Harmony Blockchain Hit by Major Exploit: 4 Billion ONE Tokens Minted Unauthorized, Token Crashes 37%
Layer-1 blockchain Harmony suffered a critical security breach when an attacker minted approximately 4 billion ONE tokens without authorization, causing the token to plummet 37%. The team is weighing whether to roll back the network to before the exploit.
The Attack and Immediate Impact
Harmony, a Layer-1 blockchain network, fell victim to a significant security exploit in which an attacker gained the ability to mint approximately 4 billion ONE tokens without authorization. The unauthorized token creation represents roughly 26% of the total ONE supply and triggered a sharp market selloff, with ONE plummeting 37% to trade around $0.00077 per token.
The exploit was initially discovered and reported by on-chain analyst Juiceberg early Wednesday, who identified the unusual minting activity through empty blocks. The timing proved devastating for token holders, as the newly created tokens rapidly flooded cryptocurrency exchanges. According to Juiceberg’s analysis, approximately 2.8 billion of the freshly minted tokens—roughly 97% of the total—reached exchange deposit wallets almost immediately after creation.
Technical Oddities and Lingering Questions
On-chain tracking revealed that the attacker retained only about 115 million ONE tokens still positioned for sale on-chain, representing approximately 2.9% of the total tokens minted during the exploit. The speed at which the tokens reached exchanges compounded the damage, overwhelming liquidity and triggering sharp selling pressure across multiple trading platforms.
Notably, price tracking services including CoinGecko continued to display the circulating supply at approximately 14.87 billion tokens, failing to account for the newly minted supply. An additional anomaly flagged by Juiceberg revealed that Harmony’s totalSupply endpoint did not initially reflect the inflated token count, creating confusion about the true extent of the damage.
Harmony’s Response and Rollback Dilemma
Harmony acknowledged the exploit and announced coordinated action with exchanges to identify and freeze funds associated with the attack. The team rapidly deployed a software patch and directed network validators to upgrade their software to prevent any further unauthorized minting. Beyond the immediate patch, Harmony disclosed it was evaluating a rollback—a drastic measure that would reset the network state to a point before the exploit occurred and continue forward from that checkpoint.
The rollback option carries significant implications. While it would eliminate the effects of the exploit, it would simultaneously erase all legitimate transactions conducted on the network after the attack was initiated, affecting ordinary users who conducted transactions in good faith. Harmony did not immediately disclose which path it would pursue or provide a complete technical breakdown of the vulnerability that allowed the exploit to succeed in the first place.
This represents Harmony’s second major security breach in recent years. In June 2022, hackers compromised the Horizon cross-chain bridge, draining approximately $100 million in assets. The FBI later attributed that attack to the Lazarus Group, a hacking operation linked to North Korea. Harmony’s initial response proposal for the 2022 breach involved minting billions of additional ONE tokens to reimburse affected users, but the plan faced significant community backlash and was ultimately abandoned.
The repeated compromises underscore how even established Layer-1 networks remain vulnerable to sophisticated attacks, a critical reminder that security remains paramount as the crypto industry matures.
For the broader crypto market, incidents like this underscore why robust security infrastructure and thorough auditing remain essential for building sustainable blockchain networks that can earn user trust.
Source: Harmony, via Decrypt. Not financial advice.