Latest News

Harmony Says Exchanges Are Helping Freeze Funds After 4…

What Happened To Harmony And The ONE Token?

Layer 1 blockchain Harmony confirmed on Wednesday that it had been exploited after an attacker reportedly minted 4 billion ONE tokens without authorization, triggering a sharp drop in the cryptocurrency’s price and raising questions over the network’s token supply.

The incident was first reported by X user Juiceberg, who said the attacker created the tokens through empty blocks. ONE subsequently fell about 34% over 24 hours to roughly $0.0008, giving the 4 billion newly minted tokens a market value of about $3.2 million at that price.

The reported attack also created an unusual supply-accounting issue. According to Juiceberg, Harmony’s totalSupply endpoint did not immediately reflect the additional tokens, making it harder for users and trading platforms to determine the extent of the dilution through standard network data.

“The attacker has roughly 115M ONE left to sell onchain — about 2.9% of the ~4B they minted,” Juiceberg wrote. “The overwhelming majority (~97%) is already on exchanges and has either been sold or is sitting in deposit wallets ready to sell.”

Harmony later responded directly to the report, confirmed the exploit and said it was working with its team and relevant exchanges to stop and freeze the funds. The project is also developing a patch and evaluating whether a blockchain rollback could be used as part of the response.

Why Does The 4 Billion ONE Mint Matter?

An unauthorized token mint creates a different problem from a conventional wallet theft because it can expand the asset’s supply without removing coins from an existing holder. If the newly created tokens reach exchanges and are sold, existing investors face both additional selling pressure and dilution from units that were never intended to exist.

The reported movement of most of the 4 billion ONE tokens toward centralized exchanges makes the response from trading platforms especially important. Exchanges may be able to freeze deposits that have not yet been withdrawn or traded, but recovering tokens that have already been sold and transferred through multiple accounts can become much more difficult.

The price decline also leaves the dollar value of the exploit highly dependent on market conditions. At $0.0008 per ONE, the unauthorized issuance is worth about $3.2 million, but the value of any recoverable funds could change quickly as traders react to updates from Harmony and exchanges.

Harmony has not disclosed the technical root cause. Until it does, investors cannot determine whether the unauthorized mint resulted from a flaw in token issuance, validator behavior, network consensus or another part of the protocol.

Investor Takeaway

The immediate issue for ONE holders is not only the token price decline. Investors need to know how many unauthorized tokens remain transferable, how much supply has reached exchanges and whether Harmony can remove or neutralize the newly minted coins without creating further disruption to the network.

Could Harmony Roll Back The Blockchain?

Harmony’s decision to evaluate rollback options introduces another difficult choice. A rollback could potentially reverse transactions connected to the exploit, but changing blockchain history can affect users and exchanges that received tokens after the attack without knowing their origin.

The longer the unauthorized ONE circulates, the more complicated that option becomes. Tokens may have already been traded for other assets, transferred between accounts or incorporated into transactions involving users with no connection to the exploit.

A patch would address the vulnerability that allowed the attack, but it would not automatically resolve the status of the tokens already minted. Harmony therefore needs both a technical fix and a decision on how the additional supply will be treated.

Exchange cooperation could reduce the need for more disruptive action if enough of the tokens are still held in identifiable deposit accounts. Harmony said it is already working with relevant exchanges, but it has not disclosed how much of the reported 4 billion ONE has been frozen.

How Does The Attack Compare With Harmony’s 2022 Hack?

The latest incident is the second major security crisis associated with Harmony. In June 2022, attackers exploited the project’s Horizon cross-chain bridge and stole cryptocurrency worth nearly $100 million, including Ethereum and stablecoins.

Security researchers linked that breach to compromised control of the bridge’s multi-signature wallet. In January 2023, the FBI attributed the attack to North Korean state-backed hacking groups Lazarus Group and APT38.

The new exploit is different because it involves the reported creation of unauthorized ONE rather than the removal of assets locked in a bridge. Even so, another major security incident puts renewed attention on Harmony’s network controls and its ability to restore confidence among exchanges, validators and token holders.

Harmony launched its mainnet in 2019 as a proof-of-stake blockchain designed to offer faster and cheaper transactions than Ethereum. ONE is used for transaction fees, staking and governance, meaning uncertainty around its supply affects the asset at the center of the network’s economic model.

The next steps will depend on Harmony’s technical findings, the amount of ONE exchanges can freeze and whether the project proceeds with a rollback. Until those details are available, the circulating supply and final financial impact of the exploit remain uncertain.

You may also like