Harmony confirmed on Wednesday that its blockchain had been exploited, hours after on-chain analyst Juiceberg posted the first public account of unusual activity showing roughly 4 billion ONE tokens had been created without authorization through a method involving empty blocks.
The minted amount represented close to 26% of ONE's existing supply of approximately 15 billion tokens. CoinGecko data shows the token fell to a new all-time low of $0.0005735 before settling near $0.00075, a drop of about 38% from where it had traded in the 24 hours before the incident became public.

We are working with our team and appropriate exchanges to stop and freeze the funds.
ā Harmony š (@harmonyprotocol) August 12, 2026
We are working on a patch and rollback options.
Will update when we have new information. https://t.co/XB0nCwTAyN
How the attacker moved through exchanges
Juiceberg was the first to put numbers to the event publicly. The analyst's initial post on X described how roughly 2.8 billion of the unauthorized tokens had already been moved toward exchange addresses before the exploit was widely known:
"Harmony exploited as on-chain data reveals unauthorized 4B ONE mint (26% of supply) via empty blocks, with 2.8B quickly funneled to exchanges as price crashed while totalSupply endpoint hides the inflation $ONE."
In a follow-up, Juiceberg described what remained on-chain:
"The attacker has roughly 115M ONE left to sell onchain ā about 2.9% of the ā¼4B they minted. The overwhelming majority (ā¼97%) is already on exchanges and has either been sold or is sitting in deposit wallets ready to sell."
Key cash-out transactions :
ā Juiceberg (@the_juice_berg) August 12, 2026
- 2.8B ONE ā exchange deposit hop (01:02Z) ā https://t.co/6p7Arfc9XR
- 111M ONE feeder split (00:12Z) ā https://t.co/F7JDPB7SqF
- 266.9M ONE feeder chunk (00:33Z) ā https://t.co/R7EkLAkbUY
One detail from that initial report created an additional layer of concern. Harmony's own totalSupply endpoint did not reflect the newly created tokens at the time, and price trackers, including CoinGecko, still listed circulating supply at approximately 14.87 billion. That gap between what public data showed and what was visible on-chain made it difficult for exchanges and traders to assess the actual scale of dilution in real time.
Harmony confirmed the attack in a post on X and said it was already in contact with exchanges.
"We are working with our team and appropriate exchanges to stop and freeze the funds. We are working on a patch and rollback options. Will update when we have new information."
Shortly after that statement, the team published four wallet addresses in both Harmony and hex formats and asked all exchanges to block and freeze any funds traceable to them. Just over two hours after the first public post, Harmony paused the LayerZero-Harmony bridge.
Due to the incident, we have paused https://t.co/V2erl739xF. https://t.co/mavyY3dSGg
ā Harmony š (@harmonyprotocol) August 12, 2026
A software patch followed almost immediately, with validators told to upgrade to a build the team said would prevent further minting. Tokens already in circulation would require a separate update:
"We'll follow up with another update to address already minted tokens," the team confirmed.
By Wednesday evening, Harmony had not publicly explained the root cause of the vulnerability. The team had also not confirmed its own figure for the total unauthorized issuance or clarified how much of the new supply had already cleared exchange systems.
What a rollback would actually mean
Harmony listed a rollback among the options under evaluation. In practical terms, a rollback returns the network to its state before the exploit and continues from that point. All transactions that occurred afterward are no longer part of the chain's accepted history. That includes legitimate transactions made by ordinary users after the attack.
The approach becomes significantly harder once funds have moved through centralized exchanges, since those platforms operate outside the chain's direct control. Reversing on-chain history does not automatically recover assets that have already been converted or withdrawn elsewhere.
The same question surfaced on Ravencoin one day earlier, when parts of that separate blockchain accepted invalid blocks and miners began rebuilding the chain from before the flaw, with several days of ordinary user transactions at risk of reversal. The Harmony and Ravencoin situations are unrelated, but both put the same tension into focus: reversing an attack can also reverse what honest users did after it.
The crypto industry has long regarded rollbacks as a challenge to blockchain's foundational principle of immutability. For Harmony's community and validators, the decision on this front will carry both a technical dimension and a political one.
A network that carries the weight of 2022
Wednesday's event is the third notable security incident in Harmony's history. The most consequential came in June 2022, when attackers drained approximately $100 million from the Horizon cross-chain bridge after compromising the private keys that controlled it. The FBI attributed that theft in January 2023 to North Korea's Lazarus Group and a second state-linked organization, APT38.
Harmony's first proposal after the 2022 bridge attack was to reimburse affected users in ONE tokens, a plan that would have required minting billions of new tokens on top of the existing supply and hard-forking the chain. The community rejected it, and the team replaced the plan with one funded from the treasury. An attacker has now carried out what that proposal would have required, without any vote.
A less-discussed incident from December 2023 fits the same pattern. A bug in Harmony's staking system caused approximately 146.3 million ONE to be created because validators that should have stopped receiving payouts continued to accumulate them. Harmony said 74 addresses were involved, with one receiving 51.2 million ONE, and about 16.4 million of those tokens moved to an exchange before the team responded with an emergency software update and blacklisted the affected addresses.
ONE at $11.5 million, four years from its peak
Harmony launched its mainnet in 2019, built as a proof-of-stake alternative to Ethereum with ONE as the native token used to pay for transactions and secure the network. The project reached a market capitalization of around $4 billion in January 2022. ONE's all-time high of $0.38 was recorded in October 2021.
Wednesday's crash leaves the token outside the top 1,000 by market cap, with a total valuation of approximately $11.5 million and a price more than 99% below its record.
Harmony had not responded to requests for further comment at the time of publication.

Disclaimer: All materials on this site are for informational purposes only. None of the material should be interpreted as investment advice. Please note that, despite the nature of much of the material created and hosted on this website, HODL FM operates as a media and informational platform, not a provider of financial advisory services. The opinions of authors and other contributors are their own and should not be taken as financial advice. If you require advice, HODL FM strongly recommends contacting a qualified industry professional.





