CoinTrust

Harmony Blockchain Exploit Mints 4 Billion ONE Tokens

harmony

Harmony blockchain has suffered a major security exploit that resulted in the fraudulent minting of approximately 4 billion ONE tokens, representing about 26% of the cryptocurrency’s total supply. The incident involved a vulnerability associated with empty blocks and triggered a rapid movement of the newly created tokens across hundreds of wallets.

The scale of the exploit has raised concerns about the impact on existing ONE holders, market stability and the blockchain’s transaction history. More than 10,000 transfers involving the fraudulently minted tokens were traced across 409 wallets. Of the affected tokens, about 2.8 billion were reportedly transferred to cryptocurrency exchanges, contributing to a sharp decline in the price of ONE, which fell by as much as 50%.

Harmony has responded by deploying an emergency software patch, asking validators to upgrade, pausing its bridge and working with exchanges to freeze funds linked to the exploit.

Harmony Traces Funds and Alerts Exchanges

Harmony said its investigation had identified 10,288 transfers involving the affected tokens across the 409 wallets where the assets had been distributed. The blockchain project also notified exchange partners about hundreds of suspicious deposit transactions associated with the stolen funds.

According to Harmony, exchange partners responded by blocking and freezing the identified hacker-controlled wallets. The company also provided exchanges with information linking the suspicious funds to four wallet addresses believed to be connected to the exploit.

The effort is intended to prevent the fraudulently created ONE tokens from being converted into other assets or withdrawn from trading platforms while the blockchain team determines how to address the underlying damage.

Harmony also paused its bridge service, bridge.harmony.one, following the incident. The measure was intended to reduce the possibility of further movement of affected assets while the emergency response was underway.

Emergency Patch Targets Minting Vulnerability

Harmony released an emergency software update designated v2026.1.1 and instructed validators to upgrade their nodes. The patch was designed to prevent the vulnerability from being exploited to create additional tokens.


The blockchain project reported that 53% of its validators had completed the upgrade roughly four hours after the emergency patch was released. Harmony thanked validators and other participants for supporting the rapid response, while continuing to work on measures addressing the tokens that had already been minted.

The distinction between stopping additional minting and resolving the existing supply increase remains significant. While the patch can prevent the same vulnerability from generating more tokens, it does not automatically remove the billions of ONE already created through the exploit.

Rollback Could Reshape Recent Transactions

Harmony indicated that a blockchain rollback had emerged as the most practical solution under consideration. Such a move could potentially remove fraudulent transactions from the chain and restore the ledger to a state before the exploit occurred.


However, a rollback could create complications for legitimate users. Transactions involving the affected tokens may have passed through exchanges or other wallets before the funds were identified. Reversing blockchain activity could therefore affect users who acquired the assets without knowing they were connected to the exploit.


At the same time, leaving the fraudulent tokens in circulation could substantially dilute existing holders because the unauthorized minting increased the effective supply by billions of ONE.

The rollback decision therefore represents a major trade-off: removing fraudulent activity could restore the intended token supply, while reversing transactions may also affect legitimate users who interacted with the blockchain after the exploit.


Harmony has said it will provide additional details after evaluating the available options. Until a final resolution is reached, the project is relying on validator upgrades, exchange-level fund freezes and the suspension of its bridge to contain the incident.

The exploit highlights the continuing security risks faced by blockchain networks, where a vulnerability affecting transaction processing or block validation can have immediate consequences for token supply, market prices and user funds. The incident also underscores the importance of rapid coordination among blockchain developers, validators and cryptocurrency exchanges when responding to large-scale security breaches.

With the emergency patch preventing further fraudulent minting, Harmony’s next major challenge is determining how to handle the approximately 4 billion previously created ONE tokens without causing unnecessary disruption to legitimate users.

Exit mobile version