
Harmony’s ONE Drops 40% After Suspected Exploit Creates 4B Tokens
Harmony’s ONE token fell roughly 40% during Asian trading Wednesday after an apparent exploit generated about 4 billion new tokens, an amount equal to more than 25% of the supply that existed before the incident.
Harmony confirmed the security breach and said it is coordinating with network operators to deploy an emergency update designed to stop any additional unauthorized minting. The project is also examining how to deal with the tokens that were created during the attack.
The network has paused its token bridge and asked exchanges to freeze funds associated with four wallet addresses reportedly connected to the incident.
Harmony said its team is working on a software patch while also evaluating possible rollback options. The project said it would release more information as its investigation develops.
Sudden Supply Increase Hits ONE
Harmony is a layer-1 blockchain that supports decentralized finance protocols and digital marketplaces. Its native ONE token is used for transaction fees and helps secure the network.
The project reached a market value of roughly $4 billion at its peak in January 2022.
About 15 billion ONE tokens existed before Wednesday’s incident. The reported creation of another 4 billion tokens would represent a supply increase of approximately 26%.
A sudden addition of that size can create significant selling pressure, especially if the newly issued tokens reach exchanges or are converted into other assets.
Potential Rollback Raises Questions
Harmony is considering whether to roll back the blockchain to a point before the exploit.
Such a move could effectively erase transactions made after the attack and prevent the attacker from retaining the newly generated tokens. However, a rollback becomes considerably harder if the affected funds have already moved to exchanges or other blockchain networks.
The approach also creates a conflict with blockchain immutability. Reversing the chain could remove legitimate transactions made after the exploit alongside the attacker’s activity.
The incident comes shortly after a separate problem involving Ravencoin, another smaller blockchain derived from Bitcoin. Parts of the Ravencoin network accepted invalid blocks, prompting miners to consider rebuilding the chain from an earlier point.
Although the incidents are unrelated, they demonstrate the difficult choice blockchain communities face when deciding between reversing an exploit and preserving legitimate transactions.
Harmony Has Faced Earlier Security Problems
Harmony has previously dealt with unauthorized token issuance.
In December 2023, a staking-system bug resulted in approximately 146.3 million ONE being created after certain tokens continued receiving rewards despite no longer being eligible.
Harmony said 74 addresses were involved, with one receiving about 51.2 million ONE. Around 16.4 million of the improperly issued tokens were subsequently transferred to an exchange.
The network responded with an emergency software update and blacklisted wallets holding the affected tokens.
The project also suffered a major bridge attack in 2022, when hackers stole approximately $100 million from the Horizon bridge after compromising its private keys. The FBI later attributed the attack to North Korea’s Lazarus Group.
Wednesday’s incident appears to be different because the reported damage stems from the creation of new ONE tokens directly on Harmony rather than the theft of existing assets from its bridge.
Harmony has not yet disclosed the exact vulnerability that enabled the minting, independently verified the reported 4 billion tokens or explained how it will handle the newly created ONE that has already entered circulation.





