Harmony to Rewind Blockchain After Trillion-ONE Mint Attack
Key Takeaways
- •Harmony will switch validators to replacement databases for shard 0 and shard 1 based on Aug. 11 checkpoints, resuming from later block heights after the rollback.
- •The first confirmed forged mint occurred on shard 0, and Harmony chose the prior block as a buffer because the intervening block had no standard transactions or staking activity.
- •Harmony rejected options such as token burns, wallet blacklisting and selective transaction replay because the forged tokens had already moved through multiple types of crypto infrastructure.
- •The affected shard-0 archive includes 141,628 blocks with more than 109,000 regular transactions, so the rollback will discard legitimate activity and alter balances and contract state.
- •Harmony said the investigation is continuing with exchanges, bridges, law enforcement and an independent security firm, and the network has faced a major exploit before in June 2022.

Harmony, a layer-1 blockchain that processes transactions across parallel shards, has moved from evaluating several recovery options to implementing a specific blockchain rollback after an attacker exploited the network to forge trillions of ONE tokens. The recovery plan will remove the fraudulent state, but it will also eliminate legitimate activity recorded after the selected checkpoints, making the intervention one of the most disruptive responses available to an operating blockchain. Rewinds of this scale are rare on live public networks because they override the transaction finality that blockchains are designed to guarantee; the best-known precedent remains Ethereum's 2016 response to the DAO hack, when a contentious hard fork reversed the stolen funds and the original chain continued on as Ethereum Classic.
In an Aug. 17 incident update, Harmony said validators would switch to replacement databases corresponding to shard 0 block 92,730,034 and shard 1 block 94,978,278. Both checkpoints correspond to Aug. 11 at 23:25:37 UTC. The rollback will remove the forged ONE-token state while also discarding legitimate transactions and other blockchain activity recorded after those checkpoints.
The first confirmed forged mint appeared on shard 0 at block 92,730,036. Harmony selected the preceding block as a safety buffer because the intervening block contained no standard transactions, staking activity, incoming receipts or gas consumption and retained the same state. Although the fraudulent mint did not occur on shard 1, Harmony included a corresponding checkpoint there as a precaution. Once validators move to the replacement databases, new blocks will resume from heights 92,730,035 on shard 0 and 94,978,279 on shard 1.
— Harmony (@harmonyprotocol) August 17, 2026
Selective Recovery Options Rejected
Before deciding on the database replacement, Harmony said it had considered several alternatives, including targeted token burns, blacklisting wallets, migrating affected tokens, selectively replaying transactions and performing a simpler database rewind.
Those approaches were ultimately rejected because the forged ONE had moved across a broad range of cryptocurrency infrastructure. The tokens passed through centralized exchanges, decentralized exchange pools, smart contracts, bridges, staking positions and shared wallets. As a result, selectively removing suspicious balances could affect legitimate users whose assets had become mixed with the forged tokens. Harmony also determined that a partial intervention could leave the blockchain with inconsistent state across different applications and services.
Extensive Token Movement Complicates Recovery
The investigation has identified rapid movement from at least one wallet associated with the forged mint. Harmony said the wallet attempted 534 transfers involving 5 billion ONE each within 106 seconds. Of those transactions, 477 were successful, moving approximately 2.385 trillion ONE — a quantity that far exceeds the network's existing token supply. The company's subsequent flow analysis accounted for nearly all of the forged amount as it moved across different services and incurred transaction fees.
Harmony has emphasized that tracing tokens to a wallet, exchange, liquidity pool or other service does not establish who controlled the assets. Nor does it necessarily make those funds suitable for destruction, because shared wallets and pooled balances may contain assets belonging to unrelated users. The investigation remains ongoing, with Harmony working alongside exchanges, bridges, law enforcement agencies and an independent security firm.
Legitimate Transactions Will Be Lost
The rollback also carries a significant cost for users. The affected shard-0 archive contains 141,628 consecutive blocks, and those blocks include 109,126 regular transactions and 315 staking transactions. Harmony classified 95.8% of the regular transactions as automated, but the remaining activity includes legitimate transactions that cannot be safely reconstructed without risking further inconsistencies.
The replacement chain will alter balances, transaction details, liquidity-pool reserves, token approvals, swap deadlines and staking positions, creating potential complications for users and applications that interacted with the network after the checkpoint. Replaying transactions from the discarded chain could also produce different outcomes. Changes to account balances, contract state or transaction ordering could cause a previously successful transaction to fail, or allow a transaction that previously failed to succeed.
Exchanges and Bridges Face Operational Challenges
The incident highlights the difficulties of restoring a live blockchain after fraudulent state has propagated across interconnected infrastructure. Because the rollback creates a discontinuity between the discarded chain and the replacement databases, exchanges, bridges and other services will need to account for the change when processing deposits, withdrawals and other transactions.
The recovery plan is intended to eliminate the forged state, but its successful execution will depend on coordinated action among validators and ecosystem operators. The incident also underscores the broader operational risks associated with cross-chain systems and decentralized financial infrastructure, where assets can move rapidly across multiple platforms before an attack is detected. Harmony has contended with high-value exploits before: in June 2022, an attacker stole roughly $100 million from the network's Horizon cross-chain bridge.
Harmony's decision therefore represents a trade-off between removing a large-scale fraudulent mint and preserving legitimate activity. The rollback is designed to restore a trustworthy state, but the resulting loss of valid transactions demonstrates the potentially far-reaching consequences of recovering a blockchain after an exploit has already spread through its ecosystem.