verification, biometric processing, sanctions controls, and jurisdiction-sensitive access restrictions are part of the core service model. That instantly places the company inside a tougher legal environment than a typical consumer app. Hong Kong privacy rules emphasize lawful and fair collection, retention discipline, and security. GDPR treatment of biometric data is stricter still, because special-category data cannot be processed casually. U.S. privacy and security expectations also matter if Humanity’s reusable credentials touch financial or consumer contexts. The company’s own documents add another layer: they contemplate provider storage, disclosure of biometric data under applicable law, and broad suspension rights under BVI-governed terms. In other words, the risk is not just “regulation may arrive someday.” Sensitive-data, cross-border, sanctions, and governance exposure are already part of the operating design. For investors, the important implication is that Humanity does not get to hide behind the phrase “decentralized identity.” Decentralization can reduce some centralized-database risks, but the company’s own legal documents show that off-chain governance, processors, law-enforcement requests, sanctions logic, and biometric-data handling are all part of the real-world operating model. Any mismatch between product claims and these operational realities could become a legal and reputational problem quickly.[CR001, CR002, CR003, CR004, CR005, CR006]
| Risk | Evidence trigger | Jurisdiction / venue | Likelihood | Severity | Mitigation maturity | Residual exposure | Diligence path |
|---|---|---|---|---|---|---|---|
| Biometric-data processing restrictions | GDPR Art. 9 and privacy-policy disclosures | EU / cross-border | High | High | Low to Medium | High | Request legal basis, DPIA, and cross-border data-flow map |
| Hong Kong privacy compliance | PDPO requires fair collection, retention, and security | Hong Kong | Medium to High | High | Low to Medium | High | Request Hong Kong compliance memo and processor controls |
| Sanctions / prohibited-jurisdiction exposure | Terms embed sanctions and prohibited-jurisdiction restrictions | BVI / global | Medium | High | Medium | Medium to High | Request sanctions controls, screening vendors, and appeals process |
| Privacy-promise enforcement risk | FTC-style expectation that privacy claims match actual practices | US / consumer protection | Medium | Medium to High | Low to Medium | Medium to High | Compare privacy claims with real storage, disclosure, and provider practices |
Rows rank the highest-evidence legal and regulatory exposures from retained public sources.
[CR001, CR002, CR004, CR006, CR007, CR008]Residual risk remains highest where biometrics, privileged access, and partner-led adoption intersect.
Heatmap uses ordinal rankings grounded in retained evidence rather than synthetic probabilities.
[CR007, CR008, CR014, CR023, CR025, CR037]7.2 The June 2026 exploit proved operational security is a thesis-level risk
The incident record is unusually important because it reveals how failure can happen in practice. Quantstamp’s summary, third-party coverage, and the recovery surfaces all point in the same direction: Humanity’s June 2026 event was driven by phishing, malware, and stolen privileged keys rather than by a conventional smart-contract bug. That is a meaningful distinction. It means the company’s real attack surface includes human operators, key backups, bridge administration, and wallet hygiene, not only the chain code. The scale of the event also matters. Reports point to unauthorized minting, large token theft, and a recovery process complicated by liquidity pools, vaults, smart-contract positions, and post-snapshot purchasers. The company responded with an incident summary, transparency tools, migration mechanics, and compensation processes, which are constructive. But those same steps also demonstrate how much operational complexity now sits behind a product whose core promise is trust. This is why the incident should be read as a control-system failure, not just a bad headline. Smart-contract audits would not have prevented a phished operator, stolen signer keys, or compromised bridge administration. Investors therefore need proof that the company changed people, process, and infrastructure controls after the attack rather than merely replacing tokens and moving on.[CR013, CR014, CR015, CR016, CR017, CR018]
| Failure mode | Evidence trigger | Likelihood | Severity | Mitigation maturity | Residual exposure | Unresolved gap |
|---|---|---|---|---|---|---|
| Privileged-key compromise / phishing | Quantstamp summary and third-party hack coverage | High | Critical | Medium | High | Need post-incident key-management redesign proof |
| Complex recovery edge cases | Claim portal and compensation mechanics | High | High | Medium | Medium to High | Need claims-resolution statistics and residual liability |
| Partnered relaunch / migration execution | Need to coordinate exchanges, bridges, and partners | Medium to High | High | Medium | Medium to High | Need migration completion metrics and partner confirmations |
| Lack of public assurance metrics | No public uptime, certification, or biometric benchmarks | Medium | High | Low | High | Need audit artifacts, SLA data, and independent tests |
Operational rows focus on the risks most directly evidenced by the 2026 incident and surrounding disclosures.
[CR013, CR014, CR015, CR018, CR019, CR020]Humanity’s main risks transmit through trust, compliance, and partner channels into customer growth, treasury flexibility, and valuation.
Shows causal direction rather than quantified loss probabilities.
[CR010, CR021, CR023, CR028, CR035, CR040]7.3 Partner dependence, competitive pressure, and missing operating proof keep residual exposure high
Even if privacy and incident risk were perfectly controlled, Humanity would still face a serious execution challenge. Much of the strongest public adoption proof runs through counterparties: Walrus, Fireblocks, Open Campus, Moongate, Mastercard, and other ecosystem partners. Those relationships are valuable, but they also mean Humanity’s public traction is partly borrowed from external rails it does not fully control. Competition adds another layer. The anti-bot and proof-of-personhood problem is growing, which is good for category demand, yet rival approaches remain available and any future security or privacy controversy could push partners or users toward alternatives. Meanwhile, investors still do not have strong public evidence on certifications, uptime, direct paying-customer retention, or how many partner announcements have turned into durable commercial deployments. The result is a risk profile that is improved by visible mitigations but still highly exposed to recurrence, compliance friction, and disappointing conversion from ecosystem interest into trustworthy operating results. The partner story magnifies that concern. If adoption remains mostly partner-led, then each additional integration increases the amount of external trust, operational coordination, and failure-surface management the company must handle. Growth can still be attractive under those conditions, but only if the underlying control environment becomes visibly stronger than it looked in June 2026.[CR022, CR023, CR024, CR025, CR026, CR027]
| Dependency | Counterparty / channel | Role | Concentration clue | Failure scenario | Severity | Mitigation | Residual exposure |
|---|---|---|---|---|---|---|---|
| Decentralized storage and developer access | Walrus / Sui-adjacent ecosystem | Credential storage and verification path | Public architecture leans on named partner integration | Partner outage or strategy change disrupts data layer | High | Document fallback architecture and portability | High |
| Institutional operability | Fireblocks | Custody and treasury distribution rail | Institutional story relies on partner reach claims | Institutional access narrative weakens if support under-delivers | High | Diversify custody and integration paths | Medium to High |
| Education credentials | Open Campus | Vertical-specific credentialing channel | One flagship proof may overstate broader education traction | Education adoption stays symbolic | Medium to High | Show more issuers and live institutions | Medium to High |
| Events and loyalty | Moongate | Real-world access and event adoption rail | Strongest real-world proof sits in acquired channel | Attach and monetization underperform | High | Report attach rates and post-acquisition growth | Medium to High |
| Financial identity | Mastercard / open finance path | Bridge into real-world financial services | Still announcement-level proof | Financial-services motion fails to convert beyond PR | High | Disclose launch metrics and counterparties | High |
Dependency risk is elevated because partner-mediated proof still outweighs direct paying-customer disclosure.
[CR022, CR023, CR024, CR028, CR039]| Role / function | Dependency or gap | Likelihood | Severity | Mitigation | Diligence path |
|---|---|---|---|---|---|
| Privileged operators / directors | Incident showed individual-device compromise can cascade into protocol crisis | Medium to High | Critical | Post-incident hardening and key segregation | Request org chart, signer policy, and device-control changes |
| Security leadership / IR process | Need repeatable incident response beyond one emergency event | Medium | High | Formalized IR playbook and external forensics | Request IR tabletop and audit schedule |
| Compliance / privacy operations | Cross-border biometric and sanctions obligations are dense | Medium | High | Dedicated privacy and sanctions governance | Request DPO / compliance ownership map |
| Partner management / GTM | Adoption thesis is distributed across counterparties | Medium | High | Structured partner governance and success metrics | Request partner scorecard and renewal / usage metrics |
People risk is elevated because the public record already shows one operator-centric failure path.
[CR004, CR014, CR034, CR035, CR039]| Risk | Monitorable trigger | Threshold / event | Action implication |
|---|---|---|---|
| Repeat privileged-key failure | New incident involving signer, admin, or bridge keys | Any recurrence before stable post-migration operation | Escalate to thesis-break and freeze underwriting |
| Privacy / regulatory escalation | Formal regulator action, major complaint, or forced data-process change | Any material action in EU, Hong Kong, or a key market | Re-underwrite growth and legal reserve assumptions |
| Partner concentration without direct-customer proof | Named partnerships expand but revenue / retention disclosure stays absent | Another 2-3 quarters of proof without customer-economics detail | Discount customer-conversion assumptions |
| Assurance gap remains open | No public certifications, uptime data, or independent biometric tests emerge | By next major financing or enterprise push | Maintain high residual-risk discount |
| Recovery execution falters | Compensation delays, disputed claims, or migration confusion persist | Meaningful unresolved claimant backlog | Increase trust and litigation risk assumptions |
Kill criteria emphasize measurable events that would invalidate a trust-led identity thesis quickly.
