Skip to main content
boxmining
Menu

What Happened to Harmony ONE? Inside the 4 Billion Token Exploit

Michael GuMichael Gu
13 min read
News
A signed cross-shard receipt looping through a cracked checkpoint and multiplying into a flood of Harmony ONE tokens headed toward exchange vaults
Contents

Live incident: This article was last checked at 07:53 UTC on August 12, 2026. Harmony has shipped a validator patch, paused its bridge and said it is considering how to handle tokens already created. It has not yet published a full postmortem or confirmed a final rollback plan.

Harmony ONE did not disappear in one dramatic collapse. It faded in stages.

The sharded blockchain was once one of the busiest alternative Layer 1 networks. Its ONE token reached $0.379 in October 2021. Harmony’s own records put peak DeFi value at about $1.41 billion. DeFi Kingdoms made the chain feel alive, while Aave, SushiSwap and Curve gave it the sort of ecosystem that every Ethereum competitor wanted in that cycle.

Then a $100 million bridge theft in June 2022 broke the backing of assets across Harmony DeFi. A recovery dragged on for years. A separate staking bug created 146.28 million ONE in 2023. By August 2026, DefiLlama measured only about $176,000 of DeFi TVL on the chain.

On August 12, the remaining story got worse. Onchain researcher Juiceberg reported that an attacker had created roughly 4 billion ONE without authorization, equal to about 26% of the previously reported supply. Juiceberg estimated that 2.8 billion ONE moved quickly toward exchanges. Harmony acknowledged the incident, asked exchanges to freeze funds, paused its bridge and released an emergency validator update.

This was not a repeat of the 2022 bridge key theft. The new exploit appears to reach into Harmony’s native cross-shard accounting and old consensus verification code. The patch tells us how the doors were left open. It does not yet tell us who walked through them, exactly when the exploit began, how much was sold or whether the chain can reverse the damage without splitting its community.

What happened on August 12, 2026

The first widely circulated alert came from Juiceberg at 01:42 UTC. The account said onchain data showed an unauthorized mint of about 4 billion ONE through empty blocks, followed by rapid transfers toward centralized exchanges. A later update estimated that only about 115 million ONE remained in attacker-controlled onchain wallets, while most of the rest had either been sold or sat in exchange deposit wallets.

Those movement figures remain the researcher’s estimates, not a completed exchange reconciliation. The numbers also changed as funds moved. They should not be read as proof that every token sent to an exchange was sold.

Harmony’s first public response came at 04:26 UTC. The team said it was working with exchanges to stop and freeze the funds, and that it was preparing a patch while reviewing rollback options. Harmony later published four wallet addresses that it asked exchanges to block:

  • 0xe7427699427821230177dd13f460d6ce43014510
  • 0xf722f7f6afffe8e0dda7b4a97b2c64bb6408efe5
  • 0xed2fc1bfc2a316c15c71a0ace3ad20cb73bb08eb
  • 0xbd357b1b7cebf824b1fe4f1f5c71ac58ff1a70ba

At 06:39 UTC, Harmony said it had paused bridge.harmony.one. One minute later, it instructed validators to install mainnet release v2026.1.1, saying the patch would prevent further minting. The team promised another update for tokens already created.

The market response was immediate. CoinGecko recorded a 24-hour low of $0.0005735, a new all-time low, and showed ONE down about 37% over 24 hours when we checked. The token was roughly 99.8% below its 2021 peak. Prices were moving quickly during the incident, so those figures are a timestamp, not a stable quote.

How the exploit appears to have worked

Harmony has not published a complete incident report. Its emergency code is more informative than its first social posts.

Pull request #5101, merged into v2026.1.1, fixes two flaws. Together they describe a credible path for accepting an old cross-shard receipt and crediting its destination more than once. That is an inference from the patch, not yet Harmony’s final account of the attack.

The signature check could accept no signers

Harmony uses committees of validators and BLS signatures to confirm blocks. Older, pre-staking epochs used a different quorum verifier from the current staking system.

