Harmony is facing one of the most serious security incidents in the network’s history after an attacker was able to create nearly 4 billion unauthorized ONE tokens, equivalent to approximately 26% of Harmony is facing one of the most serious security incidents in the network’s history after an attacker was able to create nearly 4 billion unauthorized ONE tokens, equivalent to approximately 26% of

Harmony Exploited, Nearly 4 Billion ONE Minted Illegally: Why Is This Incident More Serious Than a Typical Hack?

Harmony is facing one of the most serious security incidents in the network’s history after an attacker was able to create nearly 4 billion unauthorized ONE tokens, equivalent to approximately 26% of the pre-incident supply.
Unlike many typical crypto hacks, where attackers steal assets that already exist in smart contracts or user wallets, the Harmony incident involves the ability to create new ONE supply outside the blockchain’s normal issuance mechanism.
According to initial on-chain analysis, approximately 2.8 billion ONE was quickly transferred to exchanges. A later update estimated that around 97% of the illegally minted tokens had either reached exchanges or remained in related wallets, while roughly 115 million ONE had not been handled in the same way at the time of analysis.
Harmony has deployed a patch intended to prevent further token minting, coordinated with exchanges to freeze assets, and is considering a more controversial measure: rolling back the blockchain to a state before the attack.
The incident leaves Harmony facing a difficult question: how can it restore the integrity of ONE’s supply without undermining trust in blockchain immutability?
 

Key Takeaways

Harmony confirmed that the network was exploited after nearly 4 billion ONE were minted illegally.
This amount is equivalent to approximately 26% of ONE’s supply before the incident.
Initial on-chain analysis suggests the attacker may have exploited an issue related to empty blocks, but Harmony has not yet disclosed the full technical cause.
Approximately 2.8 billion ONE were recorded as being transferred to exchanges during the early stage of the attack.
ONE fell around 37% on the day the incident was disclosed.
Harmony released a patch to prevent further unauthorized minting.
The project is considering a rollback, but no final decision has been made.
Harmony previously suffered the approximately $100 million Horizon Bridge hack in 2022.
 

What Happened to Harmony?

The abnormal activity was discovered when on-chain analyst Juiceberg detected a massive amount of ONE appearing on the network.
Initial estimates indicated that the attacker created nearly:
4 billion ONE.
To understand the scale, the circulating supply before the incident was recorded by market trackers at approximately 14.87 billion ONE.
That means the amount of illegally created tokens was equivalent to around:
26% of the pre-incident supply.
This is what makes the incident particularly serious.
If a DeFi protocol is hacked for $10 million, the damage is usually limited to the assets held inside that protocol.
But when a blockchain is exploited in a way that allows additional native tokens to be created:
Security vulnerability → abnormal supply increase → dilution → tokens are sold → price declines.

The impact can spread to nearly every holder of that token.

 

 

How Did the Hacker Create 4 Billion ONE?

This remains one of the areas that requires an official technical report.
Initial on-chain analysis suggests the abnormal ONE supply may have been created through empty blocks.
However, Harmony has not yet disclosed the full root cause of the exploit or officially confirmed the complete technical mechanism used by the attacker.
Therefore, two pieces of information should currently be distinguished:
Confirmed by Harmony: the network was exploited and the project deployed measures to stop further unauthorized minting.
External analysis: the attacker appears to have exploited abnormal behavior related to empty blocks to generate ONE.
Until a technical post-mortem is published, the exact cause of the vulnerability should not be treated as a final conclusion.
 

Why Is Unauthorized Minting More Dangerous Than Stealing ONE?

Suppose a hacker steals 100 million ONE from a wallet.
The total ONE supply does not change.
Only ownership changes:
Wallet A → hacker.
But if the hacker is capable of creating 4 billion new ONE:
14.87 billion ONE → nearly 4 billion additional ONE created unexpectedly.
The issue is no longer only about who lost money.
All ONE holders face the risk of supply dilution.
If the newly created tokens are accepted by the market as valid ONE, each existing token represents a smaller share of the total supply.
That is why a vulnerability involving native asset issuance can become a blockchain-level problem rather than merely a protocol exploit.
 

