Harmony Says Exploit Minted About 4 Billion ONE Tokens, Token Drops 26%
Harmony, the Layer-1 blockchain behind the ONE token, said an apparent exploit minted about 4 billion new ONE tokens early Wednesday, and the token fell about 26% after the incident was reported. CoinDesk reported at 05:18:40 UTC that Harmony had publicly confirmed the exploit and that on-chain activity indicated roughly 4 billion ONE had been created.
Harmony said it was working with exchanges to freeze funds, preparing a software patch and weighing whether to roll back the chain to reverse the impact. “We are working on a patch and rollback options,” CoinDesk reported Harmony as saying in a post on X. The company had not said that any funds were successfully frozen.
The size of the apparent mint matters because it would sharply expand the token’s supply. Before the incident, roughly 15 billion ONE existed, according to CoinDesk, with market data services such as CoinMarketCap and CoinGecko showing circulating supply at about 14.99 billion around the time of the report. A mint of about 4 billion ONE would equal roughly 26% of that prior circulating supply, raising immediate concerns about dilution as well as network security.
Several key details were not yet publicly verified in reporting on the incident. Harmony had not explained how it calculated the 4 billion-token figure, had not publicly identified the exact vulnerability that allowed the mint, and had not disclosed how far back any rollback might go. Public reporting also had not verified the relevant transaction IDs, the recipient addresses or whether any of the newly minted tokens had already been moved to exchanges or cashed out. Whale Alert flagged the incident earlier on Aug. 12, but Harmony’s confirmation was the first public acknowledgment from the project itself.
Harmony is a Layer-1 blockchain, meaning it runs its own base network rather than operating on top of another chain. ONE is its native token and is used to pay transaction fees and for staking, the process by which token holders help secure the network. That means an unauthorized mint is not just a technical failure; it can also affect the economics of the token by increasing supply unexpectedly.
The incident also lands against a backdrop of prior security problems at Harmony. In December 2023, the project disclosed a staking-logic vulnerability that improperly created about 146.3 million ONE and required emergency action. Earlier, Harmony’s Horizon Bridge was hacked on June 24, 2022, with about $100 million stolen. In January 2023, the FBI said North Korea’s Lazarus Group was responsible for that bridge attack.
For now, the central facts are limited but significant: Harmony has confirmed an apparent exploit, the reported scale is about 4 billion newly minted ONE, and the market reaction was immediate. The exact cause, the path of any funds and the scope of any possible rollback had not been publicly detailed as of early Wednesday.