ZachXBT Declines to Assist Harmony as Team Prepares ONE Chain Rollback
Key Takeaways
- •ZachXBT refused to investigate Harmony's latest exploit and urged other researchers to decline unpaid work, citing a lack of compensation for contributors who assisted after the 2022 Horizon Bridge hack.
- •Approximately 4 billion ONE tokens were created without authorization, representing roughly 26% of the token's pre-exploit supply, and around 2.8 billion ONE were subsequently moved toward exchanges.
- •Harmony is requesting that exchanges freeze linked addresses and preparing a network rollback to undo the unauthorized token creation, though assets already deposited on centralized platforms may be difficult to recover.
- •The FBI formally attributed the 2022 Horizon Bridge theft of $100 million to Lazarus Group and APT38, cyber units tied to North Korea.
- •Harmony has not yet published a technical explanation of how the unauthorized mint occurred or confirmed the amount of tokens successfully frozen by exchanges.

Blockchain investigator ZachXBT has refused to assist Harmony with its latest exploit and urged other researchers not to work on the case without compensation, citing the project's handling of outside assistance following its $100 million Horizon Bridge hack in 2022. The stance highlights a broader tension in the crypto sector, where independent on-chain analysts frequently trace stolen funds and coordinate with exchanges and law enforcement — work that can be both time-intensive and legally sensitive — often without formal compensation structures or guaranteed payouts.
The dispute comes as Harmony asks exchanges to freeze addresses linked to the latest exploit and prepares a network rollback, escalating containment efforts after roughly 4 billion ONE were created without authorization. The new tokens represented approximately 26% of ONE's pre-exploit supply, with roughly 2.8 billion ONE subsequently moved toward exchanges. The unauthorized mint and the resulting collapse in ONE's market price emerged earlier Wednesday.
ZachXBT Calls on Researchers to Withhold Unpaid Assistance
ZachXBT stated he would not track the latest Harmony exploit and argued that other investigators should similarly avoid providing unpaid help. He accused Harmony of taking advantage of researchers who assisted in tracing funds after the 2022 Horizon Bridge theft, claiming that substantial freezes were secured without those contributors receiving any compensation. (https://x.com/zachxbt/status/2087429244007940368)
"I will not be tracking this incident and think no one should assist them for free," ZachXBT wrote.
He noted that researchers who contributed to the earlier case received no reward despite work that led to frozen funds and subsequent law-enforcement activity. The compensation claim reflects ZachXBT's account of the earlier response. Harmony has not publicly addressed that allegation in its latest incident updates. (https://x.com/harmonyprotocol/status/2087410115200889135)
2022 Horizon Theft Linked to DPRK Actors
The earlier $100 million Horizon Bridge theft was connected to North Korean actors shortly after the June 2022 breach, when investigators traced stolen Ether through Tornado Cash and other services.
The FBI later formally attributed the theft to Lazarus Group and APT38, cyber units associated with the Democratic People's Republic of Korea. ()
In January 2023, the attackers routed more than $60 million of the stolen ETH through Railgun before sending part of the proceeds to virtual asset service providers and converting them into Bitcoin. Coordination with those platforms resulted in a portion of the funds being frozen.
Harmony initially offered a $1 million bounty following the bridge attack before increasing its recovery offer as attempts to retrieve the stolen assets continued.
Harmony Pursues Exchange Freezes and Chain Rollback
Harmony is now pursuing a more aggressive response to the latest breach. The team has distributed attacker addresses to exchanges and requested freezes while preparing a patch and rollback intended to reverse the unauthorized ONE creation.
A rollback would require the network to revert to a state before the exploit and discard subsequent affected state changes. Rollbacks remain rare and contentious in the blockchain industry, as they can undermine the immutability principle that underpins public networks. The most prominent precedent is Ethereum's 2016 hard fork following the DAO exploit, which ultimately split the chain into Ethereum and Ethereum Classic. Tokens already deposited onto centralized exchanges create an additional recovery challenge, as those assets may have moved beyond Harmony's direct on-chain control.
Harmony has not yet published a technical post-mortem identifying how the roughly 4 billion ONE were created or confirmed how much of the 2.8 billion ONE sent toward exchanges has been frozen. The network's latest public response remains focused on exchange containment, deployment of a patch, and execution of the proposed rollback.