Harmony Confirms Exploit After Attacker Mints 4 Billion ONE Tokens
Harmony confirmed a network exploit after an attacker allegedly minted 4 billion unauthorized ONE tokens, crashing the token’s price and prompting exchange freezes and a possible rollback.
Harmony confirmed Wednesday that its network was exploited after an attacker allegedly minted roughly 4 billion unauthorized ONE tokens. The incident drove the token’s price down as much as 40% and prompted the project to coordinate with exchanges on freezing funds while weighing a chain rollback.
The mint swelled ONE’s pre-incident supply of about 15 billion tokens by roughly 26%, according to CoinDesk. Put another way, the newly created tokens represented about a quarter of total supply.
ONE fell about 40% in Asian morning trading on news of the apparent exploit, CoinDesk reported. The Block put the 24-hour drop at 34%, with ONE trading near $0.0008. Cointelegraph, citing CoinGecko, reported a 33.9% decline. The figures diverge by reporting window.
At the token’s current price, the unauthorized mint carries a nominal value of roughly $3.2 million, The Block estimated.
An X user known as Juiceberg first raised the alarm, reporting that an attacker had minted 4 billion ONE using empty blocks. Juiceberg later wrote that the attacker had roughly 115 million ONE left to sell onchain. That is about 2.9% of the minted total.
“The overwhelming majority (~97%) is already on exchanges and has either been sold or is sitting in deposit wallets ready to sell,” Juiceberg wrote, as quoted by The Block. Cointelegraph reported that Juiceberg put the figure funneled to exchanges at roughly 2.8 billion tokens. Neither outlet independently verified the claims.
Harmony acknowledged the exploit in a statement on X. It said it was working with its team and exchanges to stop and freeze funds. “We are working on a patch and rollback options,” the project said, adding it would provide another update when more information was available, according to CoinDesk.
Harmony told network operators to install an emergency software update to prevent further minting and paused its token bridge, CoinDesk reported. The project also asked exchanges to freeze funds traced to four addresses, one of which was listed as 0xf722f7f6afffe8e0dda7b4a97b2c64bb6408efe5.
A rollback would return the network to its pre-exploit state. It becomes harder to execute once funds reach exchanges, though. Many in the industry view rollbacks as antithetical to blockchain immutability, CoinDesk noted. Harmony has not said whether it will proceed with one.
The project has not disclosed the technical root cause of the exploit, confirmed its own figure for the unauthorized issuance, or explained how the minting occurred. Cointelegraph said it contacted Harmony for comment and had not received a response by publication. The Block said it had also reached out.
This is not Harmony’s first major security incident. In June 2022, attackers compromised the multi-signature wallet of the project’s Horizon cross-chain bridge and drained nearly $100 million in ETH and stablecoins. The FBI later attributed that attack to North Korea’s Lazarus Group and APT 38, The Block reported.
A smaller incident followed in December 2023. A bug in Harmony’s staking system created roughly 146.3 million ONE tokens across 74 addresses. The network responded with an emergency update and blacklisted the affected addresses, CoinDesk reported.
Separately, a day before the Harmony exploit, Ravencoin faced its own possible rollback after its network accepted invalid blocks, CoinDesk noted. The two incidents are unrelated.
Harmony launched its mainnet in 2019 as a proof-of-stake blockchain. ONE is the native token, used for transaction fees, staking, and governance. Whether the emergency patch, the exchange freeze, or a rollback will contain the damage remains unclear. Traders, as ever, disagree.