Harmony Exploited in Unauthorized Mint of 4 Billion ONE
Harmony’s ONE token plunged sharply on Aug. 12 after the Layer-1 blockchain suffered a suspected exploit that reportedly allowed an attacker to mint roughly 4 billion ONE without authorization.
The newly created tokens represent about 26% of the roughly 15 billion ONE that were circulating before the incident, raising concerns about a sudden increase in supply and triggering heavy selling pressure. Harmony confirmed the security incident and said it was working on an emergency patch while evaluating rollback options.

Harmony Exploited in Unauthorized Mint of 4 Billion ONE (Source: X)
Billions of ONE Reportedly Minted
On-chain analyst Juiceberg reported that approximately 4 billion ONE were created through empty blocks on the Harmony network. If confirmed, the issuance would be equivalent to more than one-quarter of the token’s previously circulating supply.
Harmony has not independently confirmed the 4 billion figure or disclosed the vulnerability that enabled the unauthorized mint. Instead, the project said it was working to prevent further token creation and determine how to handle the tokens that had already been generated.
The incident became more serious as large amounts of the newly minted ONE were reportedly transferred to cryptocurrency exchanges. Juiceberg estimated that around 2.8 billion ONE reached exchanges, while roughly 115 million remained available for sale on-chain at one point. Harmony has not confirmed those figures, so they remain analyst estimates.
If the estimates are accurate, the rapid movement of tokens to exchanges could make recovery significantly more difficult. Funds that remain identifiable can potentially be frozen, while tokens that have already been sold or transferred to other wallets may be harder to trace and recover.
Harmony Moves to Contain the Attack
Harmony said it identified four wallet addresses linked to the incident and asked cryptocurrency exchanges to block and freeze funds originating from them.
The project also paused its token bridge and instructed network operators to install an emergency software update intended to prevent further unauthorized minting. Harmony said it was working on a patch and considering rollback options.
A rollback would involve returning the blockchain to a state before the exploit and effectively removing subsequent transactions from the accepted chain history. Such a move could potentially eliminate unauthorized tokens that remain on the network, but it would also risk reversing legitimate transactions made during the affected period.
That creates a difficult choice for Harmony. While a rollback can be an effective emergency response, blockchain immutability is a fundamental principle of decentralized networks. Reversing transactions could therefore create additional controversy among users and developers.
Harmony has not yet announced whether it will proceed with a rollback or identified the specific block range that could be affected.


Four wallet addresses were linked to the incident
ONE Price Drops Sharply
The suspected exploit immediately sent ONE lower as traders reacted to the potential increase in supply.
According to the source material, ONE fell more than 39% at one point to approximately $0.000747. The sharp decline highlights the market’s sensitivity to unauthorized token issuance, particularly when the reported amount is large compared with the existing supply.
The potential impact goes beyond the tokens allegedly controlled by the attacker. Even if a portion of the newly created ONE can be frozen, uncertainty over the final supply can weigh on investor confidence and increase volatility.
The lack of an official supply reconciliation also leaves an important question unanswered: exactly how many ONE were created?
Until Harmony publishes a definitive figure, the reported 4 billion figure should be treated as an on-chain analyst estimate rather than a confirmed final total.


Harmony (ONE) Price Performance (Source: CoinMarketCap)
Harmony Has Faced Unauthorized Minting Before
This is not the first incident involving unintended ONE creation.
In 2023, a vulnerability in Harmony’s staking logic resulted in approximately 146.3 million ONE being minted across 74 delegator addresses. According to Harmony’s technical report, the issue involved undelegation records that were not properly cleared after validator commission changes. Some matured undelegations consequently received repeated payouts across multiple epochs, creating tokens outside the intended issuance process.
Harmony responded with an emergency hard fork and deployed a fix at block 51,118,080.
The project has also experienced a major security breach involving its Horizon Bridge. In June 2022, attackers stole roughly $100 million worth of cryptocurrency after compromising private keys controlling the bridge. The FBI later attributed the attack to North Korea-linked Lazarus Group actors.
The latest incident is different from the Horizon Bridge hack because the reported damage involves the creation of new ONE directly on Harmony’s Layer-1 network rather than the theft of assets held by a bridge.
What Happens Next?
Harmony now faces several critical questions: what vulnerability enabled the unauthorized mint, how many ONE were actually created, how many remain under the attacker’s control and how much can exchanges successfully freeze?
The decision over a potential rollback could be equally important. Reverting the chain might help eliminate unauthorized transactions, but it could also affect legitimate users and further challenge confidence in the network’s transaction finality.
For Harmony, the priority is to stop any additional unauthorized issuance, identify the root cause and establish an accurate accounting of the affected tokens. Cooperation from cryptocurrency exchanges will also be crucial if large quantities of the newly minted ONE have already entered centralized trading platforms.
As of Aug. 12, Harmony had confirmed the security incident but had not publicly confirmed the reported 4 billion ONE figure or disclosed the underlying vulnerability. The project said it would provide further updates as its investigation and response progress.
The incident leaves Harmony facing another major test of its security infrastructure and its ability to restore confidence after an unauthorized expansion of its token supply.
