Harmony's ONE token dropped about 26% in Asian morning hours on Wednesday after an apparent exploit created roughly 4 billion new tokens, equal to more than a quarter of the token's existing ~15 billion supply. The Harmony team confirmed the incident in an X post, said it is working with exchanges to freeze the funds, and is preparing a software patch alongside possible rollback options.
Why it matters
This is Harmony's third major security incident in under three years. In 2022, attackers stole about $100 million from its Horizon bridge, a theft the FBI later attributed to North Korea's Lazarus Group. In December 2023, a bug in its staking system improperly minted around 146.3 million ONE across 74 addresses, with one wallet receiving 51.2 million and roughly 16.4 million subsequently moved to an exchange. Harmony contained that episode with an emergency patch and an address blacklist. The current 4 billion figure is roughly 27 times larger than the 2023 episode and lands on the base layer itself, not a bridge.
A rollback would return the network to a state before the exploit, effectively erasing the inflated tokens and any transactions that followed on-chain. The mechanism can prevent the attacker from keeping the new tokens, but the longer the funds sit on bridges, DEXs, or centralized exchanges, the harder a clean rollback becomes. Harmony has not yet explained the underlying vulnerability, how the 4 billion figure was calculated, or how far back any proposed rollback would extend.
Market impact
The 26% drop followed a familiar pre-dawn Asian-session pattern for low-cap L1 tokens on confirmation of an exploit. The rollback question is the bigger structural issue: undoing an attack also risks undoing legitimate transactions made after it, the same trade-off Ravencoin navigated a day earlier when miners moved to rebuild its chain from before invalid blocks were accepted. The next 24 hours will determine whether major exchanges freeze the freshly minted ONE and where Harmony sets the rollback depth, decisions that will set the precedent for the next base-layer inflation incident.
Frequently asked questions
-
How many tokens did the Harmony exploit mint?
The apparent exploit created roughly 4 billion new ONE tokens, equal to about 26% of the chain's existing ~15 billion supply at the time of the incident.
-
What is Harmony doing in response to the exploit?
The Harmony team confirmed the incident in an X post, said it is working with exchanges to freeze the funds, and is preparing a software patch alongside possible rollback options.
-
What is a blockchain rollback and how does it work?
A rollback returns the network to a state before the exploit, effectively erasing the inflated tokens and any transactions that followed on-chain. It can prevent the attacker from keeping the new tokens, but becomes harder once funds have moved to bridges or exchanges.
-
Has Harmony been hacked before?
Yes. In 2022, attackers stole about $100 million from Harmony's Horizon bridge, a theft the FBI later attributed to North Korea's Lazarus Group. In December 2023, a staking bug improperly minted about 146.3 million ONE across 74 addresses, which the network contained with an emergency patch and address blacklist.
-
How does the Harmony exploit compare to Ravencoin's recent issue?
Both incidents involve the rollback trade-off. A day before Harmony's exploit, Ravencoin's miners moved to rebuild its chain from before invalid blocks were accepted, putting several days of transactions at risk of reversal. Undoing an attack can also undo legitimate transactions made after it.
CoinDesk