Harmony is facing one of the most serious security incidents in the network’s history after an attacker was able to create nearly 4 billion unauthorized ONE tokens, equivalent to approximately 26% of Harmony is facing one of the most serious security incidents in the network’s history after an attacker was able to create nearly 4 billion unauthorized ONE tokens, equivalent to approximately 26% of

Harmony Exploited, Nearly 4 Billion ONE Minted Illegally: Why Is This Incident More Serious Than a Typical Hack?

Harmony is facing one of the most serious security incidents in the network’s history after an attacker was able to create nearly 4 billion unauthorized ONE tokens, equivalent to approximately 26% of the pre-incident supply.
Unlike many typical crypto hacks, where attackers steal assets that already exist in smart contracts or user wallets, the Harmony incident involves the ability to create new ONE supply outside the blockchain’s normal issuance mechanism.
According to initial on-chain analysis, approximately 2.8 billion ONE was quickly transferred to exchanges. A later update estimated that around 97% of the illegally minted tokens had either reached exchanges or remained in related wallets, while roughly 115 million ONE had not been handled in the same way at the time of analysis.
Harmony has deployed a patch intended to prevent further token minting, coordinated with exchanges to freeze assets, and is considering a more controversial measure: rolling back the blockchain to a state before the attack.
The incident leaves Harmony facing a difficult question: how can it restore the integrity of ONE’s supply without undermining trust in blockchain immutability?
 

Key Takeaways

Harmony confirmed that the network was exploited after nearly 4 billion ONE were minted illegally.
This amount is equivalent to approximately 26% of ONE’s supply before the incident.
Initial on-chain analysis suggests the attacker may have exploited an issue related to empty blocks, but Harmony has not yet disclosed the full technical cause.
Approximately 2.8 billion ONE were recorded as being transferred to exchanges during the early stage of the attack.
ONE fell around 37% on the day the incident was disclosed.
Harmony released a patch to prevent further unauthorized minting.
The project is considering a rollback, but no final decision has been made.
Harmony previously suffered the approximately $100 million Horizon Bridge hack in 2022.
 

What Happened to Harmony?

The abnormal activity was discovered when on-chain analyst Juiceberg detected a massive amount of ONE appearing on the network.
Initial estimates indicated that the attacker created nearly:
4 billion ONE.
To understand the scale, the circulating supply before the incident was recorded by market trackers at approximately 14.87 billion ONE.
That means the amount of illegally created tokens was equivalent to around:
26% of the pre-incident supply.
This is what makes the incident particularly serious.
If a DeFi protocol is hacked for $10 million, the damage is usually limited to the assets held inside that protocol.
But when a blockchain is exploited in a way that allows additional native tokens to be created:
Security vulnerability → abnormal supply increase → dilution → tokens are sold → price declines.

The impact can spread to nearly every holder of that token.

 

 

How Did the Hacker Create 4 Billion ONE?

This remains one of the areas that requires an official technical report.
Initial on-chain analysis suggests the abnormal ONE supply may have been created through empty blocks.
However, Harmony has not yet disclosed the full root cause of the exploit or officially confirmed the complete technical mechanism used by the attacker.
Therefore, two pieces of information should currently be distinguished:
Confirmed by Harmony: the network was exploited and the project deployed measures to stop further unauthorized minting.
External analysis: the attacker appears to have exploited abnormal behavior related to empty blocks to generate ONE.
Until a technical post-mortem is published, the exact cause of the vulnerability should not be treated as a final conclusion.
 

Why Is Unauthorized Minting More Dangerous Than Stealing ONE?

Suppose a hacker steals 100 million ONE from a wallet.
The total ONE supply does not change.
Only ownership changes:
Wallet A → hacker.
But if the hacker is capable of creating 4 billion new ONE:
14.87 billion ONE → nearly 4 billion additional ONE created unexpectedly.
The issue is no longer only about who lost money.
All ONE holders face the risk of supply dilution.
If the newly created tokens are accepted by the market as valid ONE, each existing token represents a smaller share of the total supply.
That is why a vulnerability involving native asset issuance can become a blockchain-level problem rather than merely a protocol exploit.
 

Most of the ONE Was Transferred to Exchanges

One factor making the situation particularly urgent is that the attacker did not simply hold the newly created tokens.
According to data cited by Decrypt, approximately:
2.8 billion ONE
was transferred to exchanges during the early stages of the attack.
Later analysis by Juiceberg estimated that around 97% of the illegally minted ONE had reached exchanges, had been sold, or remained in related deposit wallets at the time of observation.
This creates two problems at the same time.
The first is dilution caused by the increase in supply.
The second is selling pressure if those tokens are sold into the market.
The process can be illustrated as:
Unauthorized mint → tokens sent to CEXs → ONE sold → liquidity absorbs new supply → price falls.
This is one reason ONE declined by approximately 37% on the day of the incident, falling to around $0.00077 according to data cited by Decrypt at the time.
 

