Harmony Suffers Major Security Breach, 30 Billion ONE Tokens Illegally Minted

icon MarsBit
Share
AI summary iconSummary
On August 12, 2026, Harmony suffered a major security breach after attackers exploited a vulnerability in cross-shard receipt validation to mint 30 billion ONE tokens, worth over $234 million. The exploit used forged receipts with zero signatures and a dead address, enabling the attacker to bypass validation checks. Harmony has paused its cross-chain bridge and released a software patch to prevent further minting. The team is now evaluating a network rollback. This is the third on-chain event involving Harmony’s token supply in recent years.

Article by: Mah, Foresight News

Hacker attacks are becoming the "number one killer" of cryptocurrency protocols.

On August 12, X user Juiceberg tweeted that on-chain data showed a vulnerability exploit on the Harmony protocol, during which the attacker illegally minted approximately 40 billion ONE tokens (worth over $3 million), accounting for 26% of its total supply. Around 2.8 billion tokens were rapidly transferred to exchanges during the price crash, while Harmony’s total supply endpoint failed to reflect this token minting, resulting in a discrepancy between the actual on-chain supply and publicly reported data. The attacker still holds approximately 115 million tokens on-chain (about 2.9% of the minted amount), while the vast majority have entered exchange accounts, either been sold or are held in deposit wallets.

After the announcement, the price of ONE dropped from $0.00118 to a low of $0.00056, and has since recovered to $0.00078, down nearly 38% over the past 24 hours.

Harmony

Harmony's official account subsequently replied on X, stating that it is collaborating with its team and multiple related exchanges to block and freeze the involved funds, while also advancing the development of software patches and evaluating the option of a network rollback.

Subsequently, the official further disclosed four sets of related wallet addresses, explicitly requesting all exchanges to block and freeze funds traceable to these addresses:

  • one1uap8dx2z0qsjxqthm5flgcxkeepsz3gsrghnfn
  • one17u300a40ll5wphd8kj5hktryhdjq3ml9f4phy4
  • one1a5hur07z5vtvzhr35zkw8tfqedemkz8t88xgd7
  • one1h56hkxmua0uzfv07fu04cudvtrl35u96pq47vy

At approximately 2:00 PM, the official announcement stated that the bridge.harmony.one cross-chain bridge service has been suspended due to a security incident, and all validator nodes are required to immediately upgrade to the latest patch version v2026.1.1. The official explanation noted that this patch prevents further unauthorized minting, and a subsequent update will address the already minted tokens. The related release record is now available on GitHub.

This is the third major security or technical issue related to token supply that Harmony has experienced in recent years. In June 2022, its Horizon cross-chain bridge was attacked, resulting in the loss of approximately $100 million in assets, with the U.S. Federal Bureau of Investigation later attributing the incident to a North Korea-linked hacking group. In December 2023, a bug in the staking system led to the erroneous minting of approximately 146.3 million ONE tokens across 74 addresses, with a single address receiving over 51 million tokens; some of these tokens were subsequently transferred to exchanges. The team promptly released a patch and implemented follow-up measures at the time.

From a market perspective, although this incident caused significant supply dilution and sharp price volatility, the absolute loss scale was limited. Prior to the incident, Harmony’s market cap had already declined to around $17 million; after the incident, it further dropped to approximately $12 million, resulting in a market cap loss of about $5 million. In 2022, Harmony’s total TVL once peaked above $1.4 billion, but according to the latest data from DefiLlama, its TVL has now fallen to less than $170,000.

Harmony

According to CertiK Alert monitoring, as of approximately 4 p.m., over 3 trillion ONE tokens have been anomalously minted on the Harmony network, valued at approximately $2.34 billion, across six anomalous blocks.

In the early stages of the attack, the attacker exploited the total supply API to conceal minting data, and since different blocks were being bundled progressively, the 40 billion minted at that time was far from accurate.

Harmony

The X account BlockWatchdog analyzed the incident, stating that the attacker exploited a critical logical flaw in Harmony’s cross-shard receipt verification and signature validation, forging approximately 3 trillion coins in a single attack.

Harmony

Harmony is a sharded chain, and transferring coins between different shards requires a "receipt" as proof. The hacker forged such receipts, and the receipts stated:

From a very early epoch (epoch 100, now over 3,000)

All signatures are empty (zero signatures)

Transferred from a dead address (0x00…dEaD)

Under normal circumstances, the system should have rejected the request outright. However, the system has two vulnerabilities: First, the signature check was implemented incorrectly. When verifying whether “enough people signed,” the system only checked “how many members are on the committee,” not “how many actual signatures were provided.” As a result, as long as the committee size is ≥4, even entirely empty signatures would pass. This is like a broken lock that can be opened with just a push. Second, the replay protection has a flaw: the system’s check for “has this receipt been used before?” relied, during older epochs, on a field that the attacker could control. This allowed the attacker to repeatedly reuse the same fake receipt or bypass the check entirely.

When two vulnerabilities are stacked together, attackers can generate trillions of coins in a single attack.

As of press time, the official team has not yet confirmed whether a network rollback will ultimately be executed. A rollback would restore the chain state to a point prior to the attack, theoretically erasing some of the effects of unauthorized minting. However, if a large volume of tokens has already entered centralized exchanges and been traded, the practical impact will be significantly limited. Key short-term market variables include whether exchanges effectively freeze related funds, the adoption rate of patches among validation nodes, and the planned handling of already-minted tokens.

Harmony, as an early Layer 1 blockchain emphasizing high performance and low fees, once held a notable position in DeFi and cross-chain narratives. However, consecutive security incidents combined with prolonged market cap decline have significantly reduced its visibility in today’s crypto market.

This incident once again highlights the vulnerability of low-market-cap public blockchains in terms of consensus and supply mechanisms, and reminds market participants to more carefully evaluate the historical security records and actual on-chain activity of similar projects.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.