Markets Harmony's ONE has seen a significant decline of approximately 26% after an attack reportedly generated around 4 billion new tokens, raising the total supply by over 25%.

Harmony is collaborating with exchanges to secure funds and develop a software solution.

In the early hours of Wednesday in Asia, Harmony confirmed that it is addressing the situation by working with exchanges to freeze affected funds and is preparing a software patch.

“We are working on a patch and rollback options,” Harmony stated, noting that further updates will be provided as more details emerge.

As a layer 1 blockchain designed for decentralized finance (DeFi) applications, Harmony utilizes its native token, ONE, for transaction fees and securing the network. Before the incident, the total supply of ONE was around 15 billion, meaning the newly minted tokens represent a sudden increase of about 26%.

A rollback would involve reverting the blockchain to its state prior to the exploit, effectively excluding transactions that occurred afterward. This is akin to reversing a chess move to avoid checkmate, but it complicates matters if the newly minted tokens have already been transferred to exchanges or other systems. Many industry experts argue that such rollbacks contradict the fundamental principle of immutability in blockchain technology.

The timing of this exploit is notable, occurring just a day after Ravencoin, another smaller blockchain, faced a similar issue that could lead to a rollback due to the acceptance of invalid blocks.

Previous Challenges

This is not the first instance of unauthorized token creation for Harmony. In December 2023, a flaw in its staking mechanism resulted in the creation of approximately 146.3 million ONE tokens when certain tokens that should have stopped receiving rewards continued to do so. At that time, Harmony revealed that 74 addresses were implicated, with one address receiving 51.2 million ONE, and around 16.4 million of those tokens were later transferred to an exchange.

In response to that event, Harmony implemented an emergency software update and blacklisted the addresses involved with the improperly created tokens.

Additionally, Harmony was targeted in one of the most significant attacks in the crypto space in 2022, when around $100 million was stolen from its Horizon bridge due to compromised private keys, with the FBI later linking the incident to North Korea's Lazarus Group.

Wednesday's incident appears distinct, as it involves the unauthorized creation of ONE tokens on Harmony itself rather than the theft of assets from a bridge. Harmony has yet to disclose the specifics of the vulnerability, how the 4 billion figure was determined, or the scope of any proposed rollback.

(This story is developing.)

Latest Crypto News