Harmony said it was responding to an exploit that allowed an attacker to mint 4 billion ONE tokens without authorization, creating a sudden supply shock for the network’s native asset and pushing the project toward a possible blockchain rollback.
The project confirmed the incident in a statement on X, saying it was working with its internal team and third parties to halt malicious activity, freeze funds where possible, develop a software patch, and assess rollback options. Harmony did not disclose the technical root cause or provide a timetable for restoring normal operations.
An account known as Juiceberg first reported the apparent exploit on X, describing a method involving “empty blocks.” The account said the blockchain’s publicly accessible totalSupply endpoint did not immediately reflect the newly minted tokens, even as the extra ONE was apparently being moved through the network.
ONE fell about 34% over 24 hours following the incident and traded near $0.0008 at the time of the report. At that price, 4 billion ONE would carry a market value of roughly $3.2 million, although the value recoverable by an attacker depends on how much liquidity is available when the tokens are sold.
Tokens reportedly moved to trading platforms
Juiceberg estimated that roughly 97% of the unauthorized tokens had already moved off-chain, meaning they were sent from Harmony addresses to deposit wallets associated with outside platforms or had already been sold. The account estimated that about 115 million ONE remained available for the attacker to sell on-chain, equal to around 2.9% of the newly minted supply.
The speed of those transfers would complicate Harmony’s response. Once tokens reach centralized trading venues, projects generally need cooperation from the relevant platforms to identify, freeze, and potentially return funds. Transactions that have already been converted into other assets or withdrawn to private wallets are typically more difficult to track and recover.
The reported mint increased the circulating token base by roughly 26%, according to the source material. A sudden increase of that scale places immediate pressure on the market because existing holders face dilution while the attacker has a strong incentive to sell quickly. The market impact can exceed the nominal value of the tokens if liquidity is thin and buyers step away during the disruption.
Juiceberg said around 2.8 billion of the newly created ONE had been rapidly sent to multiple trading platforms. Harmony has not publicly identified the addresses involved, named the platforms contacted, or said whether any stolen tokens had been frozen.
Rollback would reverse more than the exploit
Harmony said it was evaluating rollback options, a remedy that would return the blockchain to a point before the unauthorized minting occurred. Such a move could remove the fraudulent supply from the chain, but it would also reverse legitimate transactions confirmed after the selected rollback point.
That creates a practical trade-off for validators, applications, and users. Transfers, decentralized-finance activity, staking changes, or other valid transactions included after the exploit could disappear from the chain’s history if the network adopts a rollback. The longer the response takes, the more activity could potentially be affected.
A rollback also requires coordination across the ecosystem. Network participants must run compatible software, while wallets, infrastructure providers, and applications need to recognize the restored chain state. Platforms holding deposits may also need to decide which version of events they treat as final for customer balances.
Harmony’s statement suggests the project has not yet chosen between a rollback and a remediation approach focused on patching the vulnerability and containing the stolen funds. The final decision will likely depend on whether the exploit can be cleanly isolated, how much of the supply remains controlled by the attacker, and whether network participants support a chain reversal.
A second major security crisis for Harmony
The incident returns Harmony to the spotlight after the June 2022 attack on its Horizon cross-chain bridge, in which nearly $100 million in crypto assets were stolen. The stolen assets included Ethereum and stablecoins held by the bridge, which connected Harmony with other blockchain networks.
In January 2023, the FBI attributed the Horizon bridge theft to Lazarus Group and APT 38, groups linked to North Korea. Security researchers had previously tied that breach to the compromise of the bridge’s multi-signature wallet, where multiple approvals were supposed to protect funds from unilateral access.
The latest event differs from the Horizon attack in a crucial operational respect: the reported loss stems from unauthorized creation of Harmony’s own native asset rather than the theft of assets locked in a bridge. That gives the project a more direct technical option to erase the affected supply through a rollback, while also placing the integrity of the chain’s monetary rules at the center of the response.
The source material also pointed to a December 2023 software issue that reportedly created 146.3 million ONE tokens by mistake. Harmony has not linked that earlier event to the current exploit, and it has not said whether the two incidents involved the same token issuance code or validation process.
Harmony launched its mainnet in 2019 as a proof-of-stake blockchain. ONE is used for transaction fees, staking, and governance, so disruption to the token’s supply affects both market participants and the network’s basic operating incentives.
For now, Harmony’s response will be judged on whether its patch closes the minting path, whether stolen tokens can be stopped before further sales, and whether any rollback can be carried out without creating another dispute over transaction finality.
Concerned about exploits and rollbacks? Strengthen your security knowledge with our guide on proof-of-stake fundamentals.
Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.

