TL;DR

  • The Harmony ONE exploit reportedly created roughly 4 billion unauthorized tokens, with about 97% ultimately reaching exchanges.
  • Harmony patched two cross-shard receipt flaws and paused its bridge, but it has not published a postmortem explaining exactly how the exploit occurred.
  • A blockchain rollback could remove unauthorized tokens while also reversing valid trades, DeFi activity and other transactions.

Harmony, a layer-1 blockchain network, released an emergency validator patch on August 12 after an exploit let an attacker create units of its native token, ONE, without authorization. The project also paused its bridge, the system that lets assets move between Harmony and other blockchains, and asked exchanges to freeze funds linked to four wallets. At the same time, Harmony said it was considering a blockchain rollback.

Onchain researcher Juiceberg — an analyst who studies blockchain transaction data directly rather than relying on official disclosures — estimated that the attacker minted roughly 4 billion ONE and that nearly all of it, about 97%, ultimately reached exchanges, either sold or sitting in deposit wallets, leaving roughly 115 million ONE still unsold on the blockchain itself. Harmony has confirmed the exploit, but it has not confirmed either figure or said how much exchanges have frozen. Juiceberg also noted that Harmony’s totalSupply endpoint did not reflect the new tokens, which may have delayed outside detection.

The reported unauthorized mint would equal more than one-quarter of the roughly 15 billion ONE that existed before the incident. ONE fell about 40% during the initial market reaction, according to CoinDesk. Yet holders face excess tokens in circulation. They also face the possibility that a rollback could reverse valid transactions. 

The patch closes two receipt flaws

Harmony’s emergency release, version 2026.1.1, changes how the network verifies cross-shard receipts — the records used when a transaction moves value from one part of the blockchain to another. Harmony splits its network into several parallel sections called shards, and when a transaction moves between them, a receipt confirms the transfer happened correctly so the receiving shard can credit the right account. Validators, the computers that check and approve activity on the network, are responsible for confirming these receipts are valid.

The first flaw was in how the network checked whether enough validators had actually approved a receipt. Instead of confirming which validators had signed off, the check only compared the total size of the group against a required minimum. That meant a receipt carrying no real approvals, marked with an essentially blank signature, could still pass as valid. This affected an older part of Harmony’s validator system, dating from before the network introduced staking.

The second flaw was in how the network tracked whether a receipt had already been used, again in an older part of the system. That tracking relied on information that was not properly checked against the network’s official record of events. That gap meant a receipt that had already been processed could be resubmitted with small changes and made to look new, allowing the receiving account to be credited a second time without a matching debit elsewhere.

The Harmony patch addresses two cross-shard receipt flaws that offered possible routes for unauthorized creation. However, the project has not published a postmortem. It also has not said whether the attacker used one flaw, both flaws or another combination of steps.

Most reported tokens reached exchanges

The Harmony ONE exploit became harder to contain after the newly created tokens moved to centralized exchanges. Juiceberg’s initial estimate put 2.8 billion ONE in exchange deposit wallets. In a follow-up post roughly three hours later, the researcher raised that figure to about 97% of the minted total, either sold or sitting in deposit wallets, with roughly 115 million ONE left available to sell onchain.

Those numbers remain third-party estimates. Harmony has not named the exchanges involved or disclosed how many tokens they froze. It has also not separated amounts already sold from balances still held in deposit accounts.

At ONE’s price during the exploit, near $0.0008, the 4 billion newly created tokens carried a nominal value of roughly $3.2 million. But this figure understates the real impact. Unauthorized issuance dilutes existing holders and adds selling pressure to the market.

Source: CoinMarketCap

A rollback could reverse valid transactions

Harmony said it was evaluating rollback options, but it has not approved one or selected a cutoff block. A rollback would ask validators to accept an earlier version of the ledger and continue the chain from that point.

That could remove unauthorized ONE still recorded on Harmony. It could also erase legitimate transfers completed after the chosen cutoff, including trades, DeFi (decentralized finance) activity and bridge transactions. Tokens in an exchange’s internal system would require coordination with that venue. They would not automatically disappear if Harmony changed its ledger.

The decision therefore extends beyond correcting the ONE token supply. Wallet providers, exchanges and applications would need to agree on which chain history they recognize. Harmony has not explained how it would handle users if a rollback erased valid transactions.

The supply count remains unresolved

Harmony has published a technical fix, but not an account of what actually took place. The project has paused bridge.harmony.one without identifying it as the exploited component, and it has not said when the bridge will reopen or how it will handle transactions affected by the pause. The exploit is Harmony’s third major security incident since 2022, following a Horizon Bridge breach that cost about $100 million and a 2023 bug that improperly minted about 146.3 million ONE.

LEAVE A REPLY

Please enter your comment!
Please enter your name here