NewsCryptoHarmony's ONE Plunges 37% After Attacker Mints 4 Billion Tokens

Harmony's ONE Plunges 37% After Attacker Mints 4 Billion Tokens

Author: Decrypt·

Key Takeaways

  • An attacker exploited Harmony's network to mint approximately 4 billion ONE tokens without authorization, representing roughly 26% of the total supply.
  • The unauthorized minting caused ONE's price to decline 37% to approximately $0.00077, with about 97% of the minted tokens sent to exchanges.
  • Harmony released an emergency patch and paused its bridge to prevent further minting, while also considering a rollback to restore the network to its pre-exploit state.
  • Harmony has not disclosed the nature of the vulnerability or confirmed the exact number of tokens created, and the totalSupply endpoint did not reflect the newly minted tokens.
  • This is Harmony's second major exploit, following a June 2022 attack on its Horizon bridge that resulted in roughly $100 million in losses attributed to North Korea's Lazarus Group.
Harmony's ONE Plunges 37% After Attacker Mints 4 Billion Tokens

Layer-1 blockchain Harmony has confirmed that an attacker exploited its network to mint roughly 4 billion ONE tokens without authorization, approximately 26% of the total supply. The unauthorized minting drove the token's price down 37% to about $0.00077, according to CoinGecko data. Unauthorized minting attacks are particularly damaging because they dilute existing holders' stakes at the attacker's direction, inflating supply without any corresponding demand.

On-chain analyst Juiceberg first flagged the exploit early Wednesday, estimating the mint at close to 4 billion tokens created through empty blocks — blocks validated without containing legitimate user transactions. Around 2.8 billion of those tokens were funneled onto exchanges as the price declined.

In a follow-up post, Juiceberg reported that the attacker retained approximately 115 million ONE to sell on-chain, about 2.9% of the total minted. "The overwhelming majority (~97%) is already on exchanges," Juiceberg wrote, noting that those tokens had either been sold or were sitting in deposit wallets.

Harmony responded on social media, stating it was "working with our team and appropriate exchanges to stop and freeze the funds." The project added that it was preparing a patch and weighing rollback options. In a second post, Harmony named four wallets — each listed in both Harmony and hex formats — and asked exchanges to block anything traced to them.

We are working with our team and appropriate exchanges to stop and freeze the funds. We are working on a patch and rollback options. Will update when we have new information. — Harmony 💙 (@harmonyprotocol) August 12, 2026

Just over two hours after its initial statement, Harmony paused its bridge and released a patch within a minute, instructing validators to upgrade to a build that it said prevents any further minting. On proof-of-stake networks like Harmony, deploying a fix depends on sufficient validators coordinating the upgrade in time to be effective. Addressing the tokens already created would require another update, the team noted. By that point, five hours had elapsed since Juiceberg's first report.

The project has not disclosed the nature of the vulnerability, confirmed the exact number of tokens created, or stated how much reached exchanges. Juiceberg also noted an anomaly: Harmony's totalSupply endpoint did not reflect the newly minted tokens, and price trackers continued to list circulating supply at approximately 14.87 billion.

Rollback Considerations

A rollback would restore the network to its state prior to the exploit, erasing subsequent transactions from the accepted history. This approach carries trade-offs, as transactions made by legitimate users after the attack would also be wiped out. Rollbacks remain contentious in the crypto industry: proponents argue they protect users from catastrophic exploits, while critics contend they undermine the immutability that blockchains are meant to guarantee.

Harmony has experienced a major exploit before. In June 2022, hackers drained roughly $100 million from its Horizon cross-chain bridge in an attack that the FBI later attributed to North Korea's Lazarus Group. The project's initial recovery proposal involved reimbursing victims in ONE tokens, which would have required minting billions of new tokens and hard-forking the chain. That plan drew sufficient criticism that the team replaced it with an alternative funded from its treasury.

ONE currently holds a market capitalization of approximately $11.5 million, placing it outside the top 1,000 tokens by that metric. The token last traded near its October 2021 all-time high of $0.38 and is now down more than 99% from that level.