Why Did Harmony Need Help From Exchanges?

When an attacker transfers assets to centralized exchanges, a project has an opportunity that purely on-chain transactions usually do not provide.
Centralized exchanges can identify and freeze related accounts or deposits under their own procedures.
Harmony said it was coordinating with relevant exchanges to:
Prevent assets from continuing to move.
Identify related addresses.
Freeze assets where possible.
Limit further selling of unauthorized ONE.
Harmony also published four related addresses and asked exchanges to block assets traceable to them.
This highlights an interesting paradox in crypto.
Blockchain makes fund flows transparent and traceable, but the ability to freeze assets often depends on centralized points such as CEXs.
 

Harmony Has Deployed a Patch

Harmony’s technical response came relatively quickly after the exploit was discovered.
According to Decrypt, Harmony initially said it was preparing a patch and evaluating a rollback.
The network later paused its bridge and released a new software version for validators. Harmony said this update could prevent further unauthorized ONE minting.
This solves the first problem:
Prevent the attacker from creating more ONE.
But a harder problem remains:
What should be done with the nearly 4 billion ONE already created?
This is why rollback has entered the discussion.
 

What Is a Rollback?

A rollback essentially moves the blockchain back to a state before the exploit occurred.
It can be visualized as:
Block A → Block B → Exploit → Block C → Block D
If the network rolls back to Block B, the history after that point would be removed from the recognized chain.
In theory, this could remove the ONE created during the exploit from the new blockchain state.
But there is a major problem.
The attacker was not the only person making transactions during that period.
Normal users may also have:
Transferred ONE.
Traded tokens.
Interacted with smart contracts.
Used bridges.
Conducted other legitimate transactions.
A rollback could reverse those valid transactions as well.
 

A Rollback Puts Harmony’s Immutability to the Test

This could become the most controversial part of the incident.
One of blockchain’s key principles is:
Immutability — transaction history is extremely difficult to change.
If a blockchain can be rolled back after an exploit, users may ask:
Who gets to decide which history is preserved?
But if Harmony does not roll back, it still has to deal with nearly 4 billion ONE created outside the expected supply rules.
Both choices carry costs.
No rollback: the network may have to accept the consequences of the unauthorized ONE and find another solution.
Rollback: the network could restore a pre-exploit state but affect legitimate transactions and raise questions about immutability.
This is not simply a technical decision. It is also a governance and trust decision.
 

A Strange Detail: totalSupply Has Not Reflected the New Tokens

Another notable technical detail reported after the incident is that Harmony’s totalSupply endpoint apparently had not reflected the newly created tokens.
Market tracking platforms were still displaying a circulating supply of approximately 14.87 billion ONE.
This makes the situation even more complicated.
If tokens can appear on a blockchain, be transferred, and be sold while the supply metric does not accurately reflect the change, evaluating:
market capitalization, circulating supply, and actual dilution
becomes more difficult.
This is one of the issues Harmony will need to explain clearly in its technical post-mortem.
 

How Are ONE Holders Affected?

The most immediate impact is on ONE’s price.
When the market realized that billions of tokens may have been created unexpectedly and most were transferred to exchanges, the risk of a sudden supply increase was priced in almost immediately.
ONE fell approximately 37% in one day, according to the price recorded in the August 12 report.
But the bigger long-term issue goes beyond one day’s price movement.
A native token depends heavily on confidence that:
its supply follows the rules of the protocol.
If users can no longer be certain about that rule, the token’s monetary credibility may be damaged.
Therefore, Harmony does not only need to fix the code.
The project must also prove that the mechanism that allowed the incident to happen has been identified and cannot be repeated.
 

Harmony Previously Suffered the Horizon Bridge Hack in 2022

The new incident is even more significant because Harmony has already experienced a major attack.
In June 2022, Horizon Bridge was exploited and approximately $100 million in crypto assets was stolen.
The FBI later attributed the attack to North Korea’s Lazarus Group.
After that incident, Harmony once proposed a compensation plan that could have required minting billions of additional ONE and hard forking the blockchain.
The plan faced strong community opposition and was eventually replaced by another approach using treasury funds.
There is a notable irony:
2022: Harmony considered minting a large amount of ONE to deal with the aftermath of a hack.
2026: an attacker was able to create a massive amount of ONE without authorization.
This has once again placed supply management at the center of attention.
 

