Harmony, the Layer-1 blockchain protocol, has mapped out a sprawling web of unauthorized token transfers after an exploit flooded the network with billions of freshly minted ONE tokens. The team identified 10,288 transactions funneling fraudulent tokens into 409 distinct wallets.
Approximately 4 billion ONE tokens were minted without authorization. That figure represents roughly 26% of Harmony’s entire prior token supply.
How the exploit unfolded
The attacker exploited a vulnerability involving empty blocks to mint the tokens, a technique that bypassed normal validation mechanisms on the network.
Around 2.8 billion of the fraudulently minted ONE tokens were quickly routed toward various cryptocurrency exchanges. ONE’s price cratered between 26% and over 50% intraday as traders digested the news.
Harmony’s team moved to alert exchange partners, asking them to freeze any funds tied to the implicated wallets.
Harmony’s emergency response
Beyond contacting exchanges, Harmony deployed a software patch designed to close the vulnerability that enabled the exploit. The team also paused its bridge, cutting off a potential avenue for the attacker to move tokens cross-chain.
Perhaps the most dramatic measure under consideration is a potential rollback of the blockchain itself. Rolling back a chain essentially means rewinding the ledger to a point before the exploit occurred, erasing the fraudulent transactions as if they never happened.
Early findings from the investigation suggest the exploit was isolated to Harmony’s own infrastructure. No other protocols or unrelated entities appear to be linked to the identified transfers.
A pattern that’s hard to ignore
This is not Harmony’s first encounter with a serious security breach. In June 2022, the protocol’s Horizon bridge was exploited for approximately $100 million, an attack later attributed to North Korea’s Lazarus Group. Then in late 2023, Harmony faced an infinite mint bug that affected roughly 150 million ONE tokens, exposing a similar category of vulnerability: the ability to create tokens outside of intended protocol rules.
For ONE token holders, the immediate financial damage is clear. A 26% to 50% price decline wipes out significant portfolio value, and the uncertainty around whether a rollback will occur creates additional risk. If the chain does roll back, holders who purchased ONE after the exploit at depressed prices could see those transactions reversed. If it doesn’t, the inflated supply permanently dilutes existing holders.
Exchange freezes will be critical to the outcome. If a meaningful portion of the 2.8 billion ONE tokens sent to exchanges can be recovered or frozen, the economic impact shrinks considerably. If those tokens were already sold into the market before freezes took effect, the dilution is real and the damage is done.
Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

10 hours ago
11









English (US) ·