[CR018, CR019, CR025, CR036, CR037, CR038]Critical external dependencies cluster around storage, custody, distribution, and regulatory legitimacy.
Dependency map covers only the most visible externally named dependencies in the retained set.
[CR022, CR023, CR024, CR035, CR039]7.4 Exhibits
08Valuation
8.1 The market has repriced Humanity below its funding headline, but not into obvious cheapness
The easiest valuation mistake is to anchor on one number. If an investor uses only the January 2025 $1.1 billion fully diluted valuation, Humanity can still look like a wounded unicorn waiting to recover. If the investor uses only today’s circulating market cap near $170 million, the company can look permanently broken. Neither reading is sufficient. The more disciplined approach is to use all three public markers together: prior financing FDV, live token FDV, and live circulating market value. That framing shows a real post-hack reset, but not a collapse to zero relevance. It also shows why the company is still hard to underwrite. Price has moved much faster than disclosure quality. Investors still do not have public revenue, margin, retention, or treasury detail. That means the market has discovered a token price, but not a defensible intrinsic value. That distinction matters even more in a tokenized system because supply mechanics can preserve a large headline FDV while the realized market value available to current holders is much smaller. An investor who ignores that spread can mistake scarcity for cheapness. An investor who ignores the remaining strategic value can make the opposite mistake and underwrite the asset as if the network has no future option value at all.[CV001, CV002, CV003, CV004, CV005, CV006]
The most supportable public valuation markers are prior financing, current live FDV, and current circulating market cap.
Bars compare public markers from different contexts; they are not apples-to-apples enterprise values.
[CV001, CV002, CV004, CV006, CV008]8.2 The upside case is strategic optionality, while the downside case is unresolved trust and disclosure risk
There is a real reason not to dismiss Humanity outright. It has product breadth, named partners, and category exposure to the bot, fraud, and reusable-credential problems that are growing across crypto and AI-linked workflows. Fireblocks, Moongate, Mastercard-related coverage, and other integrations show that the identity graph could plug into several monetization lanes if execution improves. But the bearish case is equally real. The June 2026 exploit permanently changed the story. Security recovery, governance credibility, and token-supply governance are now inseparable from valuation. The enterprise-AI pivot may eventually broaden the opportunity, yet on current evidence it mostly increases execution uncertainty before it produces more cash flow. Investors are therefore being asked to pay for optionality and recovery while still missing the ordinary operating numbers used to price businesses.[CV010, CV011, CV012, CV013, CV014, CV015]
| Argument | Evidence | What would change the view |
|---|---|---|
| Bull thesis: identity category demand is real and Humanity has credible optionality | Named partner lanes, large user funnel, and product breadth across credentials and trust workflows | Need proof that optionality converts into paying customer economics |
| Bull thesis: the market already repriced a lot of bad news | Current public FDV is below the old $1.1B financing benchmark | Need proof that live token pricing is stable and not just a narrative bounce |
| Anti-thesis: the hack created a lasting governance discount | Exploit, recovery mechanics, and pivot narrative still dominate the story | Need sustained evidence of stronger controls and trust recovery |
| Anti-thesis: lack of revenue disclosure makes all valuation calls fragile | No public revenue, margin, retention, or treasury data | Need operating metrics and treasury governance disclosures |
Each thesis is paired with the diligence item that would upgrade or downgrade it.
[CV010, CV011, CV012, CV013, CV014, CV024]The recommendation flows from strategic relevance through risk and disclosure into a price-sensitive research-more stance.
Recommendation logic is causal, not quantitative.
[CV010, CV012, CV013, CV026, CV029, CV040]Public evidence supports a wide range because valuation hinges on trust recovery and operating-proof quality more than on one clean KPI.
Ranges are scenario outputs derived from public markers and narrative risk, not from discounted cash flow.
[CV032, CV033, CV034]8.3 Public comps frame the disclosure discount more than they frame a clean multiple
Comparable analysis is useful only if it stays humble. Okta, Coinbase, and Palantir are all much larger and much more transparent than Humanity. Their market caps show the outer bounds of what identity software, listed crypto infrastructure, and premium data-platform narratives can become, but their biggest value for diligence is the disclosure contrast. Public-company filings spell out revenue, margins, liquidity, risks, and governance in ways Humanity does not. That does not mean Humanity deserves no value. It means investors should apply a substantial disclosure and governance discount before borrowing any public-company halo. The comparable table in this chapter is therefore a framing tool, not a basis for forcing Humanity into a fake revenue multiple that the public record cannot support. The public comps are still helpful as a sanity check on ambition. They show that identity and trust businesses can become very large when they pair category relevance with verifiable economics and credible control environments. Humanity has category relevance already. What it lacks is the proof layer that lets outsiders know whether that relevance is compounding into durable enterprise value.[CV016, CV017, CV018, CV019, CV020, CV021]
| Scenario | Core assumptions | Valuation range | Probability signal |
|---|---|---|---|
| Bear | Trust drag persists, no meaningful monetization disclosure, and token value compresses toward spot-cap logic | $0.3B-$0.5B FDV | More likely if recovery narrative weakens or another control issue emerges |
| Base | No new incidents, partner optionality survives, but economics stay under-disclosed | $0.7B-$0.9B FDV | Most plausible on current public evidence |
| Bull | Partner lanes convert into credible enterprise or financial workflows and trust rebuild is durable | $1.1B-$1.4B FDV | Requires hard operating proof and restored credibility |
Scenario ranges are analytical outputs tied to public market markers and narrative risk, not management guidance.
[CV032, CV033, CV034]| Comparable | Metric / date | Valuation or multiple | Status | Relevance | Limitation |
|---|---|---|---|---|---|
| Humanity 2025 financing | January 2025 round | $1.1B FDV | Historical private benchmark | Best historical anchor for market expectations | FDV is not the same as audited enterprise value |
| Humanity 2026 live trading | August 2026 public token markers | ~$170M spot cap / ~$852M FDV | Current market signal | Best current public pricing indicator | Driven by token trading and supply assumptions |
| Okta | August 2026 market cap | ~$26.0B | Public identity-software comp | Shows where disclosed identity software can trade at scale | Different business model and full public disclosure |
| Coinbase | August 2026 market cap | ~$39.5B | Public crypto-infrastructure comp | Frames listed crypto-native infrastructure scale | Exchange model is very different |
| Palantir | August 2026 market cap | ~$404.8B | Public data-platform ceiling | Useful upper-bound narrative-plus-disclosure comp | Far larger and economically incomparable |
Comparable set is intentionally small and illustrative rather than exhaustive.
[CV001, CV004, CV018, CV019, CV036]The live market gives enough signals to score price and risk, but not enough to score business quality with conviction.
KPIs mix numeric and categorical markers because public evidence is stronger on market pricing than on operations.
[CV001, CV004, CV005, CV026, CV028, CV040]8.4 Research-more is the most supportable call until revenue and control evidence improve
The final recommendation should stay intentionally unsatisfying to momentum investors. Humanity is not cheap enough on public evidence to earn an easy buy, and it is not broken enough to dismiss entirely. Near current token-market levels, the story becomes interesting only for investors who can tolerate high risk, incomplete operating proof, and a thesis that depends on rebuilding trust after a major incident. A move to buy would require hard evidence on revenue, retention, treasury governance, and post-hack security controls. A move to avoid would be justified by another control failure or by continued inability to turn ecosystem relationships into durable economics. That leaves research-more as the right call, with medium confidence, high risk, and a valuation stance that is fair-to-speculative near live levels but stretched near the old funding headline.[CV026, CV029, CV030, CV031, CV032, CV033]
| Lens | Current read | Evidence basis | Decision implication |
|---|---|---|---|
| Recommendation | Research more | Live token-market price is observable, but business economics remain private. | Stay engaged only with deeper diligence and price discipline. |
| Confidence | Medium | Price and funding history are visible; revenue and treasury data are not. | Use ranges and contingencies, not a single target. |
| Risk rating | High | Post-hack trust, supply overhang, and partner conversion remain unresolved. | Underwrite downside first. |
| Valuation stance | Fair-to-speculative near live levels; stretched near $1.1B FDV | Current pricing is below the last funding headline, but disclosure quality is still weak. | Do not anchor on prior funding alone. |
Summary table is intentionally price-sensitive and evidence-sensitive.
[CV026, CV027, CV028, CV029, CV040]| Trigger | Threshold | Transmission to thesis | Action implication |
|---|---|---|---|
| Repeat security failure | Any new privileged-key or recovery-control incident | Destroys trust-rebuild thesis | Move from research-more to avoid |
| No operating disclosure progress | Still no revenue / retention / treasury disclosure by next major financing cycle | Keeps valuation purely narrative-driven | Maintain heavy discount or pass |
| Partner proof stays symbolic | Partnership count rises but direct economics remain absent | Bull case fails to convert into business quality | Cut upside assumptions |
| Token-supply governance deteriorates | Unlock or treasury behavior undermines market confidence | FDV-based bull case weakens materially | Reprice to lower scenario band |
Kill triggers focus on events that quickly invalidate a token-led recovery thesis.
