🔥BTC/USDT

Harmony exploit expands ONE supply by 3 trillion

Harmony’s ONE token was hit by an apparent unlimited-mint exploit on Aug. 12 after an attacker abused flaws in the network’s cross-shard receipt verification, creating more than 3 trillion unauthorized tokens across six abnormal blocks, according to CertiK Alert. CertiK valued the event at approximately $2.34 billion, a figure that dwarfed Harmony’s pre-incident market capitalization of roughly $17 million.

The incident placed immediate pressure on ONE’s market. Price data included with the initial reports showed the token falling from about $0.00118 to $0.00056 before recovering near $0.00078, leaving it down nearly 38% over 24 hours. Trading volume reportedly climbed to $36.9 million as the market absorbed a large volume of newly created tokens.

Harmony suspended its bridge service and urged validators to install patch version v2026.1.1, saying the upgrade was designed to prevent additional unauthorized minting. The response focuses on stopping the exploit from producing more supply, while the network faces a separate challenge: determining how to handle tokens that had already entered trading venues and wallets.

Forged receipts enabled repeated minting

BlockWatchdog’s technical analysis traced the exploit to forged inter-shard transfer receipts, messages Harmony uses to recognize transfers between different parts of its network. The attacker’s receipts referenced epoch 100, a much older period than Harmony’s current epoch range above 3,000, carried zero signatures, and identified the source of funds as the 0x00…dEaD address.

Under normal conditions, validator signatures are intended to prove that a cross-shard transaction was approved by the relevant committee. BlockWatchdog said Harmony’s vulnerable code checked the committee size rather than verifying the number of valid signatures included with the receipt. That error allowed a receipt with no genuine validator approval to pass a critical verification stage.

A second weakness compounded the failure. Harmony’s replay protections for old-epoch receipts relied on fields that BlockWatchdog said could be controlled by the attacker. That gave the attacker a way to reuse fabricated receipts repeatedly, turning a single verification flaw into a mechanism for creating large quantities of ONE.

The result was an inflation event on a scale far beyond the network’s existing economy. On-chain researcher Juiceberg initially estimated the unauthorized mint at about 4 billion ONE, then worth more than $3 million and equal to around 26% of total supply. Later monitoring identified more than 3 trillion minted tokens as additional abnormal blocks were processed.

The different estimates reflect the exploit’s progression across blocks rather than a conventional theft from a fixed pool of assets. The attacker appears to have generated new ONE units directly through manipulated network logic, creating a supply overhang that cannot be resolved simply by recovering funds from a single wallet.

Tokens reached exchange deposit systems

Juiceberg’s tracking indicated that roughly 2.8 billion ONE was transferred into exchange deposit systems during the selloff. About 115 million ONE remained under the attacker’s control on Harmony’s native chain, representing around 2.9% of Juiceberg’s earlier 4 billion-token estimate.

Harmony published four addresses for screening and freezing:

  • one1uap8dx2z0qsjxqthm5flgcxkeepsz3gsrghnfn
  • one17u300a40ll5wphd8kj5hktryhdjq3ml9f4phy4
  • one1a5hur07z5vtvzhr35zkw8tfqedemkz8t88xgd7
  • one1h56hkxmua0uzfv07fu04cudvtrl35u96pq47vy

Transfers into exchange infrastructure make a network-level response more difficult. Validators could potentially consider a rollback, restoring Harmony to a state before the exploit occurred, but tokens may already have changed hands after entering external trading systems. A rollback would also affect legitimate transactions that occurred after the chosen restoration point, creating operational and governance complications.

Harmony had not confirmed a rollback decision in the material provided. The validator upgrade instead addresses the immediate vulnerability, leaving the treatment of minted balances and post-exploit transactions unresolved.

A depleted network faces another supply crisis

The exploit arrives after years of security failures that have weakened Harmony’s position in decentralized finance. DefiLlama data cited in the report placed the network’s total value locked below $170,000, compared with a peak above $1.4 billion in 2022.

That year, Harmony’s Horizon bridge lost about $100 million in assets. The FBI later attributed the theft to a North Korea-linked hacking group. The bridge attack involved assets held by an interoperability service, while the latest incident strikes closer to the chain’s own token issuance and validation logic.

Harmony also suffered a supply-related failure in December 2023, when a staking bug mistakenly minted about 146.3 million ONE across 74 addresses. One address received more than 51 million ONE, and some tokens reached exchange deposit systems before a patch was released.

The latest event is substantially larger in reported token quantity and came when Harmony’s market capitalization was far smaller. Figures included with the incident placed its capitalization at about $12 million after the selloff, down roughly $5 million from before the exploit.

Whether Harmony can contain the damage will depend on validator coordination, the handling of flagged addresses, and the response of platforms that received transferred ONE. The patch may stop the minting route described by BlockWatchdog, but the chain must still establish which balances and transactions remain valid after an exploit that directly altered the token supply.


Concerned about exploits like Harmony’s? Strengthen your defenses by exploring crypto security breach lessons for safer trading decisions.

Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.

Sign up and trade to earn over 15,000 USDT
Sign up