
A Huma phishing email campaign is directing users to fake claim portals. Learn which domain was flagged and how to protect crypto wallet.
Author: Kritika Gupta
14th September 2026- Huma Finance warned its users that scammers are sending phishing emails from a fake domain. The emails copy Huma’s branding. They push people toward a fake claim portal and ask them to connect a crypto wallet.
High Signal Summary For A Quick Glance
Dinero en la Mesa
@DineroenlaMesa
@humafinance A useful anchor while those emails are going around: the only published Feather-to-$HUMA ratios are historical — 8.3 in Season 0, 23.5 in Season 1, 30 in Season 2. Any email quoting a figure outside that isn't coming from a published source.
Phishing emails are actively circulating from fake domains such as (humaverse. info), asking recipients to connect wallets to a fake claim portal. These emails are not from Huma. Stay vigilant. Official announcements are only made from https://t.co/AKtQYbt6Ru, @humafinance and
11:52 AM·Sep 14, 2026
Reinforce.fi | Stablecoin Yield
@reinforce_fi
@humafinance A good habit: bookmark the real domain directly rather than clicking links in emails, and never sign a wallet connection just to 'check eligibility' for a claim.
Phishing emails are actively circulating from fake domains such as (humaverse. info), asking recipients to connect wallets to a fake claim portal. These emails are not from Huma. Stay vigilant. Official announcements are only made from https://t.co/AKtQYbt6Ru, @humafinance and
07:26 AM·Sep 14, 2026
@Tomboymedellin DIANA YANETH USUGA G
@Dianausugalm
@humafinance Abrí el enlace , por suerte en la billetera solana que puso no tenía fondos y ahí el supuesto air drop le sale a uno con que no es elegible para reclamar , así que sería bueno que lo hagan saber también en todas las billeteras para que los usuarios no pierdan fondos
Phishing emails are actively circulating from fake domains such as (humaverse. info), asking recipients to connect wallets to a fake claim portal. These emails are not from Huma. Stay vigilant. Official announcements are only made from https://t.co/AKtQYbt6Ru, @humafinance and
07:18 AM·Sep 14, 2026
Steady attention without excessive speculation.
The official @humafinance account named the fake domain as humaverse[.]info. According to Huma, the emails are not from the project. So the Huma phishing email has one clear goal, and that goal is your wallet.
Huma posted the alert at 07:11 UTC on September 14. The team said the fake emails ask recipients to connect wallets to a fake claim portal. Then it repeated its official channels for readers.
Here is the core of the official warning.
Phishing emails are actively circulating from fake domains such as (humaverse. info), asking recipients to connect wallets to a fake claim portal. These emails are not from Huma. Stay vigilant.
Co-founder Richard Liu amplified the same message about two hours later. He listed the only official sources again in a follow-up post. As a result, both the company and its founder now point users to the same three channels.
Huma named only one domain in the warning, humaverse[.]info. Do not visit it. The site poses as a Huma claim page, and it asks visitors to connect a wallet.
Public registration data for humaverse[.]info was not fully available during this research. So the creation date, registrar, and owner stay unconfirmed for now.
Huma also has not said which chain the portal targets. One user replied that an earlier email asked for a Solana wallet permission. Still, that single report stays unverified.
Huma has not published the portal’s exact code. Instead, security firms describe a common pattern for these scams. The Huma phishing email follows that familiar drainer playbook.
First, a lure email points to a look-alike domain that claims an airdrop is live. Next comes the trap. Connecting a wallet alone does not move funds, so theft happens only when the victim signs the next request.
On Ethereum, that request is often a token approval or a Permit signature. According to Scam Sniffer, these signatures let attackers pull tokens later. On Solana, a malicious transaction can hand over token authority instead.
The scale is real. Scam Sniffer reported that wallet-drainer phishing stole $83.85 million from 106,106 victims in 2025. That figure fell 83% from the year before, yet the tactic still works.
Key events in the Huma phishing campaign
PhishDestroy flags humafinance.info as suspicious. However, it has not been linked to the current email campaign.
A user later reports receiving a Huma-branded email that requested permission for a Solana wallet. The report remains independently unverified.
Humavault.com appears with a “Huma Allocation Live” claim portal. No confirmed connection to the phishing emails has been established.
Huma confirms that phishing emails from fake domains, including humaverse.info, are directing users to fraudulent wallet-connect portals.
Richard Liu repeats the alert and directs users to Huma’s official app, X account and Discord server.
No verified victim count, stolen amount, receiving wallet or malicious drainer contract has been published.
Users should wait for Huma to confirm whether a legitimate claim or airdrop window is active through its official blog and Discord.
Other look-alike sites also target Huma users. The domain humavault[.]com hosts a claim-style page, though no source ties it to this email wave. PhishDestroy flagged humafinance[.]info back in February 2026, and ScamAdviser rates huma-finance[.]info as high risk too.
Scammers have chased Huma before. In March 2024, the team warned about a fake account listing a token on MEXC. Around the May 2025 token launch, fake claim domains appeared as well.
Huma changed its process in response. From Season 5 onward, the team said airdrop details would live on Discord and the blog. So an unsolicited email with a brand-new domain already breaks that rule.
This phishing wave is separate from an earlier hack. In May 2026, attackers drained about $101,400 from Huma’s legacy Polygon v1 pools through a code bug. That case was not phishing, so do not confuse it with this one.
The warning did not move the market in any measurable way. HUMA traded near $0.02276 on September 14, down about 3.9% on the day, per CoinGecko. That range looks ordinary rather than a crash.
Other metrics stayed steady as well. DefiLlama put Huma Finance V2 total value locked near $315.55 million, up 48.3% over 30 days. So far, no data links the phishing emails to any price or liquidity drop. None of this is financial advice.
The alert spread through Huma’s own channels rather than going viral. The original post drew about 3,904 views and 33 likes soon after it went live. Still, community members moved fast to warn others.
One user urged people to bookmark the real domain first. That user also warned against signing a wallet connection just to check eligibility. Another member said the scam email even reached a primary inbox, not the spam folder.
The safest move is also the simplest. Type huma.finance by hand instead of clicking email links. Use only the channels Huma named, which are its website, the @humafinance account, and its official Discord.
Never sign a claim request that arrives by email. Connecting a wallet can be harmless, yet the signature that follows can drain it. So treat any surprise claim portal as a red flag.
Researchers have not yet published a drainer address for this campaign. Until they do, the on-chain trail stays open. For now, bookmark the real domain and share the warning with anyone who holds HUMA.
Our Crypto Talk is committed to unbiased, transparent, and true reporting to the best of our knowledge. This news article aims to provide accurate information in a timely manner. However, we advise the readers to verify facts independently and consult a professional before making any decisions based on the content since our sources could be wrong too. Check our Terms and conditions for more info.