[CV030, CV031, CV035, CV038]| Topic | Missing evidence | Why it matters | Owner or diligence path |
|---|---|---|---|
| Revenue and gross margin | No public revenue or margin data | Needed to convert token narrative into business value | Management / data room |
| Retention and customer economics | No NRR, GRR, ACV, or cohort disclosure | Needed to test durability of partner-led story | Management / customer cohort deck |
| Treasury and supply governance | No detailed treasury composition or sale policy | Needed to judge dilution and overhang risk | Foundation / treasury committee |
| Post-hack control changes | No independent proof of redesigned key management or ops controls | Needed to underwrite recurrence risk | Security audit / outside assessor |
| Partner conversion | No quantified revenue or production depth for key integrations | Needed to price optionality rationally | Partner scorecards and signed-customer evidence |
These are the minimum workstreams required before issuing a conviction-level investment recommendation.
[CV030, CV035, CV038, CV040]8.5 Exhibits
Disclaimer
This report is based on publicly available information as of 2026-08-07 and is not investment advice. Humanity Protocol is a private, token-network business with limited financial disclosure, so valuation, customer-quality, and governance conclusions remain partially inference-based.
Evidence index
| ID | Statement | Confidence | Sources |
|---|---|---|---|
| CO001 | Humanity’s homepage presents the protocol as an internet trust layer that verifies claims without requiring parties to store user data. | Medium | SO001 |
| CO002 | Humanity says zero-knowledge proofs can verify attributes such as age, income, or identity without revealing the underlying personal data. | Medium | SO001 |
| CO003 | The official positioning spans enterprise verification use cases, consumer Human IDs, and developer-facing sybil-resistant applications rather than a single narrow workflow. | Medium | SO001, SO002 |
| CO004 | Humanity’s docs define the protocol as a scalable decentralized EVM-based proof-of-humanity solution built around biometric data. | Medium | SO024, SO002 |
| CO005 | Humanity’s documentation says its mobile app captures palm prints while dedicated scanners use infrared vein mapping, with both paths protected by zero-knowledge proofs. | Medium | SO025, SO011 |
| CO006 | Official and executive materials frame palm recognition as a less invasive, more scalable alternative to iris-based proof-of-personhood systems. | Medium | SO004, SO010, SO011 |
| CO007 | Terence Kwok is the publicly visible founder and CEO of Humanity Protocol across retained launch and interview materials. | High | SO004, SO008, SO009 |
| CO008 | Public materials place Humanity’s operating identity across Hong Kong, Dubai, and New York, with later interviews most clearly describing the company as Hong Kong based. | Medium | SO003, SO004, SO008 |
| CO009 | The strongest retained public evidence supports a 2024 public emergence from stealth, while a precise earlier formal founding date is not clearly documented in open sources. | Medium | SO003, SO004, SO016 |
| CO010 | Humanity announced a $30 million seed round in May 2024 led by Kingsway Capital at a $1 billion valuation. | High | SO003, SO016 |
| CO011 | The May 2024 round included Animoca Brands, Blockchain.com, Hashed, Shima Capital, and other crypto-native investors. | Medium | SO003 |
| CO012 | Humanity raised $20 million in January 2025 from Pantera Capital and Jump Crypto at a $1.1 billion fully diluted valuation. | High | SO005, SO006, SO007 |
| CO013 | The two disclosed 2024-2025 fundraisings establish at least $50 million of public capital raised. | High | SO003, SO005, SO006 |
| CO014 | Management and coverage linked the January 2025 round to Human ID expansion, proof-of-humanity development, ecosystem integrations, and mainnet or token rollout. | Medium | SO005, SO007, SO008 |
| CO015 | Humanity said it collected more than 500,000 waitlist signups within one month of emerging from stealth. | Medium | SO003 |
| CO016 | Humanity’s public testnet began in September 2024 as the first phase of a three-phase rollout centered on reserving a unique Human ID. | High | SO013, SO016 |
| CO017 | By late 2024 Humanity reported that the testnet had reached one million Human IDs roughly three months after launch. | Medium | SO016 |
| CO018 | An official 2025 roadmap post said the earlier testnet launch had already brought in over five million Human IDs. | Medium | SO014 |
| CO019 | Humanity’s testnet-beta post later reported close to seven million Human IDs, nearly ten million wallet addresses, and over five million RWT holders. | Medium | SO013 |
| CO020 | The palm-scan app rollout began after Humanity said more than eight million users had already reserved Human IDs. | Medium | SO017 |
| CO021 | Humanity’s first fairdrop launched $H on major exchanges on 25 June 2025 and presented the token as the basis for rewards, staking, governance, and validator incentives. | Medium | SO015 |
| CO022 | Official copy frames Human ID as a reusable passport across Web3 and other settings rather than as a one-off login credential. | Medium | SO001, SO015 |
| CO023 | Mainnet launch coverage said Humanity went live with zkTLS so users could prove claims from familiar web2 credentials without exposing the underlying page or account data. | Medium | SO018, SO019 |
| CO024 | At mainnet launch, reported integrations included travel and hospitality loyalty programs from Delta, Emirates, Singapore Airlines, Marriott, and Hilton. | Medium | SO019 |
| CO025 | Launch reporting also positioned Humanity as supporting financial, educational, and professional credentials in addition to travel-linked identity proofs. | Medium | SO019 |
| CO026 | Management said Humanity planned palm-scan rollout milestones across select cities in Asia and Europe during 2025. | Medium | SO010 |
| CO027 | Independent coverage consistently treats Humanity as a direct Worldcoin alternative because it uses palm biometrics where Worldcoin uses iris scans. | Medium | SO010, SO021, SO022 |
| CO028 | Management claims raw biometric information is not kept in centralized stores and is instead shielded through zero-knowledge or segmented credential design. | Medium | SO010, SO011 |
| CO029 | Humanity’s public posture now spans consumer onboarding, developer tooling, validator incentives, and enterprise credential use cases at the same time. | Medium | SO001, SO015, SO019 |
| CO030 | The official blog index shows the roadmap extending beyond core identity into Open Campus, Moongate, and Mastercard-linked credential initiatives. | Medium | SO012 |
| CO031 | The retained open record does not provide a reliable current employee count, executive-bench disclosure, or full foundation-governance map for 2026. | Medium | SO003, SO012, SO026 |
| CO032 | Humanity’s strongest public traction indicators are Human IDs, wallet addresses, referrals, and points holders rather than disclosed paying customers or revenue. | Medium | SO013, SO014, SO015 |
| CO033 | The phase-two palm-scan rollout moved Humanity from identity reservation toward actual biometric verification and future attestations. | Medium | SO017, SO013 |
| CO034 | BanklessTimes framed Humanity’s spring 2026 token surge largely as flow captured from Worldcoin’s credibility collapse rather than as proof of independent business fundamentals. | Low | SO022 |
| CO035 | A June 2026 Crypto Times report said Humanity suffered a roughly $30-32 million exploit involving unauthorized minting and sales of $H across Ethereum and BNB Chain, after which the token fell by about 86%. | Medium | SO023 |
| CO036 | The same adverse report said critics questioned whether privileged-key management, insider controls, or market-making practices were too concentrated around Humanity’s token infrastructure. | Low | SO023 |
| CO037 | By mid-2026 Humanity’s public story had become a mix of strong onboarding momentum and materially higher trust, governance, and security scrutiny. | Medium | SO013, SO017, SO023 |
| CO038 | Later chapters should treat valuation, customer monetization, and mature governance quality as less verified than identity-growth metrics and protocol ambition. | Medium | SO013, SO014, SO022, SO023 |
| CM001 | Humanity’s market is best framed as a privacy-preserving identity and proof layer rather than as a pure crypto-token product. | Medium | SM001, SM002, SM003 |
| CM002 | The included spend relevant to Humanity covers biometric proofing, proof-of-personhood, credential issuance and reuse, and selected KYC, loyalty, and anti-fraud workflows. | Medium | SM001, SM002, SM007, SM025 |
| CM003 | Humanity does not address the full IAM, password-management, or generic security-operations markets, so those budgets should be excluded from its realistic market boundary. | Medium | SM001, SM002, SM014 |
| CM004 | Status-quo alternatives to Humanity include centralized KYC vendors, social-login identity providers, manual review, CAPTCHAs, and adjacent proof-of-personhood systems such as World ID. | Medium | SM013, SM020, SM021 |
| CM005 | Mordor Intelligence estimates the identity-verification market will grow from $15.78 billion in 2026 to $26.8 billion in 2031 at 11.18% CAGR. | Medium | SM008 |
| CM006 | Mordor Intelligence estimates the biometrics market will grow from $67.86 billion in 2026 to $136.86 billion in 2031 at 15.07% CAGR. | Medium | SM009 |
| CM007 | Financial services accounted for 30.72% of identity-verification market share in 2025, making regulated onboarding the largest current spend pool in the retained source set. | Medium | SM008 |
| CM008 | Gaming and gambling is one of the fastest-growing identity-verification segments in Mordor’s market view, growing at 11.24% CAGR. | Medium | SM008 |