This Incident Shows How Layer 1 Risk Differs From a DeFi Hack

DeFi exploits usually cause users to focus on smart contract security.
But Harmony highlights a deeper layer of risk:
protocol-level security.
If a smart contract has a bug, an application may lose assets.
If a bridge has a bug, assets held in the bridge may be at risk.
But if the consensus or native token issuance mechanism has a serious vulnerability, the impact can potentially spread across the entire blockchain economy.
This is why Layer 1 networks need to secure not only smart contracts but also:
consensus → block production → validator software → issuance → bridge infrastructure.
 

What Harmony Needs to Do Next

The patch is only the first step.
To restore confidence, Harmony needs to address at least three issues.
First, publish the root cause.
The community needs to know exactly what the attacker did and why the system allowed it.
Second, deal with the ONE that was already minted.
Harmony needs to provide a clear solution for how the unauthorized tokens will be handled and whether a rollback is truly necessary.
Third, prove the vulnerability has been completely fixed.
This may be the most important part for the network’s future.
If the market does not believe ONE issuance is secure again, a price recovery would not necessarily mean trust in the protocol has been restored.
 

Long-Term Impact on Harmony

The incident occurred at a time when ONE had already lost most of its value compared with its 2021 peak.
According to data recorded shortly after the exploit, ONE’s market capitalization had fallen to only around $11.5 million, while the token was down more than 99% from its all-time high near $0.38.
Harmony therefore faces a problem larger than the immediate financial damage.
The project needs to restore:
Security credibility + token credibility + developer confidence + user confidence.
For a Layer 1 blockchain, these four factors are closely connected.
 

Conclusion

The exploit involving nearly 4 billion ONE is an exceptionally serious incident for Harmony because the issue is not only about how much money the attacker may have obtained.
The attacker appears to have been able to create an amount of native tokens equivalent to approximately 26% of ONE’s pre-incident supply, after which a very large portion of those tokens was transferred to exchanges.
Harmony responded by coordinating with exchanges, pausing its bridge, and releasing a patch to prevent further minting. But the hardest question remains unresolved: how can billions of illegally created ONE be handled without causing further damage to the network?
A rollback may be a technical solution, but it also creates concerns about immutability and could reverse legitimate transactions.
Therefore, the next things to watch are not only ONE’s price, but also the technical post-mortem, the supply remediation plan, and the final decision on rollback.
After the roughly $100 million Horizon Bridge hack in 2022, this new incident once again places security at the center of questions about Harmony’s future.
 

FAQ

How Much ONE Was Involved in the Harmony Hack?

On-chain analysis recorded nearly 4 billion ONE being minted illegally, equivalent to around 26% of the pre-incident supply.

Did the Hacker Sell All 4 Billion ONE?

It cannot be said that all of it was sold. Around 97% of the unauthorized tokens were reported to have reached exchanges, been sold, or remained in deposit wallets at the time of analysis.

Has Harmony Fixed the Vulnerability?

Harmony released an update that the project says can prevent further unauthorized minting. The full technical cause of the exploit still needs to be disclosed.

Will Harmony Roll Back the Blockchain?

Harmony is considering a rollback, but according to the information released after the incident, no final decision has been made.

Has Harmony Been Hacked Before?

Yes. Harmony’s Horizon Bridge was attacked in 2022, resulting in losses of approximately $100 million.
 
Disclaimer: The information provided here is for informational purposes only and should not be considered financial, investment, legal, or professional advice. Always conduct your own research, consider your financial situation, and, if necessary, consult with a licensed professional before making any decisions.
市場機遇
4 圖標
4實時價格 (4)
--
----
USD
4 (4) 實時價格圖表

本頁面分享的文章均源自公開平台,僅供參考。該內容不代表 MEXC 的立場或觀點。所有版權歸 Nguyen Rin Hoang 所有。如果您認為任何內容侵犯了第三方的權益,請聯絡 service@support.mexc.com 以便及時刪除。 MEXC 不保證任何內容的準確性、完整性或及時性,且不對基於所提供信息而採取的任何行動負責。本內容不構成財務、法律或其他專業建議,亦不應被解釋為 MEXC 的推薦或認可。如需專家見解和深入分析,請造訪 MEXC 學院

學習更多 4 知識

查看更多
為什麼 EDGE 會上漲?邊緣 X 價格飆升,圓圈弧合作夥伴關係推動話題利息

為什麼 EDGE 會上漲?邊緣 X 價格飆升,圓圈弧合作夥伴關係推動話題利息

EDGE 在價格大幅上漲後,已成為市場密切關注的代幣之一,並讓 edgeX 生態系統重新回到聚光燈下。直接催化因素不僅僅是更廣泛的幣種情緒,而是 edgeX 的全球資產策略重大擴張,且與即將上線的 Circle 的 Arc 主網相關。 edgeX 已宣布計劃從第一天起在 Arc 上線,推出 24/7 外匯永續合約,首發 USD/JPY,同時支援涵蓋股票、大宗商品與加密貨幣的 150+ 個永續話題。
2026/09/03
MEXC Global Card vs MEXC Card(APAC)vs MEXC Ether.Fi Card:哪張加密貨幣 Visa 卡最適合您?

