Harmony's ONE Token Drops 40% After Exploit Mints Approximately 4 Billion Tokens
Key Takeaways
- •Harmony's ONE token lost approximately 40% of its value after an exploit reportedly created around 4 billion new tokens, representing a sudden 26% increase in total supply.
- •Harmony issued an emergency software update for validators that stops additional unauthorized minting but does not address the tokens already created.
- •The project temporarily halted its token bridge and asked centralized exchanges to freeze funds tied to four wallet addresses associated with the attack.
- •Harmony has not publicly identified the vulnerability, explained how the attacker obtained minting authority, or officially confirmed the total number of tokens minted.
- •Harmony is considering a blockchain rollback to undo the exploit, an approach that could also reverse legitimate transactions and remains contentious within the cryptocurrency industry.

Harmony's ONE token fell roughly 40% on Wednesday after an apparent exploit reportedly created around 4 billion new tokens, sending traders into a sharp sell-off as the project scrambled to contain the damage.
Harmony confirmed the attack and instructed the network operators responsible for maintaining the blockchain to install an emergency software update. The project stated that the patch would prevent the attacker from minting additional ONE tokens. However, the update does not address the status of the tokens already created. Harmony said it is still evaluating how to isolate or remove those assets from circulation.
The scale of the incident triggered intense selling pressure as market participants assessed the risks of token dilution, exchange deposits, and a potential reversal of blockchain transactions.
Unauthorized Issuance Equals 26% of ONE Supply
Approximately 15 billion ONE tokens existed before the exploit. The creation of an additional 4 billion represents a sudden supply increase of roughly 26%, which can severely dilute existing holders. If the attacker successfully transfers the newly created tokens to exchanges and sells them, the additional circulating supply could place further downward pressure on ONE's price.
Harmony has not officially confirmed the total number of tokens minted or explained how the reported 4 billion figure was calculated. The network was once among the cryptocurrency industry's largest projects, reaching a market capitalization of approximately $4 billion in January 2022. The incident underscores the elevated risks that proof-of-stake networks face when minting authority is compromised, as a single attacker with sufficient access can expand supply far more rapidly than typical governance or monetary policy mechanisms allow.
Bridge Paused and Wallet Addresses Flagged
Harmony temporarily paused its token bridge to prevent potentially compromised assets from moving between networks. The project also asked centralized exchanges to block and freeze funds traced to four wallet addresses associated with the incident. By flagging those addresses, Harmony aims to help trading platforms prevent the attacker from converting or withdrawing the newly minted tokens.
Cross-chain bridges have been among the most frequently exploited components in decentralized finance, with multiple high-profile attacks recorded in 2022 affecting networks including the Ronin Network and Wormhole. The pattern has drawn attention to the structural vulnerability of bridge infrastructure, which often holds large pooled asset balances to enable transfers between otherwise incompatible blockchains.
Cooperation from exchanges may limit the damage if the assets remain identifiable. However, recovery becomes significantly more difficult if the tokens are swapped through decentralized exchanges, transferred to other networks, or divided among additional wallets. Blockchain transaction monitoring may still allow investigators to trace some movements, but it cannot guarantee that all unauthorized assets will be recovered.
Coordinated Validator Upgrade Required
Harmony's software update is designed to close the vulnerability and prevent any additional ONE from being created. Network operators must adopt the new software for the patch to take effect across the blockchain. A coordinated upgrade is essential to ensure that validators and other infrastructure providers follow the corrected network rules.
Harmony has not publicly identified the vulnerability, disclosed how the attacker gained minting authority, or confirmed whether any additional parts of the protocol remain at risk. Until the project releases a complete technical explanation, uncertainty may continue to affect ONE and applications operating on the network.
"We are working on a patch and rollback options," Harmony said, promising further updates as its investigation progresses.
A rollback would return the blockchain to a state recorded before the exploit. The network would then resume from that point, removing subsequent transactions from its accepted history. This approach could erase the creation of unauthorized tokens still on Harmony, but it could also reverse legitimate transactions completed after the selected rollback point. Rollbacks remain rare and contentious in the cryptocurrency industry because they conflict with the principle of transaction immutability that underpins public blockchains, and historically they have divided communities over whether altering recorded history is justified even in cases of theft or fraud.
Price Action
ONE lost approximately 40% of its value over the preceding 24 hours. The token briefly dropped to $0.000605 before recovering to trade above $0.00074. Technical indicators showed an RSI reading of 12, placing ONE in oversold territory, while MACD lines aligned with the prevailing bearish trend. If selling pressure persists, ONE could retest the $0.000605 level before approaching the $0.00050 psychological threshold. A recovery in buying interest could see the token move toward the $0.00112 level in the near term.