In that legacy path, the verifier was supposed to count how many validator keys were enabled in a signature bitmap. Instead, it counted the total number of public keys attached to the mask. The distinction is brutal.

A bitmap with every signer switched off could still be treated as having enough participation because the code counted the committee list, not the enabled signers. The patch notes say an all-zero bitmap paired with an all-zero identity aggregate signature could therefore satisfy quorum for a pre-staking committee.

The fix now rejects a missing mask and counts only bits that are actually enabled. New regression tests cover zero signers, too few signers and the exact threshold.

A spent receipt could look new again

Harmony moves value between shards with cross-shard receipts. When a source shard creates a receipt and the destination shard applies it, the system must mark that receipt as spent. Otherwise the same message could be presented again for another credit.

For older proofs, Harmony generated the spent-marker key from ShardID and BlockNum fields inside a Merkle proof. The patch says those fields were not cryptographically bound to the signed block header for those epochs.

An attacker could keep a genuine signed header but change the unprotected shard or block identity in the accompanying Merkle proof. Each altered copy produced a different spent-marker key. The destination then saw a supposedly fresh receipt and credited it again, even though the source side had not removed any more value.

Harmony’s fix always derives the spent marker from the signed header. Reworded in plain English: the network now identifies the receipt using the part an attacker cannot change without breaking the signature, instead of trusting editable fields carried beside it.

Why this became token inflation

Cross-shard transfers are supposed to conserve value. If 1,000 ONE leaves one shard, 1,000 ONE can arrive on another. Replaying only the destination credit breaks that conservation rule. The source loses 1,000 once while the destination can gain 1,000 repeatedly.

That is why reports describe the result as minting even though the attacker did not necessarily call a conventional token contract’s mint() function. The global balance increased because the same incoming value was accepted more than once.

The code fixes explain why old material mattered. A current validator committee did not need to sign each replay if the attacker could reach the vulnerable legacy verification path with a historical proof. Harmony still needs to disclose the exact transactions, affected shards, first exploited block, total unauthorized supply and whether both patched bugs were necessary for every replay.

What a rollback would mean

Harmony said it was reviewing “rollback options.” That phrase can make a recovery sound cleaner than it is.

A rollback would ask validators to adopt software that rewinds or overrides accepted chain history. If enough validators coordinate on the same state, attacker balances and some transfers could be removed from Harmony. Transactions made by ordinary users after the chosen cutoff could also need special handling.

The harder problem sits outside Harmony. Tokens already deposited to centralized exchanges may have been sold for USDT, BTC or other assets. Reversing Harmony’s ledger does not reverse an exchange trade automatically. Exchanges would have to freeze accounts, reconcile deposits and decide what to do with customers who bought ONE in good faith.

A rollback also creates a chain coordination risk. Validators, exchanges, RPC operators and applications must agree on the canonical history. If a meaningful group refuses, two versions of Harmony could persist. The team had not announced a chosen rollback height or validator vote by our cutoff time.

The patch stops the hole from producing more supply. It does not, by itself, remove the estimated 4 billion ONE already created.

The rise of Harmony ONE

Harmony’s original appeal was real. Founded by Stephen Tse and launched on mainnet in June 2019, it offered an EVM-compatible chain with state sharding, two-second blocks and an Effective Proof-of-Stake system designed to distribute voting power across validators.

The pitch arrived at the right time. Ethereum was expensive, users wanted faster DeFi and investors were willing to fund alternative Layer 1 ecosystems. Harmony made MetaMask and Ethereum applications feel familiar while charging very little per transaction.

By late 2021, ONE had climbed to an all-time high of $0.379. Harmony’s June 2022 internal metrics cited a peak of $1.41 billion in assets locked. The chain’s flagship, DeFi Kingdoms, combined a decentralized exchange with a pixel-art role-playing game and at one point dominated Harmony activity. Aave, SushiSwap, Curve and native lending protocols followed.