MEXC Global Card vs MEXC Card(APAC)vs MEXC Ether.Fi Card:哪張加密貨幣 Visa 卡最適合您?

自 2026 年 8 月 31 日起,MEXC 的卡片陣容已從兩張擴增為三張 Visa 卡:兩張由 MEXC 自行發行,另一張則是透過 ether.fi 發行的聯名卡。 MEXC Global Card 與 MEXC Card(APAC)屬於託管型卡片,直接動用您存放在 MEXC 的 USDT;MEXC × ether.fi 信用卡則是非託管卡片,讓您在資產仍然屬於自己的情況下進行消費。 兩張 M
2026/09/01
穩定幣 vs 代幣化存款:哪一種可能驅動支付的未來?

穩定幣 vs 代幣化存款:哪一種可能驅動支付的未來?

兩種版本的貨幣正在競爭上鏈。 其中一種來自幣種。 另一種則來自銀行。 USDT 和 USDC 等穩定幣已經證明,以美元計價的價值可以透過區塊鏈網路全天 24 小時在全球流轉。 銀行正在開發另一種模式:代幣化存款。 銀行不是創建一個由儲備資產支撐的獨立數位代幣,而是在可程式化基礎設施上呈現既有的存款餘額。 國際清算銀行如今在這場辯論中表明了明確立場。 在 8 月 28 日的傑克遜霍爾經濟研討會上,B
2026/09/01
查看更多

4 最新動態

查看更多
從稀缺交易到估值紀律:SpaceX的回調考驗OpenAI的IPO野心

從稀缺交易到估值紀律:SpaceX的回調考驗OpenAI的IPO野心

據報導,OpenAI 傾向將其 IPO 推遲至 2027 年,但更強烈的市場訊號來自 SpaceX。SpaceX 於 6 月 22 日收盤下跌了 16.4%,收於 154.60 美元,較盤中高點 225.64 美元降低了 31.5%,但仍較其 135 美元的 IPO 價格高出 14.5%。這一走勢使 SpaceX 從一個由稀缺性驅動的 IPO 成功案例,轉變為 AI 相關超大型上市週期中首個重大公開市場壓力測試。 OpenAI 的問題不在於需求,而在於估值。路透社引用《紐約時報》的報導指出,OpenAI 正考慮等待至 2027 年,以維持高達 1 兆美元的估值目標,而顧問將此選擇定調為:要麼等待達到該估值,要麼以較低目標提前上市。 預測市場已開始反映這種謹慎態度。Polymarket 的 OpenAI IPO 市場近期顯示,OpenAI 在 2026 年 12 月 31 日前完成 IPO 的機率約為四分之一,這表明交易者不再將近期上市視為明確的基本情境。對於加密貨幣交易者而言,這使得 AI 上市前的曝險從單向的稀缺性交易,轉變為與公開市場基準掛鉤的估值紀律交易。
2026/06/29
Coldcard Mk3 警告隨 $38M Bitcoin 掃蕩而來,但原因仍未確認

Coldcard Mk3 警告隨 $38M Bitcoin 掃蕩而來,但原因仍未確認

比特幣硬體錢包製造商 Coinkite 已警告用戶,Coldcard 裝置存在種子生成問題,影響範圍涵蓋所有 4.0.1 及更高版本的 Mk3 韌體。此警告是在安全研究人員調查一宗涉及 594.48 BTC(價值約 3,800 萬美元)的協調性盜取事件時出現的。然而,目前尚無公開的技術證據證實 Coldcard 的問題導致了這些轉帳。
2026/07/31
Mastercard 完成對 BVNK 的收購,金額高達 18 億美元——穩定幣進入全球支付核心

Mastercard 完成對 BVNK 的收購,金額高達 18 億美元——穩定幣進入全球支付核心

Mastercard 於三月宣布該交易後,已於 2026 年 8 月 3 日(UTC +8)完成對穩定幣基礎設施供應商 BVNK 的收購。
2026/08/04
查看更多