Harmony Faces Major ONE Token Exploit as Billions of Unauthorized Tokens Minted
Key Takeaways
- •Approximately 4 billion ONE tokens were minted without authorization, representing roughly 26% of Harmony's previously visible circulating supply of around 15 billion ONE.
- •The price of ONE declined by more than 30% following the exploit, with trading volume surging by thousands of percent as investors rushed to exit positions.
- •Around 2.8 billion of the allegedly unauthorized ONE tokens were transferred toward cryptocurrency exchanges, while approximately 115 million remained on-chain according to on-chain researcher Juiceberg.
- •Harmony has asked validators to install an emergency patch to prevent further unauthorized minting and is coordinating with centralized exchanges to freeze funds tied to the exploit.
- •Harmony is evaluating a potential blockchain rollback to invalidate the unauthorized tokens, though such a decision could also reverse legitimate transactions recorded during the same period.

Harmony is confronting a significant security crisis following an apparent exploit that resulted in the unauthorized creation of billions of ONE tokens, triggering a sharp sell-off and raising urgent questions about the network's security and the integrity of its native cryptocurrency's supply.
On-chain data cited by crypto researcher Juiceberg indicates that approximately 4 billion ONE tokens were minted without authorization—a figure representing roughly 26% of the token supply previously visible in the market and creating an extraordinary supply shock for existing holders.
The incident sent ONE sharply lower as traders reacted to the possibility that billions of newly created tokens could be sold into circulation. Reports indicated that approximately 2.8 billion ONE had already been moved toward cryptocurrency exchanges, while a much smaller amount remained on-chain.
Harmony has acknowledged the incident and said it is coordinating with exchanges to stop and freeze funds associated with the affected wallets. The project is also developing a technical patch and evaluating a possible rollback of the blockchain. The situation remains developing, and some figures circulating in the market originate from on-chain researchers rather than a complete post-mortem from Harmony.
The Coin Bureau account on X has also highlighted the incident, bringing additional attention to the rapidly evolving security event.
Sharp Price Decline and Surging Trading Volume
The immediate market reaction was severe. ONE fell by more than 30% as news of the unauthorized mint spread. At one point, market data showed the token down by more than 38% over a 24-hour period, with trading volume increasing by thousands of percent as investors rushed to reassess their positions.
Before the incident, Harmony's publicly tracked supply was around 15 billion ONE. The alleged creation of approximately 4 billion additional tokens therefore represents a substantial increase relative to the existing supply.
Such a spike in trading activity is typical of a market experiencing a major information shock. Some investors sold out of fear of additional losses, while others attempted to trade the extreme volatility. Market makers also adjusted liquidity amid uncertainty surrounding the token's supply. In incidents like this, the central issue is not only price movement but whether the market can still rely on the token count it sees.
Billions of ONE Reportedly Sent Toward Exchanges
Juiceberg's on-chain analysis indicated that approximately 2.8 billion ONE had been transferred toward exchanges after the exploit, creating a significant potential source of selling pressure. Tokens transferred to exchange-associated wallets can potentially be sold or used for other transactions, depending on the exchange's response and whether the funds are frozen.
Harmony has said it is working with relevant exchanges to stop and freeze funds connected to the affected wallets. The project has published wallet addresses associated with the incident and asked exchanges to block funds traceable to them. If exchanges can identify and freeze the majority of the remaining tokens before they are sold, some of the potential selling pressure could be contained.
Juiceberg later reported that approximately 115 million ONE remained on-chain and potentially available for further selling. If accurate, that would mean most of the alleged newly minted tokens had already been sold or were sitting in exchange wallets. However, an exchange deposit does not automatically mean a token has been sold—the assets may remain untouched, may be frozen by the platform, or could be transferred elsewhere.
Harmony Confirms Security Incident
Harmony has confirmed that an incident occurred and said its team is working to contain the damage. The project's response includes:
- Coordination with exchanges to freeze affected funds
- Development of a technical patch to prevent additional unauthorized minting
- A request for validators to upgrade to the patch
- Temporary suspension of its bridge service during the investigation
- Consideration of a possible blockchain rollback
These measures indicate that Harmony is treating the event as a network-level security emergency. The immediate priority is to stop the vulnerability from being exploited again before developers can fully address the newly created tokens. For a blockchain project, that also means restoring confidence in the chain's rules as much as containing the immediate funds flow.
Supply Integrity at the Center of the Crisis
The most critical issue raised by the exploit is supply integrity. A cryptocurrency's monetary policy depends on the assumption that tokens cannot be created outside the rules established by the protocol. The reported 4 billion ONE mint is particularly significant because of its size—a sudden increase of roughly 26% is dramatically different from normal token emissions associated with staking rewards or scheduled network incentives.