There were weaknesses underneath the growth. Most application use concentrated on Shard 0 while other shards sat idle. The ecosystem depended heavily on a small number of projects and on bridged assets whose value came from collateral held elsewhere. Harmony had impressive throughput capacity, but capacity was not the same thing as durable demand.

The 2022 Horizon bridge hack broke Harmony DeFi

On June 23, 2022, attackers took assets from Harmony’s Horizon bridge to Ethereum. Harmony’s incident summary says at least two of four private keys used by bridge validators were compromised. About $100 million in ETH, USDC, USDT, WBTC and other assets left the bridge.

The FBI later attributed the theft to North Korea’s Lazarus Group, also known as APT38. The agency said more than $60 million in stolen ETH was laundered through Railgun in January 2023, with part of it frozen at service providers.

The damage was not limited to the amount taken. Tokens such as 1USDC and 1ETH on Harmony had represented claims on assets locked in the bridge. Once the backing disappeared, those tokens broke their pegs. Harmony said roughly 64,000 wallets were affected, including about 50,000 bridge wallet owners.

DeFi accounting then turned the bridge loss into bad debt. Aave still read oracle prices for bridged stablecoins near one dollar while the market knew their backing was gone. Traders bought depegged assets cheaply, deposited them as collateral and borrowed real ONE. Aave’s Harmony market was frozen, leaving lenders unable to withdraw all supplied liquidity. Recovery proposals continued into 2026.

Harmony first proposed minting either 4.97 billion ONE for an estimated 100% reimbursement or 2.48 billion for 50%, distributed over three years. The community reaction was hostile because token holders would absorb the dilution. A later Recovery ONE burn plan switched to treasury-funded purchases and burns of depegged assets with no new minting.

Recovery work did destroy some unbacked assets, but it did not restore the old ecosystem. Harmony’s own Q1 2023 report put DeFi TVL at $6.5 million. By the morning of the 2026 exploit, DefiLlama showed only about $176,000, with 244 active addresses and $697 in 24-hour DEX volume. TVL is an imperfect metric, but the difference from $1.41 billion is too large to explain away as measurement noise.

Harmony inflated ONE again in 2023

The August 2026 exploit is not Harmony’s first native supply failure.

In December 2023, the team found a flaw in staking undelegation logic. A commission-rate rule could make a validator state update fail its sanity check. Matured undelegations were paid but not removed from state, so the same balances remained eligible for payout in later epochs.

Harmony’s technical incident report counted 146,279,995.61211874 ONE created across 74 delegator addresses and four validators. The chain used an emergency hard fork, blacklisted affected addresses and required bad ONE to be burned before addresses could leave the blacklist.

That bug was smaller than the estimated 2026 exploit, but it matters for trust. Both incidents violated a basic expectation: the protocol should know when value has already been paid or credited. In 2023, stale undelegation state paid again. In 2026, an old cross-shard receipt appears to have credited again.

The implementations differ. The accounting failure rhymes.

Was Harmony dead before this exploit?

The chain was not literally dead. It kept producing blocks. Validators and delegators remained active. The team shipped v2026.1.0 in July, a large hard fork that added EVM updates, stream-sync work and several consensus safety checks. Harmony’s 2026 roadmap focused on DeFi trading systems, hedging tools, AI agents and infrastructure work.

But the economic network around the chain had already contracted to a fraction of its peak. ONE entered August 12 more than 99% below its 2021 high. Major applications and liquidity had moved elsewhere. Bridge victims and Aave depositors were still discussing recovery. A functioning node release process did not translate into restored user trust or capital.

So the honest answer is awkward: Harmony was still maintained, but it had not recovered. The new exploit attacked the part that was still working, the base protocol itself.

What ONE holders and Harmony users should do now

This incident does not mean an attacker learned every user’s private key. A normal self-custody wallet is not automatically compromised because unauthorized ONE was created elsewhere in the ledger. The immediate risks are different: uncertain supply, exchange restrictions, bridge interruption, market volatility and a possible rollback.

