Harmony Confirms Exploit After 4 Billion ONE Tokens Reportedly Minted
- Harmony is exploring a rollback of its blockchain after an unauthorized mint of approximately 4 billion ONE tokens.
- Exchanges are being contacted to freeze affected funds while a patch is developed.
- The incident highlights the importance of cooperation with exchanges for recovery efforts after blockchain exploits.
Harmony is considering rolling back its blockchain after an apparent exploit reportedly created roughly 4 billion ONE tokens without authorization, a sudden issuance equal to more than a quarter of the token’s pre-incident supply.
The Harmony team said Wednesday that it was working with exchanges to stop and freeze affected funds while developing a patch and evaluating rollback options. Its initial statement did not identify the vulnerability, confirm the amount minted or specify which exchanges were involved.
On-chain analyst Juiceberg placed the unauthorized issuance at about 4 billion ONE and said it occurred through empty blocks, with roughly 2.8 billion ONE subsequently routed to exchanges. Harmony has not independently confirmed those figures or explained how blocks without ordinary transactions could have produced the additional tokens.
The reported mint is unusually large relative to ONE’s existing supply. Roughly 15 billion ONE were in circulation before the incident, putting 4 billion tokens at about 26% of that amount. ONE fell around 26% as reports of the exploit spread on Wednesday morning.
A rollback cannot recover every transfer
A rollback could remove the unauthorized mint and subsequent on-chain transfers from Harmony’s accepted history if validators agree to revert to an earlier state. It becomes more complicated once tokens reach centralized exchanges: trades recorded inside an exchange are not part of Harmony’s blockchain, making cooperation from those platforms important to any recovery attempt.
Harmony has faced an unintended supply increase before. A December 2023 staking bug repeatedly credited withdrawn stakes, ultimately creating nearly 150 million ONE across dozens of accounts before a fix was deployed.
The network was also hit by the $100 million Horizon Bridge theft in June 2022, though that attack involved compromised bridge keys rather than the creation of native ONE.
Harmony has not yet said how far a possible rollback would extend or when its patch will be released.