Most of the ONE Was Transferred to Exchanges

One factor making the situation particularly urgent is that the attacker did not simply hold the newly created tokens.
According to data cited by Decrypt, approximately:
2.8 billion ONE
was transferred to exchanges during the early stages of the attack.
Later analysis by Juiceberg estimated that around 97% of the illegally minted ONE had reached exchanges, had been sold, or remained in related deposit wallets at the time of observation.
This creates two problems at the same time.
The first is dilution caused by the increase in supply.
The second is selling pressure if those tokens are sold into the market.
The process can be illustrated as:
Unauthorized mint → tokens sent to CEXs → ONE sold → liquidity absorbs new supply → price falls.
This is one reason ONE declined by approximately 37% on the day of the incident, falling to around $0.00077 according to data cited by Decrypt at the time.
 

Why Did Harmony Need Help From Exchanges?

When an attacker transfers assets to centralized exchanges, a project has an opportunity that purely on-chain transactions usually do not provide.
Centralized exchanges can identify and freeze related accounts or deposits under their own procedures.
Harmony said it was coordinating with relevant exchanges to:
Prevent assets from continuing to move.
Identify related addresses.
Freeze assets where possible.
Limit further selling of unauthorized ONE.
Harmony also published four related addresses and asked exchanges to block assets traceable to them.
This highlights an interesting paradox in crypto.
Blockchain makes fund flows transparent and traceable, but the ability to freeze assets often depends on centralized points such as CEXs.
 

Harmony Has Deployed a Patch

Harmony’s technical response came relatively quickly after the exploit was discovered.
According to Decrypt, Harmony initially said it was preparing a patch and evaluating a rollback.
The network later paused its bridge and released a new software version for validators. Harmony said this update could prevent further unauthorized ONE minting.
This solves the first problem:
Prevent the attacker from creating more ONE.
But a harder problem remains:
What should be done with the nearly 4 billion ONE already created?
This is why rollback has entered the discussion.
 

What Is a Rollback?

A rollback essentially moves the blockchain back to a state before the exploit occurred.
It can be visualized as:
Block A → Block B → Exploit → Block C → Block D
If the network rolls back to Block B, the history after that point would be removed from the recognized chain.
In theory, this could remove the ONE created during the exploit from the new blockchain state.
But there is a major problem.
The attacker was not the only person making transactions during that period.
Normal users may also have:
Transferred ONE.
Traded tokens.
Interacted with smart contracts.
Used bridges.
Conducted other legitimate transactions.
A rollback could reverse those valid transactions as well.
 

A Rollback Puts Harmony’s Immutability to the Test

This could become the most controversial part of the incident.
One of blockchain’s key principles is:
Immutability — transaction history is extremely difficult to change.
If a blockchain can be rolled back after an exploit, users may ask:
Who gets to decide which history is preserved?
But if Harmony does not roll back, it still has to deal with nearly 4 billion ONE created outside the expected supply rules.
Both choices carry costs.
No rollback: the network may have to accept the consequences of the unauthorized ONE and find another solution.
Rollback: the network could restore a pre-exploit state but affect legitimate transactions and raise questions about immutability.
This is not simply a technical decision. It is also a governance and trust decision.
 

A Strange Detail: totalSupply Has Not Reflected the New Tokens

Another notable technical detail reported after the incident is that Harmony’s totalSupply endpoint apparently had not reflected the newly created tokens.
Market tracking platforms were still displaying a circulating supply of approximately 14.87 billion ONE.
This makes the situation even more complicated.
If tokens can appear on a blockchain, be transferred, and be sold while the supply metric does not accurately reflect the change, evaluating:
market capitalization, circulating supply, and actual dilution
becomes more difficult.
This is one of the issues Harmony will need to explain clearly in its technical post-mortem.
 

How Are ONE Holders Affected?

The most immediate impact is on ONE’s price.
When the market realized that billions of tokens may have been created unexpectedly and most were transferred to exchanges, the risk of a sudden supply increase was priced in almost immediately.
ONE fell approximately 37% in one day, according to the price recorded in the August 12 report.
But the bigger long-term issue goes beyond one day’s price movement.
A native token depends heavily on confidence that:
its supply follows the rules of the protocol.
If users can no longer be certain about that rule, the token’s monetary credibility may be damaged.
Therefore, Harmony does not only need to fix the code.
The project must also prove that the mechanism that allowed the incident to happen has been identified and cannot be repeated.
 

Harmony Previously Suffered the Horizon Bridge Hack in 2022

The new incident is even more significant because Harmony has already experienced a major attack.
In June 2022, Horizon Bridge was exploited and approximately $100 million in crypto assets was stolen.
The FBI later attributed the attack to North Korea’s Lazarus Group.
After that incident, Harmony once proposed a compensation plan that could have required minting billions of additional ONE and hard forking the blockchain.
The plan faced strong community opposition and was eventually replaced by another approach using treasury funds.
There is a notable irony:
2022: Harmony considered minting a large amount of ONE to deal with the aftermath of a hack.
2026: an attacker was able to create a massive amount of ONE without authorization.
This has once again placed supply management at the center of attention.
 

