Harmony Protocol Confirms Unauthorized Mint of 400M ONE, Plans Network Rollback
AI Market Summary
Harmony confirmed unauthorized minting of ONE via a crossshard receipt replay vulnerability, with early estimates at 4B ONE and onchain reconstruction indicating far larger issuance across forged transactions. Bridge services are suspended, Shard 0 is paused, and the team is preparing a rollback to a pre-attack block while coordinating freezes with validators, exchanges, and LayerZero. The incident undermines network integrity and elevates near-term operational and liquidity risk.
Impact level
● High
Affected assets
ONE/USDT-9.01%
AI Insight · ONE/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
Harmony Protocol said in an incident update on Aug. 14 (UTC+8) that unauthorized minting of ONE tokens occurred on Aug. 12. The project's investigation attributes the incident to a cross-shard receipt replay flaw, which allowed previously processed cross-shard receipts to be executed again, minting ONE into empty blocks.
The team is reconciling two impact estimates. Early analysis pointed to 4 billion ONE minted, while a newer on-chain reconstruction suggests roughly 3.01 trillion ONE may have been created across six forged cross-shard transactions to four attacker-controlled wallets. Harmony said it has confirmed an initial mint of 4 billion ONE, produced through two empty-block transactions of 1 billion ONE and 3 billion ONE, followed by transfers totaling 2.8 billion ONE to additional attacker addresses.
Harmony said it has patched issues in cross-shard receipt validation and pre-staking quorum verification, and deployed Mainnet v2026.1.1 at 06:30 UTC on Aug. 12. Bridge services remain suspended. The protocol is working with validators, exchanges and LayerZero to freeze related funds, and is preparing to roll back the network to block 92,730,034, prior to the attack.
Shard 0 has been paused at block 92,753,555, and official RPC endpoints may return 502 errors. (Source: ODAILY)