Harmony plans to roll back two of its main blockchain shards after concluding that an attacker forged more than 3 trillion ONE tokens through a flaw in its cross-shard transaction system. The recovery would erase all Shard 0 and Shard 1 blocks produced after the network identified the earliest confirmed unauthorized mint, removing both the counterfeit supply and legitimate activity recorded after that point.
The network said it selected a rollback after considering alternatives including a token burn, blacklisting wallets linked to the exploit, and migrating ONE to a replacement asset. Those options became less workable after forged tokens spread through decentralized exchange pools and blockchain bridges, where targeted removals could have affected users who were not involved in the attack.
Harmony’s core builders plan to restore Shard 0 to block 92,730,034 and Shard 1 to block 94,978,278. The reset would permanently remove more than 109,000 ordinary asset transfers and 315 staking records made after Aug. 11, according to the network.
The decision places ledger consistency ahead of preserving recent transactions. A rollback would return the affected shards to a state before the counterfeit tokens entered circulation, while wallet blacklists or selective burns would require the network to distinguish forged assets from tokens that may have been traded or pooled with legitimate holdings.
More than 3 trillion ONE traced to six mints
Harmony first confirmed the incident on Aug. 12, after detecting an unauthorized mint of ONE. An independent researcher had initially identified 4 billion tokens created through empty blocks, but Harmony later said that figure represented only the first known wave of activity.
A subsequent reconstruction found that 3.01 trillion ONE tokens were forged across six transactions and sent to four wallets controlled by the exploiter, Harmony said. One wallet moved nearly 2.4 trillion ONE in less than two minutes. At ONE’s price before the attack, that amount was valued at close to $3 billion.
The scale of the forged supply dwarfed normal token issuance and placed immediate pressure on the market. Harmony said the artificial supply contributed to a roughly 40% fall in ONE’s price and pushed the token to an all-time low.
The network said it traced nearly all of the forged tokens to identifiable wallets or services. Yet the movement of tokens through decentralized liquidity pools and bridges created a practical obstacle: funds could be mixed with assets held by unrelated users before a blacklist or burn could be applied.
That distinction helps explain why a rollback is a more disruptive but cleaner option. Rewinding the chain removes the transactions that created and moved the forged tokens in the first place. It also removes valid transactions made by users after the chosen restoration point, forcing service providers and users to reconcile balances with the rewritten chain history.
Receipt-validation flaw enabled repeated processing
Harmony attributed the exploit to a weakness in cross-shard receipt verification. In a sharded blockchain, separate chains process activity in parallel, and receipts provide evidence that an action on one shard should be recognized on another. The vulnerability allowed valid receipts to be processed more than once, enabling ONE to be minted without an equivalent debit on the originating side.
Harmony said the attack code was able to pass empty batches through the system without the approvals the protocol was supposed to require. According to the network’s description, the verification logic counted the full validator list rather than confirming the digital signatures actually supplied for a batch.
That error undermined the intended security threshold. Instead of requiring a valid set of validator approvals, the system could treat an empty or insufficiently signed set of data as meeting the approval condition. The attacker then used that weakness to create new tokens without reducing a corresponding balance elsewhere on the network.
Harmony said it patched the vulnerability on Aug. 12, the day the unauthorized mint was detected. Patching the code prevents the same method from being used again, but it does not by itself reverse the counterfeit supply or unwind transfers that followed.
The planned rollback therefore addresses a separate problem from the patch. The code fix closes the route used by the attacker, while the chain reset would remove the affected historical state from the two shards.
Users and services face a ledger reset
The rollback would require exchanges, bridge operators, wallet providers and other services supporting Harmony to update their internal records to match the restored chain. Deposits, withdrawals, staking actions and token transfers recorded after the rollback point could disappear from Shard 0 and Shard 1 even if users previously saw them as completed.
Harmony advised users to avoid moving funds across its bridges while the recovery is underway and until the updated client software is released. The network identified version v2026.1.2 as the required update for future transfers.
Users holding ONE or other assets on the affected shards will need to follow the chain selected by the validator set after the rollback. Transactions created in the discarded period would no longer form part of the canonical ledger, meaning a balance displayed by an exchange or wallet provider may need adjustment once its systems synchronize with the restored history.
The episode also exposes the difficulty of responding to a large-scale mint exploit on networks that connect multiple execution environments. Freezing wallets can contain funds that remain identifiable, but decentralized pools and bridge transfers can rapidly distribute exposure across applications and chains. Harmony’s proposed reset is designed to remove that uncertainty at the ledger level, though it comes with the direct cost of erasing a substantial volume of normal user activity.
Concerned about exploits and forged tokens? Strengthen your defenses with our guide on crypto safety standards every trader should know.
Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.
