Harmony was hit by another token supply-related security incident on Aug. 12, after onchain data cited by X user Juiceberg indicated that the protocol had been exploited and roughly 4 billion ONE were illicitly minted through empty blocks. That initial amount was valued at a little over $3 million and represented 26% of the token’s total supply.
According to the early findings, about 2.8 billion of those tokens were quickly moved to exchanges during the price plunge. Harmony’s total supply endpoint also failed to reflect the newly minted tokens, creating a mismatch between actual onchain supply and publicly displayed data. Roughly 115 million ONE remained onchain in the attacker’s possession, or about 2.9% of the minted amount at that stage, while most of the rest had already moved into exchange accounts, were sold, or sat in deposit wallets.
After the incident became public, ONE dropped from $0.00118 to a low of $0.00056, then recovered to $0.00078. The token was still down nearly 38% over 24 hours.
Harmony moves to freeze funds and push a patch
Harmony later reposted a response on X saying it was working with its team and several relevant exchanges to block and freeze the funds tied to the incident. The project also said it was developing a software patch and evaluating a possible network rollback.
It then published four wallet addresses and explicitly asked exchanges to block and freeze any funds traceable to them:
- one1uap8dx2z0qsjxqthm5flgcxkeepsz3gsrghnfn
- one17u300a40ll5wphd8kj5hktryhdjq3ml9f4phy4
- one1a5hur07z5vtvzhr35zkw8tfqedemkz8t88xgd7
- one1h56hkxmua0uzfv07fu04cudvtrl35u96pq47vy
At around 2 p.m., Harmony said it had suspended the bridge.harmony.one cross-chain bridge because of the security incident and instructed all validators to upgrade immediately to patch version v2026.1.1. The team said the patch would stop further unauthorized minting, with another update to follow for handling tokens that had already been created. A related release record was already visible on GitHub.
Later monitoring raised the abnormal mint above 3 trillion ONE
The initially reported 4 billion ONE did not reflect the full scale of the incident. According to CertiK Alert, by around 4 p.m. the amount of abnormally minted ONE on the Harmony network had exceeded 3 trillion, worth about $2.34 billion at the time, across six anomalous blocks.
The earlier, much smaller figure was attributed to the attacker’s use of the total supply interface to conceal the inflation, while additional blocks were still being packaged. That meant the first observed 4 billion ONE was far from the real total.
BlockWatchdog points to flaws in cross-shard receipt verification
X account BlockWatchdog said the attacker exploited severe logic flaws in Harmony’s cross-shard receipt verification and signature checking, allowing the creation of roughly 3 trillion tokens in one sweep.
Harmony is a sharded chain, and transfers between shards rely on receipts as proof. According to BlockWatchdog’s analysis, the attacker forged such receipts and set them up with several abnormal traits: they referenced a very old epoch, epoch 100, while the network is already beyond 3,000 epochs; the signatures were completely empty, or zero signatures; and the transfer source was a dead address, 0x00…dEaD.
Under normal conditions, the system should have rejected such receipts. BlockWatchdog said two flaws made that possible anyway. First, the signature verification logic was wrong. When checking whether enough parties had signed, the system looked at the total number of committee members rather than the number of actual signers. As a result, if the committee size was at least four, an all-empty signature set could still pass.
Second, the replay protection had a flaw. For receipts tied to old epochs, the system’s check for whether a receipt had already been used relied on a field the attacker could fill in. In BlockWatchdog’s description, that allowed the same forged receipt to be reused or the protection check to be bypassed.
Taken together, those two flaws let the attacker mint tokens on a massive scale.
Third major supply-linked issue in recent years
This is Harmony’s third major security or technical problem in recent years tied directly to token supply.
In June 2022, Harmony’s Horizon bridge was attacked, with about $100 million in assets lost. The Federal Bureau of Investigation later attributed that incident to a North Korea-linked hacking group.
In December 2023, a bug in the staking system led to the erroneous minting of about 146.3 million ONE across 74 addresses. One address received more than 51 million ONE, and some of the tokens were later moved to exchanges. Harmony released an emergency patch at the time and took follow-up measures.
Market value and TVL had already shrunk sharply
In absolute terms, the loss tied to this incident remained limited even though it heavily diluted supply and caused sharp price swings. Before the event, Harmony’s market capitalization had already fallen to around $17 million. Afterward, it slipped further to roughly $12 million, wiping out about $5 million in market value.
Harmony’s total value locked once peaked above $1.4 billion in 2022. The latest DefiLlama data shows its TVL has now fallen to less than $170,000.
Rollback decision still unconfirmed
As of publication, Harmony had not confirmed whether it would ultimately carry out a network rollback. A rollback would restore chain state to a point before the attack and could in theory remove part of the impact from the illicit minting. If large amounts of tokens have already entered centralized exchanges and been traded, though, the practical effect would be much more limited.
Whether exchanges can effectively freeze the funds, how quickly validators adopt the patch, and what plan is used to handle the already minted tokens are now the central issues to watch in the near term.
Harmony was once an early Layer 1 chain known for high performance and low fees, with a place in DeFi and cross-chain narratives. After repeated security incidents and a long decline in market value, its profile in the broader crypto market has faded considerably.