  • Do not use Harmony’s bridge while it is paused. A copycat site or fake support account may claim to offer a migration route.
  • Check the exchange itself before depositing ONE. Deposits, withdrawals and trading can be restricted independently. Do not rely on an influencer screenshot.
  • Keep transaction records. If Harmony rolls back history, a timestamp, transaction hash and exchange deposit record will matter.
  • Do not share a seed phrase or sign a recovery transaction sent by direct message. No legitimate rollback requires handing a stranger your wallet secret.
  • For staked ONE, verify the address on the explorer and official staking interface. A dashboard display problem is not proof that the stake vanished.
  • Wait for the postmortem before treating the 4 billion figure as final accounting. The exploit is confirmed. The final minted, sold, frozen, burned and rolled-back amounts are not.

Anyone trading during this period is accepting more than ordinary crypto volatility. The final supply and even the canonical transaction history remain under discussion.

Can Harmony recover this time?

Shipping v2026.1.1 within hours was the right containment step. Publishing the patch also gives independent researchers something concrete to inspect. Neither action settles the harder questions.

Harmony now has to provide a block-by-block accounting of the exploit, explain why legacy receipt and signature paths remained reachable, disclose how the vulnerabilities escaped the large July hard fork, and show which exchanges froze what amount. If it chooses a rollback, it needs a public rule for handling innocent buyers and transactions after the cutoff. If it rejects a rollback, it needs a credible way to remove or absorb unauthorized supply without pretending the market impact never happened.

The project is also carrying old debt, both financial and reputational. The 2022 bridge loss remains partially unresolved. The 2023 staking inflation incident already demonstrated that emergency patches and blacklists can contain a bug without rebuilding an ecosystem. In 2026, there is much less DeFi activity left to anchor a second recovery.

Harmony began with a serious technical idea: scale an EVM chain horizontally through shards while keeping fast finality and open staking. Its decline was not proof that sharding itself cannot work. It was a record of security and accounting failures around the system that was built.

The question is no longer whether Harmony can restart block production. It never stopped for long. The question is whether users, validators and exchanges will accept its ledger as trustworthy after the same receipt appears to have become money again and again.

Harmony ONE exploit FAQ

What happened to Harmony ONE in August 2026?

An attacker appears to have replayed cross-shard receipts and created roughly 4 billion ONE without authorization. Harmony released an emergency validator patch and paused its bridge.

Is the 4 billion ONE figure final?

No. It was the leading incident estimate when this article was updated. Final minted, moved, frozen, burned or rolled-back amounts require Harmony's completed accounting.

How did the 2026 Harmony exploit work?

The public patch indicates an empty signer bitmap could pass an old signature path and a mutable receipt identity could bypass the spent marker, enabling repeated credit.

Which Harmony software fixed further minting?

Harmony released mainnet version v2026.1.1 on August 12, 2026. Validator operators should verify binaries and instructions from the official repository.

Did the exploit compromise every Harmony wallet?

No evidence showed that every user's private key was compromised. Immediate risks concerned supply, exchanges, the bridge, volatility and possible ledger changes.

What would a Harmony rollback do?

A rollback would choose an earlier state as canonical, potentially reversing both attacker and innocent transactions after a cutoff and creating difficult exchange-accounting questions.

What was the 2022 Harmony Horizon bridge hack?

Attackers compromised bridge validator keys and removed about $100 million in backing assets. The FBI later attributed the theft to North Korea's Lazarus Group.

Did Harmony have another inflation bug before 2026?

Yes. A 2023 staking undelegation flaw created about 146.28 million ONE before an emergency hard fork and blacklist response.

Should users use the Harmony bridge during the incident?

No. The bridge was paused, and users should avoid unofficial migration or recovery links and verify current status only through Harmony's official channels.

Can Harmony recover from the exploit?

The patch contained further minting, but recovery also requires transparent accounting, a credible treatment of unauthorized supply and renewed trust from validators, exchanges and users.

This article is news and technical analysis, not financial advice. The August 12 incident is developing. Follow Harmony's official channels and verify release links independently before changing validator or wallet software.

Share

Found this useful?

Share it with someone who'd want to read it.

Related