• 5 mins read
  • Published

Harmony Considers Blockchain Rollback After Billions in ONE Minted Illegally

Catheryne Nicholson Crypto infrastructure writer EgonCoin

Post by Catheryne Nicholson

Harmony Considers Blockchain Rollback After Billions in ONE Minted Illegally EgonCoin © egoncoin.com
Harmony Considers Blockchain Rollback After Billions in ONE Minted Illegally © egoncoin.com

Harmony has halted further unauthorized minting of its ONE token after a protocol flaw allowed billions to be created and sent to exchanges, but the fate of the excess supply and possible transaction rollback remains unresolved

Harmony, a layer-1 blockchain network, is facing a major supply crisis after a protocol vulnerability enabled the unauthorized creation of billions of its native ONE tokens. The project has released an emergency patch to block further minting, but the status of the excess tokens already in circulation-and whether the network will attempt a full blockchain rollback-remains uncertain.

Emergency Patch and Ongoing Risks

On August 12, Harmony instructed validators to install version v2026.1.1, a software update designed to close two critical flaws in the network's cross-shard receipt system. According to Harmony, these vulnerabilities allowed attackers to bypass signature checks and replay transaction receipts, resulting in the creation of new ONE tokens without proper authorization. While the patch is now live and further unauthorized minting is reportedly blocked, Harmony has not confirmed the total number of tokens created or the full extent of the impact.

Independent on-chain researcher Juiceberg estimated that approximately 4 billion ONE tokens-about 26% of the previously reported supply-were minted through the exploit, with 2.8 billion reaching exchanges. Harmony has not independently verified these figures. The project has published wallet addresses believed to be involved and asked exchanges to freeze any traceable funds, but has not disclosed which venues have complied or how much has been recovered.

Technical Details of the Exploit

The vulnerabilities exploited involved how Harmony's protocol verified cross-shard receipts, which are used to transfer transaction results between different parts of the network. One flaw allowed an empty signer record and a mathematically neutral aggregate signature to pass quorum checks, letting unauthorized receipts be accepted. Another flaw allowed attackers to modify certain proof fields, making previously spent receipts appear new and enabling double-crediting of tokens.

The emergency patch changes how the network calculates quorum and ties the spent marker to authenticated block header data, closing both attack vectors. Harmony also paused its bridge.harmony.one service as a precaution, though it has not confirmed whether the bridge itself was the source of the exploit. The incident is technically distinct from Harmony's June 2022 Horizon bridge exploit, which involved compromised multisignature controls and resulted in $100 million in stolen assets.

Rollback Under Consideration

Harmony has stated that it is considering a full blockchain rollback to address the unauthorized supply, but has not committed to this course of action or specified a potential rollback point. A rollback would involve reversing transactions to a previous state, potentially impacting users, exchanges, and applications that interacted with the network after the exploit. The project's initial response emphasized that all options remain on the table as it works with validators and exchanges to contain the fallout.

The situation highlights the risks of protocol-level vulnerabilities in blockchain networks, especially when flaws affect token supply mechanisms. As Harmony weighs its next steps, the broader crypto community is watching closely for precedent on how layer-1 networks may respond to large-scale unauthorized minting events. For context, recent protocol proposals in other networks, such as Ethereum's consideration of changes to staking rewards, have also raised questions about how core blockchain rules can be adapted in response to evolving threats and market pressures. Readers interested in how protocol-level changes can affect token economics may find additional perspective in EgonCoin's coverage of Ethereum's proposal to phase out native staking rewards for large holders.

According to public blockchain data, Harmony's circulating supply of ONE prior to the incident was estimated at roughly 15.5 billion tokens. The addition of up to 4 billion unauthorized tokens, if confirmed, would represent a sudden increase of more than 25% in supply. The price of ONE has experienced heightened volatility since the exploit, with trading activity concentrated on exchanges where the excess tokens may have been deposited. As of August 2026, Harmony has not published a final incident report or confirmed the total amount of frozen or recovered funds.

Protocol-level exploits that affect token supply present unique challenges for blockchain governance and user trust. Unlike smart-contract vulnerabilities, which can often be isolated to a single application, flaws in core network logic can undermine the integrity of the entire system. Rollbacks are controversial because they can reverse legitimate user transactions and disrupt downstream applications, but may be considered when the alternative is permanent dilution or loss of confidence in the network's token. The Harmony incident underscores the importance of robust protocol design, timely patching, and transparent communication with stakeholders when critical vulnerabilities are discovered.

Related articles