| CM009 | Biometric verification led the identity-verification market by solution type in 2025 with 35.84% revenue share. | Medium | SM008 |
| CM010 | Cloud platforms held 65.12% of identity-verification market share in 2025, showing that buyers increasingly expect software-delivered orchestration rather than only appliance-based systems. | Medium | SM008 |
| CM011 | Within biometrics, hardware still leads current revenue while software is forecast to grow fastest at 16.35% CAGR through 2031. | Medium | SM009 |
| CM012 | Contactless biometric systems are growing faster than contact-based ones, which is directionally supportive for smartphone- or scanner-based palm capture models. | Medium | SM009 |
| CM013 | Government and law enforcement represented 38.10% of the biometrics market in 2025, underscoring how much biometric spend sits outside Humanity’s immediate Web3 wedge. | Medium | SM009 |
| CM014 | North America leads current identity-verification and biometrics spending, while Asia-Pacific is the fastest-growing geography in both market lenses. | Medium | SM008, SM009 |
| CM015 | FATF says reliable digital ID can make customer due diligence easier, cheaper, and more secure while also supporting transaction monitoring and financial inclusion. | Medium | SM010 |
| CM016 | NIST SP 800-63-4, finalized in July 2025, sets updated digital-identity guidance spanning identity proofing, authentication, and federation. | Medium | SM011 |
| CM017 | The European Commission’s digital identity program is designed to let people prove identity electronically and use wallet-linked trust services across borders. | Medium | SM012 |
| CM018 | The World Economic Forum notes that roughly 850 million people still lack legal ID and many more lack privacy and control over how their data is shared. | High | SM013, SM014 |
| CM019 | WEF’s privacy-preserving digital ID analysis argues that decentralized credentials can reduce the panopticon problem of centralized identity providers that observe every identity transaction. | Medium | SM013 |
| CM020 | WEF’s Reimagining Digital ID report says decentralized ID could help expand access and user control but still needs fit-for-purpose policy, regulation, and technology to deliver social benefit at scale. | Medium | SM014 |
| CM021 | WEF’s ethics article says future digital identity systems raise serious questions about consent, dignity, authenticity, and misuse as AI-generated replicas become easier to create. | Medium | SM015 |
| CM022 | Entrust says identity fraud has become industrialized and that deepfakes now represent one in five biometric fraud attempts. | Medium | SM016 |
| CM023 | Entrust reports that injection attacks rose 40% year over year and deepfaked selfie attempts increased 58% in one year. | Medium | SM016 |
| CM024 | LexisNexis says synthetic identities now account for 11% of fraud and have increased eight-fold globally year over year. | Medium | SM017, SM019 |
| CM025 | LexisNexis says agentic traffic grew 450% between January and December 2025 while malicious bot attacks rose 59% over the year. | Medium | SM017 |
| CM026 | ID.me says generative AI removes historical bottlenecks in synthetic identity creation and that attackers now target liveness systems with injection-based deepfakes. | Medium | SM018 |
| CM027 | ID.me argues that identity verification can no longer be treated as a one-time checkpoint because fraud now exploits the entire workflow continuously. | Medium | SM018 |
| CM028 | Humanity’s realistic market wedge is the subset of identity demand where buyers care about proving a unique human and reusing that proof across applications. | Medium | SM001, SM003, SM006, SM007 |
| CM029 | Web3 protocols are likely the earliest paying segment because Humanity’s fairdrop and anti-sybil story directly targets farmer resistance, validator incentives, and governance integrity. | Medium | SM006, SM020, SM021 |
| CM030 | Travel, hospitality, fintech, education, and professional credentials are adjacent buyers where reusable trust signals can lower repeated onboarding friction. | Medium | SM007, SM001, SM025 |
| CM031 | The buyer-user-payer split varies by segment, with compliance teams paying in regulated onboarding while product, partnership, or foundation budgets pay in web3 and loyalty-oriented use cases. | Medium | SM007, SM010, SM025 |
| CM032 | Adoption depends on a chain of steps from enrollment to stronger verification to issuer acceptance and cross-platform reuse, so network effects are possible but not automatic. | Medium | SM023, SM024, SM007, SM017 |
| CM033 | Standards fragmentation, privacy law, and cross-border assurance requirements are likely to slow deployment even if raw demand for digital identity rises. | High | SM010, SM011, SM012, SM014 |
| CM034 | Broad biometrics or identity-verification TAMs overstate Humanity’s opportunity because large portions of those markets do not require decentralized credentials or proof-of-personhood. | Medium | SM008, SM009, SM014 |
| CM035 | The strongest present demand driver for Humanity-like products is the rise in AI fraud, synthetic identity, and bots rather than a purely ideological move toward self-sovereign identity. | Medium | SM016, SM017, SM018 |
| CM036 | Humanity’s Human ID and wallet metrics demonstrate strong crypto-native onboarding demand, but they do not by themselves prove paid enterprise market capture or revenue quality. | Medium | SM023, SM024, SM005, SM006 |
| CM037 | Biometric decentralized identity faces meaningful adoption constraints around privacy, consent, and trust that cannot be solved by growth alone. | Medium | SM015, SM016, SM018 |
| CM038 | The market is likely to split between high-assurance regulated identity verification and lower-friction community proof-of-personhood layers, with long-term value accruing to systems that bridge both credibly. | Medium | SM010, SM011, SM012, SM007 |
| CP001 | Humanity and World are both competing to provide a human-only identity or access layer, but World requires Orb-based verification while Humanity emphasizes palm-based onboarding. | Medium | SP003, SP018, SP019, SP024 |
| CP002 | World ID markets itself as universal proof of human for dating, live events, gaming, social media, and related consumer use cases. | Medium | SP003 |
| CP003 | World publicly highlights deep face, face auth, credentials, and rewards on top of its core proof-of-human layer. | Medium | SP003 |
| CP004 | BrightID describes itself as a public-good, nonintrusive, decentralized, open-source social identity network. | Medium | SP005, SP006 |
| CP005 | BrightID says it solves unique identity through social-graph analysis without recording personally identifying information. | Medium | SP005 |
| CP006 | Proof of Humanity positions itself as a decentralized, sybil-resistant list of humans. | Medium | SP007 |
| CP007 | Proof of Humanity’s workflow relies on a profile with name, photo, and video, plus deposit, vouching, and challenge steps. | Medium | SP007 |
| CP008 | Human Passport markets proof-of-personhood tools and data services for both onchain and offchain use cases. | Medium | SP008 |
| CP009 | Human Passport publicly reports 2M+ passports, 120+ ecosystem partners, 43M+ credentials, and more than $512M in airdrops secured against sybils. | Medium | SP008 |
| CP010 | Human Passport says it does not store names, emails, IPs, or personal identifiers and instead uses hashed or reduced signals. | Medium | SP008 |
| CP011 | Persona markets itself as a flexible and secure way to verify real people and real businesses online. | Medium | SP009 |
| CP012 | Persona’s site shows a broad mainstream customer roster and highlights 2026 Gartner and 2025 Forrester recognition in identity verification. | Medium | SP009 |
| CP013 | Persona’s public product taxonomy spans government ID, document AI, selfie recognition, digital ID, KYB, KYA, reverification, and risk reports. | Medium | SP009, SP010 |
| CP014 | Civic’s public website now centers signal-based GTM, Bryn, Auth, and MCP for AI-powered workflows rather than a core human-identity-verification product line. | Medium | SP011, SP012 |
| CP015 | Civic’s public pivot implies that at least one adjacent identity brand has found better monetization outside Humanity’s exact category. | Medium | SP011, SP012 |
| CP016 | Fractal ID’s site was unavailable during this run, limiting public visibility into its current competitive positioning. | Medium | SP013 |
| CP017 | Onfido’s public product page was blocked by security verification during this run, which limited direct comparison of its current product packaging. | Medium | SP014, SP015 |
| CP018 | Jumio’s retrieved public pages were too minimal to extract a detailed current feature or pricing comparison in this run. | Medium | SP016, SP017 |
| CP019 | Humanity differentiates from World by arguing that palm biometrics can deliver lower friction and less invasive capture than Orb-centered iris verification. | Medium | SP018, SP019, SP024 |
| CP020 | Humanity differs from BrightID and Proof of Humanity because it uses biometrics instead of social-graph or vouch-and-challenge proofs. | Medium | SP005, SP007, SP024 |
| CP021 | Human Passport is Humanity’s most direct non-biometric web3 rival because it targets the same anti-sybil, governance, airdrop, and community-integrity workflows. | Medium | SP008, SP021 |
| CP022 | Persona and incumbent KYC vendors are more dangerous in regulated onboarding because they already fit compliance workflows and show broader enterprise proof. | Medium | SP009, SP010, SP017 |
| CP023 | World appears stronger on consumer-network ambition and brand awareness than Humanity, but also carries heavier privacy and regulatory baggage. | Medium | SP003, SP018, SP023 |
| CP024 | BrightID and Proof of Humanity likely offer a more privacy-purist posture than Humanity, but with slower or higher-friction onboarding for mainstream users. | Medium | SP005, SP007, SP019 |
