An attacker minted roughly 4 billion ONE tokens on the Harmony blockchain without authorization, expanding the circulating supply by about 25% and sending the token's price down by as much as 34%. The Harmony team confirmed the breach on August 12, 2026, and is now weighing a network rollback to neutralize the damage.

Most of the illicit tokens, around 2.8 billion, were already moved to exchange deposit addresses before the team could act. ONE traded near $0.0008 at one point during the selloff. On-chain analysts estimate only 115 million ONE (about 2.9% of the minted total) remain in the attacker's wallet.
How the exploit worked
Industry observers say the attacker leveraged empty blocks in a way that bypassed standard verification checks. The network's supply-reporting mechanism failed to flag the expansion immediately, giving the attacker time to transfer tokens to exchanges.
Harmony's total circulating supply was estimated at around 15 billion ONE before the incident. Adding 4 billion tokens diluted every existing holder by roughly one-quarter in a matter of minutes.
Harmony's response
The team said it is working with exchanges to freeze affected funds and has paused the cross-chain bridge as a precaution. Validators have been urged to upgrade to a new software release designed to block further unauthorized minting.
A rollback remains under consideration. If executed, it would revert the blockchain to a pre-exploit state, effectively erasing any tokens the attacker still holds on-chain. That would not recover tokens already sold on exchanges, however.
Not Harmony's first security incident
This is the third major security event for the layer-1 network in four years. In 2022, its Horizon bridge lost assets worth nearly $100 million. In late 2023, a staking-logic bug allowed tens of millions of extra ONE tokens to be created before an emergency patch was deployed.
A pattern of exploits raises hard questions about the network's code-review and audit processes. Fintech teams evaluating Harmony as a settlement or bridging layer should factor in this track record.
Logicity's Take
Three supply-inflating incidents in four years is an unusually rough record for any layer-1. The rollback option, if taken, would restore on-chain balances but cannot claw back tokens already dumped on exchanges. For treasury teams holding ONE or building on Harmony, the immediate priority is confirming validator upgrades and pausing any automated bridge flows until the patch is fully audited.
What comes next
Harmony says a full technical post-mortem is underway. The team has not provided a timeline for the patch or a decision on whether to proceed with a rollback. Exchange operators have been asked to blacklist specific wallet addresses linked to the activity.
Whether the attacker can be identified or the funds recovered remains unclear. Until then, the price of ONE will likely stay volatile as the market prices in both dilution risk and the possibility of a supply reset.
Guidance on protecting digital assets and responding to breaches
Need Help Implementing This?
If your organization holds crypto assets or integrates with layer-1 networks like Harmony, Logicity can help you audit your exposure and build monitoring workflows. Get in touch for a free assessment.
Source: Crowdfund Insider
Huma Shazia
Senior AI & Tech Writer
Produced with AI assistance and reviewed by the Logicity editorial team. Learn more in our Editorial Policy.






