Security

Harmony’s ONE Slides 26% After Apparent Exploit Mints Billions of Tokens

2 min read
Harmony's ONE Slides 26% After Apparent Exploit Mints Billions of Tokens

Harmony’s native token ONE dropped roughly 26% during Asian morning trading Wednesday after an apparent exploit generated about 4 billion new tokens. That figure exceeds a quarter of the chain’s existing supply, CoinDesk reported.

Approximately 15 billion ONE existed before the incident, per CoinDesk. The unauthorized mint, then, amounted to a 26% supply expansion in a single event. CoinGecko data cited by Cointelegraph pointed to a steeper 33.9% decline over the trailing 24 hours, a broader window than CoinDesk’s Asian-morning snapshot.

Harmony confirmed the attack on X. “We are working on a patch and rollback options,” the project wrote, adding it would share more when information was available.

A rollback would rewind the network to its pre-exploit state, scrubbing subsequent transactions from the blockchain’s accepted history. The move grows harder to pull off once funds reach exchanges or external systems. Many users consider rollbacks antithetical to blockchain immutability. Harmony has not said how far back any proposed rollback would reach.

The project is also coordinating with exchanges to freeze funds and preparing a software fix. Cointelegraph contacted Harmony for comment but had not received a response by publication.

An X account called Juiceberg claimed roughly 2.8 billion of the newly minted ONE were quickly funneled to exchanges as the price fell. About 115 million ONE, or 2.9% of the allegedly minted amount, remained onchain, per that account. Cointelegraph could not independently verify those figures. Harmony itself has not confirmed the cause of the exploit, the number of tokens created, or how much reached exchanges.

Wednesday’s incident involves creation of ONE on Harmony’s own chain rather than assets stolen from a bridge. That separates it from the June 2022 Horizon bridge hack, in which about $100 million was stolen after attackers compromised private keys. The FBI later attributed that theft to North Korea’s Lazarus Group.

The episode also echoes a smaller prior incident. In December 2023, a bug in Harmony’s staking system created about 146.3 million ONE. Tokens that should have stopped receiving payouts continued to receive them. Seventy-four addresses were involved. One received 51.2 million ONE. About 16.4 million was subsequently moved to an exchange. Harmony responded with an emergency software update and blacklisted the addresses.

The apparent exploit landed a day after Ravencoin, a smaller chain built from Bitcoin’s code, faced its own possible rollback after parts of its network accepted invalid blocks.

Harmony has not yet explained the vulnerability, how the 4 billion figure was calculated, or how far back any proposed rollback would go. The total dollar value of the exploit has not been confirmed by either source.

Holders, as ever, are divided. Some want the chain rewound. Others would rather eat the dilution.

Avatar of Mara Velasquez

Mara Velasquez

Mara Velasquez covers markets and DeFi for NFT Signals, reporting on price action, liquidity and the listed companies with crypto on their balance sheets. She also tracks exploits and stolen-funds recovery.