| CP025 | Human Passport benefits from composability and partner-network effects because it aggregates many proof signals rather than insisting on one biometric modality. | Medium | SP008 |
| CP026 | Humanity’s moat depends on whether mobile-accessible palm verification and reusable credentials can outperform both hardware biometrics and non-biometric aggregators. | Medium | SP003, SP008, SP024, SP025 |
| CP027 | Multi-homing is plausible because many buyers can combine a KYC incumbent with a separate anti-sybil or proof-of-personhood layer. | Medium | SP008, SP009, SP017, SP021 |
| CP028 | Pricing and packaging are generally opaque across this field, with enterprise demos, ecosystem incentives, or community models more common than transparent rate cards. | Medium | SP008, SP009, SP017 |
| CP029 | A major substitute for Humanity is internal build around a mainstream KYC vendor plus CAPTCHAs, manual review, and separate anti-abuse heuristics. | Medium | SP009, SP017, SP021 |
| CP030 | Regulatory and trust posture is a buying criterion, so biometric rivals with more controversy or weaker controls can lose despite stronger distribution. | Medium | SP018, SP019, SP023 |
| CP031 | Persona’s visible customer logos provide stronger public proof of mainstream enterprise adoption than Humanity currently discloses. | Medium | SP009, SP020 |
| CP032 | Human Passport’s published passport, partner, and credential counts imply stronger current web3 distribution than Humanity’s named partner set alone. | Medium | SP008, SP020 |
| CP033 | Proof of Humanity’s challenge mechanism may be especially durable in governance contexts even if it is slower for mass onboarding. | Medium | SP007 |
| CP034 | Civic’s reduced focus on this category narrows its direct rivalry today but also illustrates monetization risk inside decentralized identity. | Medium | SP011, SP012 |
| CP035 | Humanity occupies a potentially unstable middle ground between enterprise KYC incumbents and privacy-first community proof systems. | Medium | SP009, SP019, SP024 |
| CP036 | Long-term competitive durability is more likely to come from issuer acceptance, developer integrations, and trust after incidents than from raw sign-up counts alone. | Medium | SP020, SP021, SP022, SP025 |
| CI001 | Humanity’s public token materials frame $H as the economic incentive layer for validators, developers, and protocol participation rather than as a simple equity proxy. | Medium | SI001, SI002 |
| CI002 | The $H page says the token is meant to reward validators who uphold identity integrity and to fuel developers building applications on the network. | Medium | SI001 |
| CI003 | Humanity publicly states that $H has a fixed supply of 10 billion ERC-20 tokens. | High | SI001, SI003 |
| CI004 | The published allocation table reserves 19% for early contributors and 10% for investors. | Medium | SI001 |
| CI005 | The same allocation page shows sizable pools for community incentives, ecosystem funding, identity-verification rewards, and foundation operations, reinforcing a tokenized network-economics model. | Medium | SI001 |
| CI006 | Humanity’s official fairdrop materials present token distribution as a sybil-resistant user-acquisition and ecosystem-bootstrap mechanism, not a disclosed software pricing plan. | Medium | SI005, SI001 |
| CI007 | Public materials describe staking and validation incentives, but they do not disclose a clean fee schedule showing how much protocol activity converts into revenue retained by the company or foundation. | Medium | SI001, SI002, SI005 |
| CI008 | No retained official source exposes list pricing, contract minimums, enterprise subscription bands, or standardized onboarding fees for customers. | Medium | SI026, SI021, SI022 |
| CI009 | That absence of public price disclosure makes Humanity’s monetization model materially less transparent than a typical SaaS identity vendor. | Medium | SI026, SI025 |
| CI010 | Official positioning consistently emphasizes programmable trust, credentials, and token incentives, implying the economic design is closer to protocol adoption plus treasury appreciation than to conventional seat-based SaaS. | Medium | SI001, SI021, SI022 |
| CI011 | Multiple sources support about $50 million of publicly disclosed capital raised across Humanity’s 2024 round and January 2025 round. | High | SI007, SI008, SI009, SI010 |
| CI012 | The January 2025 round was widely described as $20M at a $1.1B fully diluted valuation led by Pantera Capital and Jump Crypto. | High | SI008, SI009, SI010 |
| CI013 | The 2024 raise was explicitly framed as a $30M round at a $1B valuation, giving Humanity headline financing momentum before token launch. | Medium | SI007 |
| CI014 | Because the $1.1B marker is described as fully diluted valuation, it should be interpreted as token-network valuation context rather than as audited operating equity value. | Medium | SI008, SI010, SI001 |
| CI015 | Official milestone posts disclose strong top-of-funnel growth — 1M Human IDs, then 7M+ Human IDs and roughly 10M wallets — but those metrics are not equivalent to paying customers or recognized revenue. | Medium | SI011, SI012, SI006 |
| CI016 | The best public traction metrics are identity reservations, wallet counts, token participation, and ecosystem integrations, not revenue, ARR, or gross margin. | Medium | SI011, SI012, SI015, SI016 |
| CI017 | No retained source discloses revenue, ARR, gross margin, burn, cash balance, CAC, payback, NRR, or runway. | Medium | SI026, SI001, SI021 |
| CI018 | That makes Humanity financially real in capital formation terms but still not publicly modelable in operating-performance terms. | Medium | SI011, SI017, SI003 |
| CI019 | The staking portal confirms an active staking surface, but the retained output is too thin to prove staking volume, yield structure, or treasury capture. | Medium | SI002 |
| CI020 | The fairdrop and staking materials suggest user incentives were central to growth strategy around token launch. | Medium | SI005, SI006, SI002 |
| CI021 | CoinGecko’s 2026 market page shows roughly 2 billion tokens circulating against a 10 billion maximum supply, highlighting the difference between spot market cap and fully diluted valuation. | Medium | SI003, SI001 |
| CI022 | On 2026-08-07 CoinGecko listed Humanity at roughly $170M market cap and about $852M FDV, materially below the prior $1.1B financing headline. | Medium | SI003 |
| CI023 | That gap implies public market trading was discounting the token network below the January 2025 fully diluted financing benchmark. | Medium | SI003, SI012 |
| CI024 | The public token page explicitly links real-human verification to fairdrop eligibility, suggesting growth spending partly took the form of token emissions rather than cash-only marketing. | Medium | SI001, SI005 |
| CI025 | Moongate expands Humanity’s possible revenue surface beyond pure identity verification into event ticketing, access control, loyalty, and real-world activations. | Medium | SI014 |
| CI026 | Even so, the Moongate announcement does not disclose acquisition price, revenue contribution, gross margin, or payback period. | Medium | SI014 |
| CI027 | The mainnet coverage broadens the product story toward credentials and Web2/Web3 reputation, but the public record still stops short of proving recurring enterprise monetization. | Medium | SI015, SI016 |
| CI028 | The June 2026 exploit added a direct economic overhang because token price damage, recovery obligations, and governance scrutiny can all reduce treasury flexibility and customer trust. | Medium | SI017, SI018, SI019, SI020 |
| CI029 | Humanity’s recovery portal shows multiple holder categories requiring manual review, indicating the incident likely created nontrivial operational and compensation complexity. | Medium | SI019, SI020 |
| CI030 | The transparency tracker shows the team treated the incident as an on-chain recovery and disclosure problem, but it does not disclose the total balance-sheet cost borne by the issuer or foundation. | Medium | SI020, SI019 |
| CI031 | Official docs and homepage messaging focus on identity, privacy, and protocol design rather than on revenue recognition or customer billing, reinforcing that financial diligence is still constrained by company-controlled disclosure. | Medium | SI021, SI022, SI026 |
| CI032 | Compared with a public identity platform such as Okta, Humanity offers far less standardized financial disclosure, making comparability on gross margin, R&D intensity, and sales efficiency impossible from public sources. | Medium | SI025, SI026 |
| CI033 | The public record supports a plausible future mix of token appreciation, protocol incentives, developer activity, and enterprise credential services, but it does not yet reveal what share of value accrues as current cash revenue. | Medium | SI001, SI021, SI014 |
| CI034 | Nothing in the retained sources proves meaningful working-capital burdens such as inventory, receivables finance, or project-finance debt; the main capital need appears to be ecosystem building, engineering, and go-to-market execution. | Medium | SI007, SI014, SI021 |
| CI035 | Nothing in the retained sources proves positive unit economics on customer acquisition, identity verification cost per user, or validator payout efficiency. | Medium | SI001, SI002, SI026 |
| CI036 | The most supportable public financial verdict is that Humanity has raised enough capital and built enough token-market infrastructure to matter, but not enough disclosure exists to underwrite revenue quality, margin path, or runway with confidence. | Medium | SI011, SI012, SI017, SI003 |
| CE001 | Humanity’s official positioning spans proof-of-humanity, reusable credentials, and a broader “trust layer” rather than a single KYC workflow. | Medium | SE001, SE002, SE003 |
