Harmony Hit by Alleged 4B ONE Mint; 2.8B Tokens Reportedly Sent to Exchanges
Key Takeaways
- •On-chain analyst Juiceberg reported that an attacker minted approximately 4 billion ONE tokens through empty blocks, an amount equal to about 26% of Harmony's total supply.
- •Around 2.8 billion of the purportedly minted tokens are believed to have been sent directly to cryptocurrency exchanges, while roughly 115 million ONE remain on-chain in the attacker's possession.
- •Harmony is coordinating with exchanges to freeze affected funds, developing a patch, and evaluating rollback options, but it has not confirmed the reported mint count or whether a rollback will be executed.
- •The reported supply increase has placed ONE under immediate selling pressure and could severely dilute existing holders if the newly created tokens are sold into the market.
- •The incident follows Harmony's June 2022 Horizon Bridge exploit, in which approximately $100 million in cryptocurrency was stolen and later attributed by the FBI to North Korea's Lazarus Group.

Harmony is responding to a suspected exploit that allegedly triggered the unauthorized creation of billions of ONE tokens. The team says it is coordinating with exchanges to freeze affected funds while it assesses the technical options available to contain the incident. ONE is the native token of the Harmony network, a layer-1 blockchain that launched its mainnet in 2019 and runs on a proof-of-stake consensus model; ONE is used to pay for transactions and to stake with validators.
In a post on X, the project wrote:
We are working with our team and appropriate exchanges to stop and freeze the funds. We are working on a patch and rollback options. Will update when we have new information.
— Harmony 💙 (@harmonyprotocol) August 12, 2026
Nearly 4B ONE Allegedly Created
On-chain analyst Juiceberg reported that an attacker minted roughly 4 billion ONE tokens through empty blocks, an amount equal to about 26% of Harmony's total supply (post on X).
Harmony has not independently endorsed or commented on the stated mint count, and it has not published an account of how the suspected exploit came about. Its public response, however, indicates that the team is treating the situation as a live security incident.
The reported supply increase is significant in scale because it could produce severe dilution for existing ONE holders if the newly created tokens are sold into the market.
Juiceberg additionally claimed that the total supply endpoint on the network did not immediately account for the purported inflation, potentially obscuring the supply changes in routine data queries.
2.8B ONE Reportedly Reached Exchanges
Based on the same on-chain analysis, 2.8 billion of the purportedly minted tokens are believed to have been sent directly to cryptocurrency exchanges.
Juiceberg estimated that roughly 115 million ONE — about 2.9% of the nearly 4 billion tokens said to have been created — remain on-chain in the attacker's possession. The rest of the tokens were either sold or moved to exchange deposit wallets, where they could also be sold.
ONE Faces Heavy Selling Pressure
Following the alleged exploit, the market price of ONE came under immediate pressure. If the tokens are sent to market en masse, potential sell-side liquidity would increase sharply, which represents a distinct risk to holders.
Neither Harmony nor an independent party has confirmed how much of the supply has been sold, and that amount remains unclear.
Harmony Prepares Patch and Considers Rollback
Harmony stated that it is in contact with its team and with exchanges to halt and freeze the funds connected to the incident. The project also has a patch under development and is evaluating rollback options.
If a rollback were carried out, Harmony could reverse or remove transactions tied to the suspected exploit — a step that would require coordination between the network and the platforms involved. Harmony has not confirmed whether a rollback will in fact be executed, and the team said it would share updates when new information becomes available. Network-level reversals of this kind are rare and have historically been contentious; after the 2016 DAO hack, Ethereum's decision to hard-fork its chain to reverse stolen funds split the network and produced Ethereum Classic.
The incident adds to Harmony's record of security issues. The project's Horizon Bridge, a cross-chain bridge linking Harmony to other networks, was exploited in June 2022, with the attacker taking approximately $100 million in cryptocurrency. The FBI subsequently attributed that attack to North Korea's Lazarus Group.
For now, the emphasis is on containing the alleged 4 billion ONE inflation, restricting the movement of potentially affected funds, and determining how the network should be restored.