Harmony’s ONE Crashes 40% After Suspected Exploit Mints 4 Billion Tokens
Harmony’s ONE token plunged nearly 40% during Asian trading Wednesday after a suspected exploit appeared to create approximately 4 billion additional tokens, equivalent to more than a quarter of the supply that existed before the incident.
Harmony acknowledged the attack and said it is working with network operators to deploy an emergency software update aimed at stopping any further unauthorized minting. The team is also investigating how to handle the tokens that have already been created.
The project has temporarily suspended its token bridge and urged cryptocurrency exchanges to freeze funds linked to four wallets associated with the attack.
Harmony said it is developing a patch while considering rollback options, with further information expected as the investigation continues.
4 Billion New ONE Tokens Add Major Supply Pressure
Harmony operates a layer-1 blockchain designed for decentralized finance applications and marketplaces. Its native ONE token is used for transaction fees and contributes to network security.
The project previously reached a valuation of roughly $4 billion in January 2022.
Around 15 billion ONE tokens were in circulation before the exploit. The reported creation of another 4 billion tokens would therefore increase the supply by approximately 26%.
Such a sudden expansion can put substantial pressure on the token price, particularly if the newly created assets are sold or transferred to trading platforms.
Harmony Weighs Blockchain Rollback
One of the options under consideration is a rollback that would return the Harmony network to a state before the exploit occurred.
Reverting the chain could remove post-attack transactions and make it harder for the attacker to retain the newly minted tokens. However, the approach becomes more difficult once affected assets have been deposited on exchanges or transferred to other networks.
A rollback can also conflict with the principle of blockchain immutability because legitimate transactions made after the exploit could be reversed along with the malicious activity.
The incident follows a separate issue involving Ravencoin, another smaller blockchain derived from Bitcoin’s code. Parts of that network recently accepted invalid blocks, prompting miners to consider rebuilding the chain from an earlier point.
While the two incidents are unrelated, both illustrate the challenges involved in deciding whether reversing an attack is worth potentially undoing legitimate transactions.
Harmony Has Dealt With Similar Issues Before
The project has previously experienced problems involving unauthorized ONE creation.
In December 2023, a staking-system bug led to about 146.3 million ONE being generated after certain tokens continued receiving rewards even though they should have stopped.
Harmony said 74 addresses were affected, including one wallet that received about 51.2 million ONE. Approximately 16.4 million of those tokens were later transferred to an exchange.
The network responded by releasing an emergency software update and blacklisting wallets that held the improperly created tokens.
Harmony also suffered a major security breach in 2022, when approximately $100 million was stolen from its Horizon bridge after attackers compromised the private keys controlling it. The FBI later attributed the incident to North Korea’s Lazarus Group.
The latest attack appears to differ because the reported loss involves unauthorized issuance of ONE directly on the Harmony blockchain rather than the theft of existing assets from a bridge.
Harmony has not yet disclosed exactly how the attacker managed to mint the tokens, independently confirmed the reported 4 billion issuance or explained its final plan for the newly created ONE already in circulation.