| CE002 | The public docs describe the protocol as an EVM-based proof-of-humanity solution built around decentralized identifiers and verifiable credentials. | Medium | SE002, SE003 |
| CE003 | Humanity distinguishes Human ID reservation, stronger biometric verification, and reusable credentials as separate layers of the user journey. | Medium | SE003, SE004, SE008, SE007 |
| CE004 | The biometric docs say Humanity uses palm biometrics as the core uniqueness primitive for proof-of-humanity. | Medium | SE004, SE008 |
| CE005 | Official materials emphasize privacy-preserving verification and user ownership rather than centralized storage of raw identity data. | Medium | SE001, SE003, SE004 |
| CE006 | Palm scanning moved from theory into a public rollout phase in 2026, which is stronger evidence of maturity than the earlier waitlist-only Human ID period. | Medium | SE008, SE021, SE022 |
| CE007 | Mainnet is publicly live, and official coverage describes it as the point where Humanity started bridging Web2 and Web3 credentials. | High | SE007, SE016, SE017 |
| CE008 | The mainnet launch post says zkTLS developed with Reclaim is live inside the dashboard. | Medium | SE007, SE005 |
| CE009 | The same post expands the product from simple proof-of-personhood into broader proof-of-reputation use cases such as employment, education, and memberships. | Medium | SE007, SE006 |
| CE010 | Humanity’s verifiable-credentials post frames credentials as wallet-held, selectively shared, and portable across ecosystems. | Medium | SE006, SE003 |
| CE011 | Official examples include humanity proof, membership proof, travel or loyalty credentials, and other attestations rather than only government-ID-style checks. | Medium | SE006, SE007 |
| CE012 | The public SDK/API docs position Humanity as an OAuth-2.0-like integration surface for web applications. | Medium | SE009, SE012, SE013 |
| CE013 | The TypeScript SDK README shows presets for isHuman, age checks, and accredited-investor-style verification flows. | Medium | SE012 |
| CE014 | The connect SDK exposes state, nonce, token exchange, refresh, revoke, and credential-update polling primitives, which is materially more than a thin marketing placeholder. | Medium | SE012 |
| CE015 | The React SDK claims ready-made components can reduce integration time from multiple days to roughly 30 minutes. | Medium | SE013 |
| CE016 | The React SDK also includes typed providers, verification hooks, credential-update hooks, and testing helpers, indicating a maturing front-end integration surface. | Medium | SE013 |
| CE017 | The GitHub organization page showed 31 repositories with multiple recent updates in late July and early August 2026, which is a real developer-activity signal even if stars alone do not prove adoption. | Medium | SE011 |
| CE018 | The docs resources page exposes chain IDs, explorer, faucet, bridge, dashboard, and developer portal links, showing that the public stack includes chain operations in addition to identity UX. | Medium | SE010 |
| CE019 | The Walrus integration says Humanity migrated major credential components, including claims data, proofs, issuance metadata, revocation logs, and verification receipts, onto decentralized nodes. | Medium | SE014 |
| CE020 | That Walrus post also says credential data is encrypted at rest with user-delegated keys and accessed through API abstraction plus cross-chain communication. | Medium | SE014 |
| CE021 | Official Walrus materials imply that Sui developers and smart contracts can request verification results through a simplified API path. | Medium | SE014 |
| CE022 | The Fireblocks integration is an operational rather than purely marketing signal because it places Humanity Mainnet inside institutional custody and treasury workflows already used for other digital assets. | Medium | SE015 |
| CE023 | Humanity says Fireblocks serves more than 2,400 institutions and 130+ blockchains, which, if accurate, broadens the reachable operating environment for H and the mainnet. | Medium | SE015 |
| CE024 | Public third-party coverage consistently describes Humanity as privacy-first and aimed at bridging Web2 and Web3 identity rather than replacing every existing identity system. | Medium | SE016, SE017, SE018, SE019 |
| CE025 | The public product story is therefore broader than a single mobile biometric app: it includes identity reservation, palm verification, credentials, APIs, smart-contract access, and treasury/custody rails. | Medium | SE001, SE007, SE009, SE014, SE015 |
| CE026 | The docs and blogs provide qualitative architecture detail, but they do not disclose false-positive rates, throughput, latency, liveness benchmarks, or independent biometric accuracy tests. | Medium | SE004, SE005, SE007 |
| CE027 | No retained source proves SOC 2, ISO 27001, or similar conventional enterprise assurance certifications for the product surface. | Medium | SE001, SE009, SE010 |
| CE028 | Likewise, the retained set does not provide a public uptime history or formal status-page evidence for the identity, API, or mainnet surfaces. | Medium | SE009, SE010, SE011 |
| CE029 | Visible dependencies include Reclaim for zkTLS, Walrus and Sui-adjacent infrastructure for decentralized storage, Fireblocks for institutional custody, and GitHub-hosted SDK distribution for developers. | Medium | SE005, SE014, SE015, SE011, SE012, SE013 |
| CE030 | The incident response surfaces show the team can publish recovery and transparency tooling quickly, but they also reveal that privileged-access and operational security are real technical diligence items. | Medium | SE023, SE024 |
| CE031 | The connect SDK explicitly supports mock providers and testing helpers, which is a stronger developer-maturity signal than a docs-only API narrative. | Medium | SE012, SE013 |
| CE032 | Humanity’s public use-case map now spans financial reputation, education, travel, event access, governance, and bot resistance. | Medium | SE006, SE007, SE014, SE025 |
| CE033 | The Mastercard coverage, while third-party, supports the view that Humanity is trying to turn Human ID into reusable financial-eligibility infrastructure rather than a one-time login credential. | Medium | SE025 |
| CE034 | The product is more mature on integration surfaces and narrative breadth than on independently benchmarked performance or compliance proof. | Medium | SE009, SE010, SE014, SE015 |
| CE035 | The best public verdict is that Humanity has a real multi-layer identity stack with meaningful developer activity and expanding partner integrations, but it still asks investors to trust a lot of architecture and reliability claims without third-party validation. | Medium | SE007, SE011, SE014, SE015, SE009 |
| CU001 | Humanity’s public record now points to at least five visible customer or partner segment clusters: end users, developers, education ecosystems, event/access ecosystems, and institutional or financial rails. | Medium | SU001, SU002, SU005, SU006, SU007, SU008 |
| CU002 | The official product story still centers on end users creating Human IDs and proving humanity, but the public go-to-market has broadened well beyond consumer onboarding alone. | Medium | SU001, SU017, SU024 |
| CU003 | The testnet and growth posts show user-scale signals — 1M Human IDs, then roughly 7M IDs and 10M wallets — that establish demand but not customer monetization. | Medium | SU003, SU004 |
| CU004 | Open Campus is the clearest education-sector proof in the retained set because the announcement specifies credentialing, learner identities, and institutional engagement goals. | Medium | SU006 |
| CU005 | The Open Campus partnership positions Humanity as the proof-of-humanity and verifiable-credential layer inside education use cases rather than as a generic marketing partner. | Medium | SU006 |
| CU006 | Moongate is the clearest real-world access and event-distribution proof because Humanity acquired infrastructure already used for ticketing, credentialing, and access control. | Medium | SU005 |
| CU007 | The Moongate post says that platform had already powered more than 300,000 on-chain tickets globally, which is one of the strongest quantified deployment indicators in the retained customer set. | Medium | SU005 |
| CU008 | Fireblocks is the clearest institutional-operability proof because it places Humanity Mainnet into an existing custody and treasury environment used by thousands of institutions. | Medium | SU007 |
| CU009 | Humanity says Fireblocks supports more than 2,400 institutions and over 130 blockchain networks, which, if accurate, materially expands the reachable distribution environment for H and related workflows. | Medium | SU007 |
| CU010 | Walrus is better read as ecosystem and developer adoption proof than as traditional customer proof, because the announcement emphasizes Sui developers and app builders using identity signals. | Medium | SU008 |
| CU011 | The Korea hackathon post adds lightweight but useful practitioner proof that third parties were building real-world applications on top of Humanity’s surfaces. | Medium | SU009 |
| CU012 | The Mastercard integration points to a financial-services distribution thesis around reusable Human ID and open-finance credentials, but the retained proof is still partner-announcement level rather than contracted-revenue proof. | Medium | SU010, SU011 |
| CU013 | Taken together, Open Campus, Moongate, Fireblocks, Walrus, and Mastercard show a multi-vertical expansion thesis rather than a single-customer concentration around one dApp. | Medium | SU005, SU006, SU007, SU008, SU010 |
| CU014 | The public customer story is stronger on strategic partner breadth than on direct proof of paying enterprise accounts. | Medium | SU005, SU006, SU007, SU010, SU014 |
| CU015 | Identity Week and FinanceFeeds both frame Humanity’s mainnet as a bridge between Web2 and Web3, supporting a cross-vertical customer thesis around privacy-first identity. | Medium | SU012, SU013 |
