Harmony Protocol: Unauthorized Event Led to Initial Minting of 4 Billion ONE

AI Market Summary
Harmony confirmed an unauthorized ONE mint caused by a cross-shard receipt double-validation exploit, with initial analysis at 4B ONE and later reconstruction indicating far larger issuance across forged transactions. Bridge services are suspended, Shard 0 is halted, and the team has patched validation logic, deployed a mainnet upgrade, and is coordinating freezes while preparing a rollback. The incident elevates protocol and settlement risk for ONE and related venues.
Impact level
● High
Affected assets
ONE/USDT-9.01%
AI Insight · ONE/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
Harmony Protocol released an incident update confirming an unauthorized minting of ONE tokens. The project said its investigation found the attacker exploited a flaw in the cross-shard receipt double-validation mechanism, allowing previously processed cross-shard receipts to be executed again and minting ONE in empty blocks. The team is reconciling two sets of impact figures. Early analysis pointed to an initial issuance of 4 billion ONE. A more recent on-chain reconstruction indicates roughly 3.01 trillion ONE were minted via six forged cross-shard transactions to four attacker-controlled wallets. Harmony confirmed the initial 4 billion ONE mint came from two empty-block transactions—1 billion ONE and 3 billion ONE—followed by the transfer of 2.8 billion ONE to other attacker addresses. Harmony said it has patched the cross-shard receipt validation vulnerability and a pre-committee quorum verification issue, and has deployed Mainnet v2026.1.1. Bridge services remain suspended. The protocol is working with validators, exchanges, and LayerZero to freeze related funds, and is preparing a network rollback to block 92,730,034, prior to the attack. Shard 0 has been halted at block 92,753,555. As a result, official RPC endpoints may return 502 errors.