This Incident Shows How Layer 1 Risk Differs From a DeFi Hack

DeFi exploits usually cause users to focus on smart contract security.
But Harmony highlights a deeper layer of risk:
protocol-level security.
If a smart contract has a bug, an application may lose assets.
If a bridge has a bug, assets held in the bridge may be at risk.
But if the consensus or native token issuance mechanism has a serious vulnerability, the impact can potentially spread across the entire blockchain economy.
This is why Layer 1 networks need to secure not only smart contracts but also:
consensus → block production → validator software → issuance → bridge infrastructure.
 

What Harmony Needs to Do Next

The patch is only the first step.
To restore confidence, Harmony needs to address at least three issues.
First, publish the root cause.
The community needs to know exactly what the attacker did and why the system allowed it.
Second, deal with the ONE that was already minted.
Harmony needs to provide a clear solution for how the unauthorized tokens will be handled and whether a rollback is truly necessary.
Third, prove the vulnerability has been completely fixed.
This may be the most important part for the network’s future.
If the market does not believe ONE issuance is secure again, a price recovery would not necessarily mean trust in the protocol has been restored.
 

Long-Term Impact on Harmony

The incident occurred at a time when ONE had already lost most of its value compared with its 2021 peak.
According to data recorded shortly after the exploit, ONE’s market capitalization had fallen to only around $11.5 million, while the token was down more than 99% from its all-time high near $0.38.
Harmony therefore faces a problem larger than the immediate financial damage.
The project needs to restore:
Security credibility + token credibility + developer confidence + user confidence.
For a Layer 1 blockchain, these four factors are closely connected.
 

Conclusion

The exploit involving nearly 4 billion ONE is an exceptionally serious incident for Harmony because the issue is not only about how much money the attacker may have obtained.
The attacker appears to have been able to create an amount of native tokens equivalent to approximately 26% of ONE’s pre-incident supply, after which a very large portion of those tokens was transferred to exchanges.
Harmony responded by coordinating with exchanges, pausing its bridge, and releasing a patch to prevent further minting. But the hardest question remains unresolved: how can billions of illegally created ONE be handled without causing further damage to the network?
A rollback may be a technical solution, but it also creates concerns about immutability and could reverse legitimate transactions.
Therefore, the next things to watch are not only ONE’s price, but also the technical post-mortem, the supply remediation plan, and the final decision on rollback.
After the roughly $100 million Horizon Bridge hack in 2022, this new incident once again places security at the center of questions about Harmony’s future.
 

FAQ

How Much ONE Was Involved in the Harmony Hack?

On-chain analysis recorded nearly 4 billion ONE being minted illegally, equivalent to around 26% of the pre-incident supply.

Did the Hacker Sell All 4 Billion ONE?

It cannot be said that all of it was sold. Around 97% of the unauthorized tokens were reported to have reached exchanges, been sold, or remained in deposit wallets at the time of analysis.

Has Harmony Fixed the Vulnerability?

Harmony released an update that the project says can prevent further unauthorized minting. The full technical cause of the exploit still needs to be disclosed.

Will Harmony Roll Back the Blockchain?

Harmony is considering a rollback, but according to the information released after the incident, no final decision has been made.

Has Harmony Been Hacked Before?

Yes. Harmony’s Horizon Bridge was attacked in 2022, resulting in losses of approximately $100 million.
 
Disclaimer: The information provided here is for informational purposes only and should not be considered financial, investment, legal, or professional advice. Always conduct your own research, consider your financial situation, and, if necessary, consult with a licensed professional before making any decisions.
Market Opportunity
4 Logo
4 Price(4)
--
----
USD
4 (4) Live Price Chart

Description:Crypto Pulse is powered by AI and public sources to bring you the hottest token trends instantly. For expert insights and in-depth analysis, visit MEXC Learn.

The articles shared on this page are sourced from public platforms and are provided for reference only. They do not represent the position or views of MEXC. All rights belong to Nguyen Rin Hoang. If you believe any content infringes upon the rights of a third party, please contact service@support.mexc.com for prompt removal. MEXC does not guarantee the accuracy, completeness, or timeliness of any content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be interpreted as a recommendation or endorsement by MEXC. For expert insights and in-depth analysis, visit MEXC Learn.