Representatives from Harmony confirmed the attack, which resulted in approximately 4 billion new ONE tokens being created in the network—more than a quarter of the total coin supply. Prior to the incident, around 15 billion ONE were in circulation, so the additional issuance caused a sharp decline in the asset's value.

The Harmony team announced that it is already working with cryptocurrency exchanges to freeze the stolen funds and is preparing a patch for the code. Project representatives have not disclosed details of the vulnerability or how far back a potential network rollback might go.
“We are evaluating options for releasing a patch and rolling back the network to one of the previous versions,” the Harmony team said, promising to provide updated information as it becomes available.
Harmony is a Layer-1 blockchain designed for DeFi protocols and trading platforms. The native token, ONE, is used to pay for transactions and secure the network. A “rollback” refers to reverting the network to its state prior to the hack, excluding all subsequent transactions from the blockchain history. This action prevents attackers from retaining newly acquired tokens on the network, but becomes less effective if funds have already been deposited on exchanges or transferred to other systems.
This is not the first instance of unauthorized token issuance on Harmony. In December 2023, a bug in the staking system led to the issuance of approximately 146.3 million ONE tokens—tokens that should have ceased payouts but continued to be generated. The incident involved 74 addresses, with one address receiving 51.2 million ONE, and approximately 16.4 million later transferred to an exchange. In response, the project team released an emergency update and blacklisted addresses containing incorrectly created tokens.
Previously, in 2022, Harmony suffered one of the largest cross-chain bridge attacks: attackers stole approximately $100 million through the Horizon bridge by exploiting compromised private keys. The FBI later linked this theft to the North Korean group Lazarus.
Recently, the crypto payment service Coinsbuy was compromised, resulting in over $7.9 million being stolen from its wallets. Analysts from PeckShield suggested that the breach may have been caused by compromised private keys or a critical vulnerability in the service’s infrastructure.

