Advertisement

Harmony ONE Crashes 40% as Exploit Appears to Mint Tokens Worth a Quarter of Supply

Harmony’s ONE Falls 40% After Suspected Exploit Creates Billions of Tokens

Harmony’s ONE token plunged roughly 40% during Asian trading Wednesday after an apparent exploit generated around 4 billion new tokens, representing more than 25% of the supply that existed before the attack.

Harmony confirmed the incident and said it is working with network validators on an emergency software update intended to prevent additional unauthorized token creation. The team is also assessing how to address the tokens that were already minted.

The project has temporarily halted its token bridge and requested that crypto exchanges freeze funds connected to four wallet addresses associated with the exploit.

Harmony said it is developing a software patch and examining potential rollback solutions. The network plans to provide further details as its investigation progresses.

Attack Adds About 26% to ONE Supply

Harmony is a layer-1 blockchain focused on decentralized finance applications and digital marketplaces. Its native ONE token is used to pay transaction fees and support network security.

The blockchain previously reached a market capitalization of about $4 billion in January 2022.

Approximately 15 billion ONE tokens were in existence before the latest incident. The creation of an additional 4 billion tokens would therefore represent a sudden supply increase of roughly 26%.

Such a sharp expansion in supply can create significant selling pressure, particularly if the newly issued tokens are moved to exchanges or sold on the market.

Rollback Could Reverse Exploit’s Impact

Harmony is also considering a potential rollback that would restore the blockchain to a point before the exploit occurred.

A rollback could remove transactions recorded after the attack and potentially prevent the attacker from retaining the newly generated tokens. However, the approach becomes more complicated if the affected assets have already been transferred to exchanges or other networks.

The proposal also raises concerns about blockchain immutability, one of the core principles underlying decentralized networks. Reversing legitimate transactions alongside malicious ones can create significant consequences for users who had nothing to do with the exploit.

The situation follows a separate incident involving Ravencoin, another smaller Bitcoin-derived blockchain, which faced a potential chain rollback after invalid blocks were accepted by portions of its network.

Ravencoin miners considered rebuilding the chain from before the problem occurred, potentially reversing several days of transactions. Although unrelated to Harmony, both incidents highlight the difficult balance between recovering from an attack and preserving legitimate blockchain activity.

Harmony Has Experienced Previous Token Issues

Harmony has faced unauthorized token creation before.

In December 2023, a staking-system bug caused approximately 146.3 million ONE to be issued after certain tokens continued receiving rewards despite no longer being eligible.

Harmony said 74 addresses were affected, with one wallet receiving roughly 51.2 million ONE. Around 16.4 million of the improperly created tokens were later transferred to an exchange.

The project responded by deploying an emergency software update and blacklisting wallets holding the affected tokens.

Harmony was also the victim of a major bridge exploit in 2022, when attackers stole approximately $100 million from its Horizon bridge after gaining control of private keys. The FBI subsequently attributed the attack to North Korea’s Lazarus Group.

The latest incident appears to be distinct from that attack because it involves the unauthorized creation of ONE directly on Harmony rather than the theft of existing assets from a bridge.

Harmony has not yet explained the precise method used to mint the additional tokens, confirmed the reported 4 billion figure or outlined a final plan for dealing with the tokens that have already been created.