Harmony Confirms Exploit After Attacker Mints 4 Billion ONE Tokens
Security

Harmony Confirms Exploit After Attacker Mints 4 Billion ONE Tokens

August 12, 20263 min read

Layer-1 blockchain Harmony has confirmed its network was exploited after an attacker minted roughly 4 billion ONE tokens that were never supposed to exist. The coin's price dropped 37% within hours, and the team is now choosing between a partial fix and a full network rollback that would also wipe out ordinary users' transactions.

What exactly happened to the Harmony network?

On-chain analyst Juiceberg first flagged the issue early Wednesday, August 12. By their estimate, the attacker created close to 4 billion ONE, about 26% of circulating supply, by exploiting the network's "empty blocks". A large share of the tokens moved straight to centralized exchanges. The analyst first counted 2.8 billion transferred tokens, then later said around 97% of the entire minted amount had already reached trading venues. About 115 million ONE, just under 3% of the minted total, reportedly remained in the attacker's wallets.

ONE reacted instantly. According to CoinGecko, the token fell 37% to roughly $0.00077. Harmony confirmed the incident on its official account, saying it was working with its team and relevant exchanges to stop and freeze the funds. In a follow-up post the project named four attacker addresses, in both Harmony and hex format, and asked exchanges to block any transfers linked to them.

ONE exploit at a glance
Illegally minted~4B ONE (26% of supply)
Price drop-37%, to $0.00077
Market cap after attack~$11.5M
All-time high, Oct 2021$0.38

How did the attacker mint billions of tokens out of nowhere?

Harmony has not disclosed the exact attack mechanism yet. What is known comes from the analyst. The new tokens appeared through manipulation of the network's "empty blocks", meaning the attacker found a way to get blocks confirmed with coins nobody had requested. Interestingly, the network's totalSupply endpoint still doesn't reflect the new issuance. Price trackers keep showing circulating supply at around 14.87 billion ONE, even though the real amount in circulation is already different.

  • Key point: Harmony paused its bridge roughly two hours after its first public post about the exploit.
  • A minute after pausing the bridge, the team shipped a patch and told validators to upgrade their nodes to block further minting.
  • The project hasn't decided what to do with the tokens already created, and says a separate update is coming for that.
  • About five hours passed between the analyst's first post and the patch going live.
While Harmony was still working out how to stop the attack, almost all of the illegal tokens had already spread across exchanges, and getting them back is nearly impossible.

Why is Harmony hesitant to roll back the chain?

A rollback is technically possible. The network could return to its pre-attack state and continue from there. But the cost is high, because the attacker's minting would disappear along with every legitimate transaction users made after the exploit. Transfers, swaps, any activity on the network over the past several hours simply wouldn't make it into the rewritten history.

This isn't Harmony's first time facing that dilemma. In June 2022, hackers drained about $100 million through the Horizon bridge, an attack the FBI later attributed to North Korea's Lazarus Group. Back then the team's first proposal was to reimburse victims by minting billions of new ONE and hard-forking the chain, a plan that drew heavy criticism and was replaced with treasury-funded payouts instead. Four years later, an attacker minted a comparable amount without asking anyone.

This is already the second similar incident this week

Harmony's case is the second time in a few days that a blockchain team has had to weigh a rollback over a consensus-level failure. Earlier this week, Ravencoin faced a similar dilemma. After a critical exploit tied to block confirmation, its developers also chose to roll back the network to undo the attack's effects. Both cases show that even less popular chains with relatively small market caps remain targets for attacks on the base protocol layer, not just smart contracts or bridges.

What does this mean for holders of smaller altcoins?

It's still unclear how many tokens Harmony will manage to freeze or recover, since most of them reached exchanges before the exploit was even confirmed publicly. ONE, which peaked at $0.38 in October 2021, now trades hundreds of times cheaper and has dropped out of the top 1,000 tokens by market cap. Unlike networks such as Bitcoin or Ethereum, smaller and older blockchains often simply lack the resources for code audits and fast incident response, which is why vulnerabilities like this can go unnoticed for years.

Comments

Your email address will not be published. Required fields are marked *

or verify by email