Harmony Network Hacked: Attacker Mints Roughly 4 Billion ONE Tokens, Price Craters

Harmony, the layer-1 network that survived a $100 million bridge hack in 2022, was hit again this month — this time from the inside, through the chain’s own block production process rather than a smart contract exploit. Here is how the incident unfolded, based on Harmony’s own incident disclosures and on-chain analysis that surfaced in the hours that followed.
August 12, Early UTC Hours — Empty Blocks, Unauthorized Minting
An attacker found a way to trigger unauthorized issuance of native ONE tokens by exploiting “empty blocks” — valid blocks on the Harmony chain that contain no user transactions but were apparently not fully protected against manipulation of the minting logic tied to block production. Estimates converged around 4 billion ONE minted out of thin air, roughly a quarter of the token’s previously reported circulating supply, spread across a reported 409 wallet addresses in thousands of transactions.
Within Hours — A Race to the Exchanges
Because Harmony’s public totalSupply figure did not update in real time, the newly minted tokens could be moved and sold before the anomaly became obvious. On-chain trackers estimated that around 2.8 billion of the minted ONE — roughly 97% of that portion — was funneled toward exchange deposit addresses in an apparent rush to cash out before exchanges could react. ONE’s price collapsed as the selling pressure hit order books, with different data providers clocking the immediate decline anywhere from roughly 30% to as much as 38-40% depending on the exact time window measured, before the token found a floor at a fraction of a cent.
Same Day — Harmony’s Emergency Response
Harmony acknowledged the exploit publicly within hours, saying it was working with its team and “appropriate exchanges to stop and freeze the funds” while evaluating both a patch and a possible chain rollback. The team identified clusters of exploiter-linked wallets and asked exchanges to block further movement from those addresses. A fix was packaged into mainnet release v2026.1.1, which Harmony says was deployed by 06:30 UTC that same day — a fast turnaround, though it came after a meaningful share of the minted tokens had already reached exchanges.
An Awkward Echo of 2022
The response effort also surfaced friction left over from Harmony’s last major incident. Independent on-chain investigator ZachXBT reportedly declined to help trace this exploit and publicly discouraged others from volunteering for free, arguing that Harmony had treated contributors who helped freeze funds after the 2022 Horizon bridge hack — a $100 million theft attributed to North Korea’s Lazarus Group — poorly, rewarding that earlier help with little more than a thank-you.
As of this writing, Harmony has not disclosed how much of the illicitly minted supply has been successfully frozen or recovered, and whether a rollback will ultimately be pursued remains an open question. For a network that had already spent years working to rebuild trust after 2022, a second nine-figure-adjacent security failure in the same core infrastructure is a hard story to spin.
New to how blockchain minting and supply mechanics actually work under the hood? Coin680’s Bitcoin Academy covers the basics in accessible terms.
This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency markets, and smaller-cap tokens in particular, can experience extreme volatility following security incidents — always do your own research before making investment decisions.
