Harmony blockchain has suffered a major security exploit that resulted in the fraudulent minting of approximately 4 billion ONE tokens, representing about 26% of the cryptocurrency’s total supply. The incident involved a vulnerability associated with empty blocks and triggered a rapid movement of the newly created tokens across hundreds of wallets.
The scale of the exploit has raised concerns about the impact on existing ONE holders, market stability and the blockchain’s transaction history. More than 10,000 transfers involving the fraudulently minted tokens were traced across 409 wallets. Of the affected tokens, about 2.8 billion were reportedly transferred to cryptocurrency exchanges, contributing to a sharp decline in the price of ONE, which fell by as much as 50%.
Harmony has responded by deploying an emergency software patch, asking validators to upgrade, pausing its bridge and working with exchanges to freeze funds linked to the exploit.
Harmony Traces Funds and Alerts Exchanges
Harmony said its investigation had identified 10,288 transfers involving the affected tokens across the 409 wallets where the assets had been distributed. The blockchain project also notified exchange partners about hundreds of suspicious deposit transactions associated with the stolen funds.
According to Harmony, exchange partners responded by blocking and freezing the identified hacker-controlled wallets. The company also provided exchanges with information linking the suspicious funds to four wallet addresses believed to be connected to the exploit.
The effort is intended to prevent the fraudulently created ONE tokens from being converted into other assets or withdrawn from trading platforms while the blockchain team determines how to address the underlying damage.
Harmony also paused its bridge service, bridge.harmony.one, following the incident. The measure was intended to reduce the possibility of further movement of affected assets while the emergency response was underway.
Emergency Patch Targets Minting Vulnerability
Harmony released an emergency software update designated v2026.1.1 and instructed validators to upgrade their nodes. The patch was designed to prevent the vulnerability from being exploited to create additional tokens.
We are asking all exchanges to block and freeze funds that traces back to these 4 wallet addresses:
one1uap8dx2z0qsjxqthm5flgcxkeepsz3gsrghnfn
0xe7427699427821230177dd13f460d6ce43014510one17u300a40ll5wphd8kj5hktryhdjq3ml9f4phy4
0xf722f7f6afffe8e0dda7b4a97b2c64bb6408efe5… https://t.co/wiR6uQOazW— Harmony 💙 (@harmonyprotocol) August 12, 2026
The blockchain project reported that 53% of its validators had completed the upgrade roughly four hours after the emergency patch was released. Harmony thanked validators and other participants for supporting the rapid response, while continuing to work on measures addressing the tokens that had already been minted.
The distinction between stopping additional minting and resolving the existing supply increase remains significant. While the patch can prevent the same vulnerability from generating more tokens, it does not automatically remove the billions of ONE already created through the exploit.
Rollback Could Reshape Recent Transactions
Harmony indicated that a blockchain rollback had emerged as the most practical solution under consideration. Such a move could potentially remove fraudulent transactions from the chain and restore the ledger to a state before the exploit occurred.
Due to the incident, we have paused https://t.co/V2erl739xF. https://t.co/mavyY3dSGg
— Harmony 💙 (@harmonyprotocol) August 12, 2026
However, a rollback could create complications for legitimate users. Transactions involving the affected tokens may have passed through exchanges or other wallets before the funds were identified. Reversing blockchain activity could therefore affect users who acquired the assets without knowing they were connected to the exploit.
All validators, please upgrade. This patch prevents any further minting.
We'll follow up with another update to address the already minted tokens.https://t.co/FpjmbuBNTG https://t.co/JcmP22Nkat
— Harmony 💙 (@harmonyprotocol) August 12, 2026
At the same time, leaving the fraudulent tokens in circulation could substantially dilute existing holders because the unauthorized minting increased the effective supply by billions of ONE.
The rollback decision therefore represents a major trade-off: removing fraudulent activity could restore the intended token supply, while reversing transactions may also affect legitimate users who interacted with the blockchain after the exploit.
We traced 10288 transfers across all 409 wallets where the fraudulently minted tokens have landed, and alerted exchange partners on hundreds of suspicious deposit transactions. They promptly blocked the hacker’s wallets.
As of now, 53% of our validators completed the upgrade…
— Harmony 💙 (@harmonyprotocol) August 12, 2026
Harmony has said it will provide additional details after evaluating the available options. Until a final resolution is reached, the project is relying on validator upgrades, exchange-level fund freezes and the suspension of its bridge to contain the incident.
The exploit highlights the continuing security risks faced by blockchain networks, where a vulnerability affecting transaction processing or block validation can have immediate consequences for token supply, market prices and user funds. The incident also underscores the importance of rapid coordination among blockchain developers, validators and cryptocurrency exchanges when responding to large-scale security breaches.
With the emergency patch preventing further fraudulent minting, Harmony’s next major challenge is determining how to handle the approximately 4 billion previously created ONE tokens without causing unnecessary disruption to legitimate users.







