Harmony Hit by Fresh Exploit as Attacker Mints Tens of Billions of ONE
Hack-driven exploits are increasingly becoming one of the biggest threats to crypto protocols. On Aug. 12, X user Juiceberg said on-chain data pointed to an exploit affecting Harmony, where an attacker illicitly minted roughly 40 billion ONE tokens—valued at more than $3 million—equal to about 26% of the token's total supply.
During the ensuing selloff, about 2.8 billion ONE were quickly transferred to exchanges. Harmony's total-supply endpoint did not show the newly minted tokens, creating a gap between the actual on-chain supply and the figures publicly reported. The attacker is still holding around 115 million ONE on-chain (about 2.9% of the minted amount), while most of the tokens appear to have moved into exchange accounts, either sold or sitting in deposit wallets.
Following the disclosure, ONE fell from $0.00118 to an intraday low of $0.00056 before rebounding to about $0.00078, down nearly 38% over the past 24 hours.
Harmony's official X account said it is working with its team and multiple exchanges to block and freeze funds linked to the incident, while pushing software patches and assessing a potential network rollback. The team also published four wallet addresses and asked exchanges to freeze any funds traceable to them:
one1uap8dx2z0qsjxqthm5flgcxkeepsz3gsrghnfn
one17u300a40ll5wphd8kj5hktryhdjq3ml9f4phy4
one1a5hur07z5vtvzhr35zkw8tfqedemkz8t88xgd7
one1h56hkxmua0uzfv07fu04cudvtrl35u96pq47vy
At around 2:00 p.m., Harmony said the bridge.harmony.one cross-chain bridge had been suspended due to the security incident, and required all validator nodes to upgrade immediately to patch version v2026.1.1. The team said this release prevents further unauthorized minting, with a follow-up update to address tokens already minted. The release notes are available on GitHub.
The episode marks the third major token-supply-related security or technical event for Harmony in recent years. In June 2022, Harmony's Horizon bridge was hacked for roughly $100 million, an incident later attributed by the U.S. Federal Bureau of Investigation to a North Korea-linked hacking group. In December 2023, a staking-system bug mistakenly minted about 146.3 million ONE across 74 addresses, including more than 51 million ONE to a single address; some tokens were later transferred to exchanges, and the team issued a patch and follow-up measures.
From a market standpoint, the event triggered sharp dilution concerns and volatility, though the absolute loss appeared limited. Harmony's market cap had already fallen to about $17 million before the incident and slid to roughly $12 million afterward, implying an estimated $5 million decline. Harmony's total value locked (TVL) peaked above $1.4 billion in 2022, but DefiLlama data now show TVL below $170,000.
CertiK Alert later reported that, as of around 4:00 p.m., more than 3 trillion ONE tokens had been anomalously minted on Harmony across six abnormal blocks, with an estimated value of about $2.34 billion. CertiK said the attacker initially leveraged the total-supply API to obscure minting data, and as blocks were bundled progressively, the earlier figure of 40 billion was far from the full amount.
X account BlockWatchdog attributed the incident to a critical logic flaw in Harmony's cross-shard receipt verification and signature validation, alleging an attacker forged roughly 3 trillion coins in a single operation. Harmony is a sharded chain where transfers between shards require a "receipt" as proof. BlockWatchdog said the forged receipts referenced an early epoch (epoch 100, versus more than 3,000 today), contained empty signatures (zero signatures), and cited transfers from a dead address (0x00…dEaD). Under normal conditions, such requests should have been rejected.
Two weaknesses were highlighted. First, signature verification was reportedly implemented incorrectly: when checking whether "enough people signed," the system checked committee size rather than the number of actual signatures provided, allowing empty signatures to pass as long as committee size was at least four. Second, replay protection was said to be flawed: for older epochs, the "has this receipt been used before?" check relied on a field the attacker could control, enabling repeated reuse of the same fake receipt or bypassing the check. Combined, these issues could allow minting on the scale of trillions of tokens.
As of publication, Harmony had not confirmed whether it will execute a rollback. While a rollback could restore the chain state to a point before the exploit and theoretically erase some effects of unauthorized minting, its practical impact would be limited if large volumes of tokens have already been deposited to centralized exchanges and traded.
Near-term market focus is on whether exchanges effectively freeze related funds, how quickly validators adopt the patch, and what plan is implemented for already minted tokens. Harmony, an early high-performance, low-fee Layer 1 once prominent in DeFi and cross-chain narratives, has seen visibility fade amid repeated security incidents and a prolonged market-cap decline. The latest event again underscores the fragility of low-cap public chains in consensus and supply mechanisms, and highlights the need for closer scrutiny of security track records and real on-chain activity.