Harmony ONE drops 26% as exploit mints quarter of token supply
Harmony's native token plunged after an attacker inflated the supply by a quarter, forcing the layer-1 network to consider a controversial rollback that undermines blockchain immutability.
Harmony’s ONE token plummeted 26% in Asian trading on Wednesday after an apparent exploit allowed a malicious actor to mint 4 billion new tokens. The sudden inflation represents more than a quarter of the layer-1 blockchain’s existing supply of roughly 15 billion ONE.
The Harmony team confirmed the incident on social media and is coordinating with cryptocurrency exchanges to freeze the illicit funds. “We are working on a patch and rollback options,” the network stated. However, the team has not yet explained the exact vulnerability, how the 4 billion figure was calculated, or how far back any rollback would reach.
A rollback would effectively rewind the blockchain to a state prior to the attack, erasing the maliciously created tokens from the recognized ledger. While this could prevent the attacker from cashing out the newly minted assets, it becomes significantly more complex once funds cross over to external exchanges or other networks.
The prospect of a rollback presents a fundamental dilemma for investors and market professionals. Reversing the ledger to neutralize an attack inherently means undoing legitimate user transactions that occurred in the interim, a practice many in the industry view as antithetical to blockchain’s core principle of immutability.
This dilemma is not isolated. A day earlier, Ravencoin miners initiated a similar chain rebuild after parts of their network accepted invalid blocks, putting several days of user transactions at risk of reversal. The back-to-back incidents highlight the fragile security trade-offs smaller networks make when confronting severe exploits.
For Harmony, this marks the second time in roughly a year that unauthorized token creation has disrupted its network. In December 2023, a staking system bug improperly generated 146.3 million ONE across 74 addresses, with one address alone receiving 51.2 million tokens. The network responded at the time with an emergency software update and blacklisted the offending addresses after about 16.4 million of the minted tokens were moved to an exchange.
The network has also previously suffered catastrophic security failures. In 2022, attackers compromised private keys to steal $100 million from its Horizon bridge, an attack later attributed by the FBI to North Korea’s Lazarus Group.
Unlike the 2022 bridge theft, Wednesday’s incident involved the direct manipulation of ONE’s native supply on its own blockchain. Until Harmony finalizes its response, users and exchanges face lingering uncertainty over the finality of their recent transactions.