Juiceberg also alleged that Harmony's totalSupply endpoint did not immediately reflect the additional tokens. If confirmed, that could make it difficult for market participants to accurately determine the real circulating supply during the incident, potentially leading to misleading market-cap calculations. In practice, that kind of mismatch is one reason supply-related exploits can become especially disruptive: traders, exchanges, and data providers may all be trying to interpret the same asset under incomplete information.
The Rollback Question
A rollback is one of the most consequential options available to a blockchain team. In simple terms, a rollback attempts to return the network to an earlier state before problematic transactions or blocks were recorded. However, such a decision is extremely complicated because it can affect legitimate transactions that occurred during the same period—users who bought, sold, or transferred ONE normally could potentially see those transactions reversed.
Harmony has described a rollback as an option under consideration rather than a confirmed decision. The project must balance the desire to eliminate unauthorized activity against the need to preserve confidence in the blockchain's transaction history.
The fate of the 4 billion allegedly unauthorized ONE tokens remains one of the biggest unanswered questions. Harmony could attempt to invalidate the affected tokens through a rollback or protocol-level intervention. Alternatively, tokens that have already been sold may be impossible to recover in full, leaving the market to absorb the economic consequences. A successful rollback might remove much of the unauthorized supply but could raise questions about transaction finality, while allowing the tokens to remain could preserve blockchain history but create permanent dilution.
Historical Context: The 2022 Horizon Bridge Hack
The latest event arrives with Harmony's previous history of security problems still relevant to the project's reputation. In June 2022, attackers stole approximately $100 million from Harmony's Horizon Bridge—one of the most significant hacks in the history of cross-chain infrastructure.
Harmony subsequently developed reimbursement proposals for affected users, including plans involving the minting of additional ONE tokens over an extended period. One proposal discussed minting approximately 4.97 billion ONE for a 100% reimbursement scenario. However, the two incidents are technically different: the Horizon attack involved the cross-chain bridge, while the current incident concerns an alleged unauthorized mint of ONE on Harmony's own network.
Harmony has spent years attempting to rebuild confidence after the Horizon bridge attack. Another major supply-related security incident creates an additional challenge for the network and its community.
The Role of Centralized Exchanges
Centralized exchanges may play a major role in containing the incident. Once tokens associated with an exploit reach an exchange, the platform can potentially freeze the funds, flag the addresses, and prevent withdrawals or sales. However, this does not guarantee recovery. Exchanges must first identify the affected assets and determine whether they can be connected to the exploit. Blockchain transactions are public, but tracing funds across multiple wallets and platforms can become complicated, as attackers can split funds across addresses, move them between chains, or attempt to convert them into other assets.
Harmony's decision to publish affected wallet addresses reflects the importance of that coordination. The faster exchanges receive reliable wallet information, the greater the possibility of preventing additional sales.
Validators Asked to Complete Emergency Upgrade
Harmony has reportedly instructed validators to install a patch designed to prevent additional unauthorized minting. Validators play a critical role in maintaining the network and confirming its state, making a coordinated software upgrade an essential part of containing a protocol-level exploit. The challenge is ensuring that validators upgrade correctly and that the fix does not introduce additional problems. In a crisis, developers must move quickly without sacrificing the testing and verification normally required for a major network change.
Ongoing Uncertainty
For holders of ONE, several important variables remain unresolved: the exact exploit mechanism has not yet been fully explained; the final amount of unauthorized tokens may still be under investigation; the amount already sold remains uncertain; exchange freezes may prevent some funds from moving; and Harmony has not confirmed whether a rollback will ultimately take place.
The most reliable developments will come from Harmony, affected exchanges, and independent blockchain-security investigators. On-chain researchers can provide valuable information, but preliminary figures can change as investigators trace additional transactions.
What Comes Next
Several developments are likely to dominate the next phase of the story:
- Investigators will seek to identify the precise vulnerability that enabled the unauthorized mint
- Exchanges will determine how much of the affected supply can be frozen
- Harmony will need to clarify the actual amount of ONE created
- Validators will need to complete the emergency upgrade
- The community will evaluate whether a rollback is appropriate
The market will also watch whether additional unauthorized tokens appear after the patch is deployed. If the vulnerability is successfully closed, attention will shift toward recovery. If new minting continues, the crisis could become significantly more severe.
The reported 4 billion ONE exploit represents one of the most serious challenges Harmony has faced since the Horizon bridge attack. The final impact will depend on how much of the unauthorized supply can be contained, whether the network can successfully eliminate the vulnerability, and what decision Harmony makes regarding the blockchain's history. The incident is also likely to reignite broader discussions about blockchain security, token supply controls, and the risks associated with highly complex decentralized infrastructure.
Source: Hoka News