An attacker minted roughly 4 billion ONE tokens on the Harmony blockchain early Wednesday, adding about 26% to a supply that had stood near 15 billion, and drove the token to an all-time low of $0.0005735 during Asian trading hours. Harmony confirmed the exploit in a statement on X, said it is coordinating with exchanges to freeze the funds, and told holders it is preparing a software patch while it evaluates rolling back the network.
Minting is the creation of new units of a cryptocurrency and their addition to the circulating supply, an action normally restricted by rules written into a blockchain’s code. In this case those rules failed.
On-chain analyst Juiceberg, who first flagged the mint, reported that the tokens were produced through empty blocks and that roughly 2.8 billion of them had already reached exchanges. ONE traded near $0.0008 later in the session, down between 26% and 34% on the day depending on the venue, valuing the minted supply at roughly $3.2 million at current prices, according to CoinDesk.
Key takeaways
- An attacker minted about 4 billion ONE on Harmony, equal to roughly 26% of the token’s pre-incident supply of around 15 billion.
- ONE hit a record low of $0.0005735 and traded near $0.0008 later in the session, putting the minted supply at about $3.2 million.
- Roughly 2.8 billion of the tokens moved to exchanges before Harmony asked for a freeze, leaving about 115 million ONE, or 2.9% of the mint, still on-chain.
- Harmony has named four attacker wallets, is preparing a patch, and is weighing a rollback. It has not disclosed the root cause.
Published: August 12, 2026 10:15 UTC
What Harmony has confirmed so far
Harmony acknowledged the incident directly in reply to the on-chain report, without describing the vulnerability that allowed it. “We are working with our team and appropriate exchanges to stop and freeze the funds,” the team wrote. “We are working on a patch and rollback options. Will update when we have new information.”
The team later published four wallet addresses tied to the mint and asked every exchange to block deposits and freeze balances traced to them. That request is the only real recovery mechanism left. Juiceberg put the on-chain remainder at about 115 million ONE, or 2.9% of the roughly 4 billion created, with the rest already sold or sitting in exchange deposit wallets.
Harmony launched its mainnet in 2019 as a proof-of-stake network pitched as a faster and cheaper alternative to Ethereum, with ONE covering transaction fees, staking, and governance. Neither The Block nor BeInCrypto had a technical explanation from the team at the time of publication.

Why the rollback question is the hard part
A rollback returns a blockchain to a state recorded before a chosen block and continues from there, erasing every transaction made after that point from the accepted history. It is the bluntest tool a network has, and it works best in the first hours after an attack.
Harmony has largely missed that window. A rollback can strip an attacker of tokens still sitting on the chain, but it cannot claw back coins already sold into exchange order books to buyers who did nothing wrong. With about 97% of the mint off Harmony by the time the team responded, the recoverable share is small and the collateral damage would not be.
Ravencoin faced the same decision on Tuesday after parts of its network accepted invalid blocks, putting four days of transactions at risk of reversal. Both cases pose one trade-off: undoing an attack also undoes everything honest users did afterward, which cuts against the immutability that gives a public blockchain its value.
Harmony has produced unauthorized ONE before
This is the third serious security failure in Harmony’s history and the second involving tokens that should never have existed.
In December 2023, a bug in the staking system created about 146.3 million ONE by continuing to pay rewards to positions that should have stopped receiving them. Harmony said 74 addresses were involved, one of which received 51.2 million ONE, and that roughly 16.4 million was moved to an exchange. The network shipped an emergency update and blacklisted the addresses holding the improperly created tokens.
The larger incident came in June 2022, when attackers compromised the private keys controlling Harmony’s Horizon cross-chain bridge and took close to $99.6 million in Ethereum and stablecoins. The FBI attributed that theft to North Korea’s Lazarus Group and APT38 in January 2023. Wednesday’s exploit differs in kind: the loss came from creating ONE on Harmony itself rather than draining a bridge, so the damage lands on every existing holder through dilution instead of on one pool of locked funds.
What happens next for ONE holders
Three things determine how this ends. Whether exchanges freeze the flagged deposits fast enough to matter, whether the patch closes the minting path without a chain halt, and whether Harmony publishes a root cause credible enough to keep validators and listing venues on board.
The supply question outlasts all of them. Unless a rollback succeeds or the extra tokens are burned, ONE holders are diluted by about a quarter permanently, and that arithmetic sits underneath any price recovery.
The incident lands during a bad stretch for on-chain security. A Coreum bridge serving XRP was drained for $200,000 the same day, following the $8 million Coinsbuy hack and the BTCPay flaw that drained Lightning nodes earlier this month. Bitcoin traded near $63,700 on Wednesday as markets waited on the US CPI print, leaving little appetite for risk in small-cap tokens carrying fresh security questions.
Frequently asked questions
How much is the Harmony exploit worth?
About $3.2 million at current prices. The attacker minted roughly 4 billion ONE, but the token fell to a record low as those coins hit exchanges, so the realized proceeds are likely lower than the headline figure suggests. Harmony has not published a confirmed loss estimate.
Can Harmony reverse the unauthorized mint?
Only partially. A rollback could remove tokens still held on Harmony, which is about 115 million ONE, or 2.9% of the mint. The other 97% already moved to exchanges, where a rollback has no effect. Recovery there depends on exchanges freezing the flagged deposits.
Is this related to the 2022 Harmony bridge hack?
There is no indication that it is. The 2022 attack drained close to $99.6 million from the Horizon bridge through compromised private keys and was attributed by the FBI to North Korea’s Lazarus Group. Wednesday’s incident involves minting new ONE on Harmony itself, a different attack surface.








