In brief
- Harmony has acknowledged a security breach where an attacker minted approximately 4 billion ONE tokens, constituting around 26% of the total supply.
- According to on-chain analyst Juiceberg, nearly 97% of the minted tokens have already been moved to exchanges.
- Following the incident, ONE's value dropped by 37%, trading at about $0.00077, as Harmony implemented a patch to prevent further minting.
Harmony, a layer-1 blockchain, confirmed that it experienced a hack in which an unauthorized party minted around 4 billion ONE tokens, leading to a 37% decline in the token's price to approximately $0.00077, based on data from CoinGecko.
On-chain analyst Juiceberg reported the incident early Wednesday, estimating that nearly 4 billion tokens were minted, which is about 26% of the total supply, generated through empty blocks. Approximately 2.8 billion of these tokens were funneled onto exchanges as the price fell.
In a subsequent tweet, Juiceberg noted that the attacker still possesses about 115 million ONE tokens, which is around 2.9% of the total minted. "The overwhelming majority (~97%) is already on exchanges," he mentioned, indicating that these tokens had either been sold or were in deposit wallets.
In response, Harmony tweeted that it was collaborating with its team and relevant exchanges to halt and freeze the funds, while also preparing a patch and considering rollback options. They later identified four wallets involved in the incident and requested exchanges to block any transactions associated with them.
We are working with our team and appropriate exchanges to stop and freeze the funds.
We are working on a patch and rollback options.
Will update when we have new information. https://t.co/XB0nCwTAyN
ā Harmony š (@harmonyprotocol) August 12, 2026
Shortly after the initial statement, Harmony paused its bridge and then released a patch within minutes, instructing validators to upgrade to a version that prevents any further minting. Addressing the situation regarding the already minted tokens would require a subsequent update, the team stated. This all transpired about five hours after Juiceberg's initial post.
Harmony has not yet disclosed the specific vulnerability exploited, the total number of tokens minted, or how many reached exchanges. Juiceberg also pointed out that Harmony's totalSupply endpoint did not account for the newly minted tokens, with price trackers still listing the circulating supply at around 14.87 billion.
Considering a Chain Rollback
A rollback would revert the network to its state prior to the exploit, effectively eliminating all transactions that occurred afterward. This approach could disadvantage regular users who engaged in transactions after the attack.
This is not the first time Harmony has faced such challenges; in June 2022, hackers stole approximately $100 million from its Horizon cross-chain bridge, an incident later linked by the FBI to North Korea's Lazarus Group.
Following the 2022 hack, Harmony initially proposed to reimburse victims in ONE tokens, which would have necessitated minting billions more tokens and executing a hard fork. The plan faced significant backlash, leading the team to revise it to a solution funded from its treasury. Four years later, a similar amount of tokens has been minted without authorization.
The current market capitalization of ONE stands at approximately $11.5 million, placing it outside the top 1,000 tokens. It is now trading significantly lower than its peak price of $0.38 reached in October 2021, representing a decline of over 99% from that level.