| CU016 | The verifiable-credentials materials explicitly broaden the user-value proposition into travel, education, and gated-access workflows, which is relevant for expansion even without direct revenue proof. | Medium | SU025, SU024 |
| CU017 | The public record does not disclose paying-customer counts, ACV, NRR, GRR, renewal rates, or logo churn. | Medium | SU001, SU023, SU017 |
| CU018 | No retained source proves recurring enterprise revenue customers at scale. | Medium | SU001, SU006, SU007, SU010 |
| CU019 | That means the strongest “customers” evidence is deployment or partnership proof, not software-book transparency. | Medium | SU005, SU006, SU007, SU008, SU010 |
| CU020 | The buyer-user-payer mix is still blurry: end users enroll, developers integrate, partners distribute, and an undisclosed party may ultimately pay for enterprise or institutional workflows. | Medium | SU001, SU002, SU024 |
| CU021 | User and wallet counts should not be treated as customer counts, because the public record does not tie those top-of-funnel figures to contracts or revenue cohorts. | Medium | SU003, SU004, SU024 |
| CU022 | Token incentives appear to help customer acquisition and ecosystem engagement, especially around fairdrop and staking, but they also make it harder to judge organic retention. | Medium | SU004, SU021, SU003 |
| CU023 | One visible concentration risk is partner dependence: much of the strongest proof sits in counterparties such as Moongate, Open Campus, Fireblocks, Walrus, and Mastercard rather than in a large disclosed base of direct paying customers. | Medium | SU005, SU006, SU007, SU008, SU010 |
| CU024 | Another concentration risk is that many public use cases remain web3-native or crypto-adjacent, which leaves the story exposed to ecosystem cycles even when the identity concept is broader. | Medium | SU013, SU014, SU015 |
| CU025 | Open Campus, Moongate, and Mastercard each suggest credible land-and-expand logic because they connect Humanity to larger issuance, access, or financial networks beyond one-off signups. | Medium | SU005, SU006, SU010, SU011 |
| CU026 | Fireblocks suggests expansion into institutions that already operate multiple chains, but it does not itself prove those institutions are using Human ID for end-customer identity workflows. | Medium | SU007 |
| CU027 | Walrus suggests expansion into Sui developers and apps, but it is still ecosystem infrastructure proof rather than proof of large paying developer cohorts. | Medium | SU008 |
| CU028 | The strongest quantified outcome signals in the retained set are 300,000+ on-chain tickets at Moongate and 2,400+ institutions reachable through Fireblocks, plus the Human ID and wallet counts from official growth posts. | Medium | SU005, SU007, SU003, SU004 |
| CU029 | Public geography proof is broad but soft: Humanity is clearly operating in global web3 ecosystems, while named proofs touch education, events, and institutional rails across multiple regions without disclosing region-level revenue. | Medium | SU005, SU006, SU007, SU013 |
| CU030 | The exploit and adverse commentary complicate the customer story because trust-sensitive buyers may hesitate until incident response and governance credibility improve. | Medium | SU022, SU016 |
| CU031 | The public set also lacks direct user-satisfaction or review-platform evidence, so quality of experience cannot be inferred from partner announcements alone. | Medium | SU023, SU017 |
| CU032 | The named proofs strongest enough for an IC memo are Moongate for real-world events, Open Campus for education credentials, Fireblocks for institutional operability, and Mastercard for financial-identity ambition. | Medium | SU005, SU006, SU007, SU010, SU011 |
| CU033 | Hackathon and developer-facing evidence is useful, but weaker than named production or distribution partnerships when underwriting customer durability. | Medium | SU008, SU009 |
| CU034 | Humanity’s customer chapter therefore reads stronger on expansion surface and ecosystem fit than on renewals, contract economics, or direct enterprise penetration. | Medium | SU013, SU017, SU023 |
| CU035 | The best public verdict is that Humanity has real adoption vectors and credible named proof across several verticals, but the market still cannot see which of those vectors convert into durable paying customers. | Medium | SU005, SU006, SU007, SU010, SU017 |
| CR001 | Humanity’s terms explicitly contemplate identity verification through palm print and vein image recognition, confirming that biometric processing sits near the center of the service design. | Medium | SR002 |
| CR002 | Humanity’s privacy policy says it may collect, process, store with providers, and disclose biometric data in connection with the service and applicable laws. | Medium | SR001 |
| CR003 | The privacy policy also states users may have deletion and other privacy rights, but those rights are constrained by applicable law and operational obligations. | Medium | SR001 |
| CR004 | Humanity’s terms define Personal Data by reference to the BVI Data Protection Act 2021 and other applicable BVI laws, anchoring the legal framework partly outside Hong Kong or the EU. | Medium | SR002 |
| CR005 | The same terms say disputes are governed by British Virgin Islands law and allow the company to suspend, restrict, or terminate access in multiple circumstances. | Medium | SR002 |
| CR006 | The terms also include prohibited-jurisdiction and sanctions language, meaning compliance exposure is embedded directly into account access and platform usage. | Medium | SR002 |
| CR007 | Hong Kong PDPO guidance requires lawful and fair collection, accuracy controls, retention discipline, and security protection for personal data, which are directly relevant to biometric identity products. | Medium | SR003 |
| CR008 | GDPR Article 9 treats biometric data used to uniquely identify a natural person as special-category data whose processing is generally prohibited unless a permitted condition applies. | Medium | SR004 |
| CR009 | The FTC’s privacy and security guidance reinforces that companies must honor their privacy promises and maintain security appropriate to the sensitivity of the data they possess. | Medium | SR005 |
| CR010 | Because Humanity wants reusable credentials that can touch financial or eligibility contexts, cross-border privacy compliance is a first-order risk rather than a back-office detail. | Medium | SR001, SR004, SR005 |
| CR011 | FATF, NIST, and EU digital-identity materials all support the idea that digital identity systems sit inside a tightening compliance environment where assurance, minimization, and governance matter. | Medium | SR018, SR019, SR020 |
| CR012 | Humanity’s own policy language about provider storage and disclosure means its privacy burden extends beyond just on-chain design into off-chain processors and data handling. | Medium | SR001, SR003 |
| CR013 | Quantstamp’s incident summary says the June 2026 attack involved unauthorized minting and selling of H on Ethereum and BSC after attacker-controlled keys were used. | Medium | SR006 |
| CR014 | The same summary says the attacker phished a director, installed malware, and stole keys, making the exploit primarily an operational-security failure rather than a code bug. | High | SR006, SR010, SR011 |
| CR015 | BSCN explicitly says the incident was not caused by a smart-contract vulnerability but by compromised private keys and operational-security failures. | Medium | SR011, SR012 |
| CR016 | The incident summary says roughly 150 operational H wallets and related gas-funding wallets were also drained, showing a wider privileged-surface problem than one admin key alone. | Medium | SR006 |
| CR017 | BSCN reports about 447 million H tokens were stolen or unauthorizedly minted across the attack, which made the financial and governance impact too large for a simple patch response. | Medium | SR011, SR012 |
| CR018 | The claim portal shows that liquidity-pool, vault, smart-contract, and post-snapshot purchasers require manual review, which adds operational, legal, and customer-support complexity to recovery. | Medium | SR007, SR011, SR012 |
| CR019 | CoinAlert explicitly notes that some claimants may face KYC or AML screening after forensic analysis, which creates privacy and UX risk for holders who expected a frictionless crypto recovery. | Medium | SR012 |
| CR020 | The transparency tracker is a mitigating control because it exposes attacker-linked addresses and movements, but it also publicly evidences how much trust now depends on incident communications. | Medium | SR008, SR006 |
| CR021 | The exploit therefore creates three simultaneous risks: treasury damage, user-trust damage, and proof that privileged-key management is a core technical attack surface. | Medium | SR006, SR009, SR010, SR011 |
| CR022 | Humanity’s customer and product stories remain partner-mediated, so failures in partners or integrations can hit both adoption and perceived safety. | Medium | SR025, SR026, SR027, SR028, SR029, SR030 |
| CR023 | Visible dependencies include Walrus for decentralized storage, Fireblocks for institutional operability, Open Campus for education proof, Moongate for events, and Mastercard for financial-identity distribution. | Medium | SR025, SR026, SR028, SR029, SR030 |
| CR024 | Those dependencies are strategically helpful, but they also mean Humanity’s public traction is partly downstream of counterparties it does not fully control. | Medium | SR023, SR025, SR026, SR028, SR029, SR030 |
| CR025 | The public record still does not prove SOC 2, ISO 27001, formal uptime reporting, or independent biometric-accuracy benchmarks, leaving assurance risk open. | Medium | SR001, SR002, SR024 |
| CR026 | AI-driven fraud and bot growth are genuine market tailwinds for Humanity’s category, but they also raise the bar for failure because customers buy identity products to reduce trust risk, not add more. | Medium | SR021, SR022, SR024 |
