NewsCryptoHarmony Confirms Critical Exploit After 4 Billion ONE Are Minted Without Authorization

Harmony Confirms Critical Exploit After 4 Billion ONE Are Minted Without Authorization

Author: Metaverse Post·

Key Takeaways

  • Approximately 4 billion ONE tokens were minted without authorization, representing roughly 26% of the token's pre-existing supply.
  • The attacker moved about 97% of the illicitly minted tokens to centralized exchanges, where they have either been sold or remain in deposit wallets.
  • Harmony's ONE token dropped approximately 40% to near $0.0008, giving the unauthorized tokens a nominal value of roughly $3.2 million.
  • This exploit is Harmony's third major security incident in recent years, following a December 2023 staking bug and the 2022 Horizon Bridge attack that drained about $100 million.
  • On-chain investigator ZachXBT declined to assist with recovery, citing Harmony's failure to compensate those who helped during the 2022 bridge exploit.
Harmony Confirms Critical Exploit After 4 Billion ONE Are Minted Without Authorization

Harmony, a Layer 1 blockchain, has confirmed a critical exploit in which approximately 4 billion ONE tokens were minted without authorization through empty blocks, equal to roughly 26% of the token's pre-existing supply. Unauthorized minting exploits are particularly damaging for Layer 1 networks because they directly dilute the token supply and undermine confidence in consensus-level monetary policy, as opposed to bridge or wallet hacks that transfer existing tokens.

On-chain analyst Juiceberg reported that the attacker quickly moved about 2.8 billion ONE to centralized exchanges as the token price dropped sharply. According to Juiceberg, the attacker still holds only about 115 million ONE on-chain, or roughly 2.9% of the illicit supply, while “the overwhelming majority, approximately 97%, is already on exchanges and has either been sold or is sitting in deposit wallets ready to sell.”

“We are working with our team and appropriate exchanges to stop and freeze the funds. We are working on a patch and rollback options. Will update when we have new information. — Harmony (@harmonyprotocol) August 12, 2026

The market reaction was immediate. ONE fell about 40% to trade near $0.0008, putting the nominal value of the unauthorized tokens at roughly $3.2 million. Compounding concerns about transparency, Harmony's totalSupply endpoint did not immediately reflect the inflation, which may have obscured the dilution for users and monitoring systems.

In response, Harmony told validators to install an emergency patch that would prevent further minting, paused its token bridge, and published four wallet addresses tied to the incident, asking exchanges to freeze the associated funds. The network said it is developing a comprehensive patch and evaluating rollback options. Whether major exchanges will cooperate with freeze requests, and whether enough validators will adopt the patch promptly to halt further minting, will be critical signals to watch in the coming hours.

ZachXBT Refuses to Assist as Recovery Efforts Continue

The incident has renewed scrutiny of Harmony's previous security failures and its relationship with the investigator community. On-chain investigator ZachXBT publicly refused to help with the current case, saying: “I will not be tracking this incident and think no one should assist them for free.”

“I will not be tracking this incident and think no one should assist them for free. Harmony took advantage of people who assisted during the $100M Harmony Bridge exploit by DPRK in 2022 and rewarded $0 for significant freezes which lead to LE seizures and simply said 'good job'” — ZachXBT (@zachxbt) August 12, 2026

He pointed to Harmony's handling of the 2022 Horizon Bridge exploit, which the FBI attributed to North Korea's Lazarus Group. ZachXBT said Harmony allegedly “took advantage of people who assisted” and “rewarded $0 for significant freezes which lead to LE seizures and simply said 'good job.'”

The boycott highlights a growing trust gap as Harmony considers a blockchain rollback, which would restore the network to a pre-exploit state but erase later transactions, a step widely seen as contrary to blockchain immutability. Rollbacks remain contentious in the crypto industry — the most notable precedent is Ethereum's response to the 2016 DAO hack, which resulted in a chain split and the creation of Ethereum Classic. The recovery effort is further complicated by the fact that most of the funds have already reached exchanges.

The exploit is Harmony's third major security failure in recent years, following a December 2023 staking bug that created 146.3 million ONE and the 2022 bridge attack that drained about $100 million. The pattern of repeated incidents raises broader questions about audit rigor and post-incident remediation at smaller Layer 1 projects, where limited resources can constrain both security testing and bug bounty programs. Harmony has not yet disclosed the technical root cause of the latest breach.