| CR027 | Competitive pressure from World and non-biometric identity alternatives means Humanity may face reputational damage faster if security or privacy claims underperform. | Medium | SR013, SR014, SR015 |
| CR028 | The public customer record remains light on direct paying-customer disclosures, which itself is a risk because partner announcements can mask concentration or weak retention. | Medium | SR028, SR029, SR030 |
| CR029 | Market research and identity-fraud reports support a large addressable need, but they do not remove the execution risk of turning interest into safe, compliant deployment. | Medium | SR016, SR017, SR021, SR022, SR023 |
| CR030 | Humanity’s terms reserve broad rights to restrict access, and that can be useful for sanctions compliance but risky for user trust if enforcement or appeals processes are opaque. | Medium | SR002 |
| CR031 | The privacy policy’s broad disclosure and provider language means an investor should not assume the system is purely self-custodial or purely on-chain from a data-governance perspective. | Medium | SR001, SR025 |
| CR032 | BSCN says Humanity planned to relaunch mainnet in the weeks after the recovery and coordinate with exchanges, bridges, and liquidity partners, which highlights complex execution dependencies during crisis response. | Medium | SR011 |
| CR033 | The recovery design includes a compensation fund and a one-to-one airdrop, which are visible mitigations but also admissions that the edge-case burden is material. | Medium | SR007, SR011, SR012 |
| CR034 | The official incident summary naming a director’s compromised machine and key backups indicates people and process controls are at least as important as smart-contract audits for Humanity. | Medium | SR006, SR010 |
| CR035 | Because biometric and credential systems involve sensitive personal data, any future privacy controversy could transmit quickly into customer adoption, regulatory scrutiny, and partner caution. | Medium | SR001, SR004, SR005, SR013 |
| CR036 | The strongest public mitigations today are transparency tooling, a formal incident summary, token migration, compensation mechanisms, and more explicit anti-fraud product positioning. | Medium | SR006, SR007, SR008, SR011, SR024 |
| CR037 | What is still missing are independent proofs that key-management controls, processor controls, biometric safeguards, and uptime controls have been materially strengthened after the incident. | Medium | SR001, SR006, SR010, SR024 |
| CR038 | A practical kill criterion would be any repeat privileged-key incident or major privacy controversy before the company demonstrates stable credential and partner growth. | Medium | SR006, SR001, SR013 |
| CR039 | Another kill criterion would be evidence that named partners remain symbolic while direct paying-customer disclosures never materialize. | Medium | SR028, SR029, SR030 |
| CR040 | The overall risk verdict is high: Humanity sits in an attractive market, but the combination of biometric sensitivity, operational-security failure, partner dependence, and disclosure gaps keeps residual exposure elevated. | Medium | SR004, SR006, SR022, SR023, SR025, SR030 |
| CV001 | Humanity’s January 2025 headline funding benchmark was a $20M round priced at a $1.1B fully diluted valuation. | Medium | SV007, SV008, SV009 |
| CV002 | Humanity’s May 2024 financing was publicly framed around $30M raised at roughly a $1B valuation. | Medium | SV006 |
| CV003 | Those financing references are best read as token-network FDV markers rather than as audited operating-enterprise values. | Medium | SV001, SV006, SV007 |
| CV004 | CoinGecko’s August 2026 page places Humanity near $170M spot market cap and about $852M fully diluted valuation. | Medium | SV002 |
| CV005 | CoinMarketCap’s H/USDT page shows H near $0.0859 on 2026-08-07, consistent with a sub-$1B fully diluted token value. | Medium | SV003, SV004 |
| CV006 | Current public token-market markers therefore sit materially below the January 2025 $1.1B funding headline. | Medium | SV002, SV004, SV007 |
| CV007 | That reset is meaningful, but it does not by itself make Humanity obviously cheap. | Medium | SV002, SV007, SV018 |
| CV008 | The gap between about $170M spot cap and about $852M FDV means circulating value and fully diluted value tell very different stories. | Medium | SV001, SV002, SV004 |
| CV009 | Investors are therefore underwriting future token distribution and unlock governance, not just today’s float. | Medium | SV001, SV002 |
| CV010 | Humanity’s strongest bullish valuation input is strategic optionality across identity, anti-fraud, developer, and institution-facing workflows. | Medium | SV010, SV012, SV023, SV024, SV029, SV030 |
| CV011 | A second bullish input is that some hack damage has already been repriced because live FDV sits below the old financing headline. | Medium | SV002, SV004, SV007, SV014 |
| CV012 | The strongest bearish input is the lack of public revenue, margin, retention, and treasury disclosure. | Medium | SV001, SV018, SV019 |
| CV013 | The June 2026 exploit created a lasting governance and trust discount in any valuation model. | Medium | SV013, SV014, SV015, SV016, SV017 |
| CV014 | Current public narrative still revolves around the hack, recovery, and pivot more than around operating metrics. | Medium | SV005, SV015 |
| CV015 | The enterprise-AI pivot may widen optionality, but on public evidence it adds execution risk before it adds proven monetization. | Medium | SV005, SV015 |
| CV016 | Humanity cannot be valued like a mature identity software company on disclosed revenue multiples. | Medium | SV018, SV019, SV020 |
| CV017 | Okta, Coinbase, and Palantir are useful only as boundary markers because they are economically proven and publicly disclosed in ways Humanity is not. | Medium | SV018, SV019, SV020, SV021, SV022 |
| CV018 | CompaniesMarketCap places Okta near $26.0B, Coinbase near $39.5B, and Palantir above $400B as of August 2026. | Medium | SV020, SV021, SV022 |
| CV019 | Those public comps are dangerous to overread because their values rest on audited financials and governance, not on token unlock paths. | Medium | SV018, SV019, SV020, SV021, SV022 |
| CV020 | Palantir’s 10-K and Okta’s annual report show exactly the disclosure depth Humanity lacks on revenue quality, liquidity, and risks. | Medium | SV018, SV019 |
| CV021 | That disclosure gap alone justifies a substantial discount relative to public software and infrastructure comparables. | Medium | SV018, SV019, SV020 |
| CV022 | Recent CoinMarketCap history shows H remained volatile in early August 2026. | Medium | SV003, SV004 |
| CV023 | The hack changed valuation by shifting the main underwriting question from adoption scale to trust recovery. | Medium | SV013, SV014, SV015 |
| CV024 | Partner optionality from Fireblocks, Moongate, Open Campus, and Mastercard deserves some value because it shows multiple adoption lanes. | Medium | SV023, SV024, SV029, SV030 |
| CV025 | That optionality still cannot be capitalized aggressively without direct revenue or production-depth proof. | Medium | SV023, SV024, SV029, SV030 |
| CV026 | The most supportable public recommendation is research-more rather than buy or avoid. | Medium | SV002, SV013, SV018, SV019 |
| CV027 | Confidence should remain medium at best because price history is observable while operating economics are mostly private. | Medium | SV002, SV003, SV018, SV019 |
| CV028 | Risk rating should remain high because the thesis depends on security recovery, supply governance, partner conversion, and future monetization. | Medium | SV013, SV015, SV023 |
| CV029 | At today’s public markers, Humanity looks more defensible near live levels than at the old $1.1B funding headline. | Medium | SV002, SV004, SV007 |
| CV030 | A move from research-more to buy would require hard evidence on revenue, retention, treasury governance, and post-hack controls. | Medium | SV013, SV018, SV019 |
| CV031 | A thesis break would include another privileged-key incident, unresolved compensation liabilities, or failure to convert partnerships into direct economics. | Medium | SV013, SV016, SV017, SV029, SV030 |
| CV032 | A public bear case centers on valuation compressing closer to spot-cap logic if trust recovery weakens. | Medium | SV002, SV014, SV015 |
| CV033 | A base case centers on stable recovery and public FDV holding in the high-hundreds-of-millions range while monetization stays unproven. | Medium | SV002, SV004, SV015 |
| CV034 | A bull case requires partner lanes converting into credible enterprise or financial workflows plus restored trust. | Medium | SV007, SV023, SV024, SV029, SV030 |
| CV035 | The absence of direct customer and revenue data means any single-number target would be false precision. | Medium | SV018, SV019, SV023 |
| CV036 | Comparables still help directionally: Okta frames identity-software disclosure, Coinbase frames listed crypto infrastructure, and Palantir frames narrative-plus-data-platform scale. | Medium | SV018, SV019, SV020, SV021, SV022 |
| CV037 | Humanity’s live public pricing is best interpreted as a narrative-adjusted token-market mark, not as a clean measure of enterprise intrinsic value. | Medium | SV002, SV003, SV004, SV005 |
| CV038 | The minimum final diligence asks are revenue proof, retention proof, treasury governance, and post-hack control evidence. | Medium | SV013, SV018, SV019, SV023 |
| CV039 | Until those asks are answered, the right stance is price-sensitive curiosity rather than conviction. | Medium | SV025, SV026, SV028 |
| CV040 | The overall valuation verdict is that Humanity is strategically interesting, financially under-disclosed, and only conditionally attractive near current token-market levels for high-risk investors. | Medium | SV002, SV013, SV018, SV019, SV023 |