Harmony mulls blockchain rollback after exploit inflates ONE supply
A suspected exploit that inflated the circulating supply of ONE tokens by roughly a quarter has forced the Harmony network to consider a rare blockchain rollback, underscoring the severe governance and valuation risks inherent in layer-1 digital assets.
Harmony is evaluating a rollback of its blockchain following a suspected exploit that drastically inflated the supply of its native ONE token. The layer-1 network stated it is preparing a software patch and coordinating with trading platforms to freeze illicit funds while it assesses its options.
The crisis stems from allegations that an attacker manipulated the network to mint nearly 4 billion unauthorized ONE tokens. This unauthorized creation represents approximately 26 percent of the token’s total circulating supply, severely diluting existing holdings.
The sudden expansion of supply triggered an immediate repricing of the asset in secondary markets. Trading data indicates the token fell 33.9 percent over a 24-hour period as the unauthorized coins entered circulation.
Independent analysis from an observer known as Juiceberg suggests the unauthorized tokens were generated through the creation of empty blocks. According to these estimates, roughly 2.8 billion of the newly minted coins were rapidly funneled to exchanges to be liquidated.
The same analysis indicates the attacker retained about 115 million ONE tokens on the network, which accounts for 2.9 percent of the allegedly minted amount. The remainder of the supply was either sold into the market or parked in exchange deposit wallets.
Harmony has not officially confirmed the exact mechanics of the breach, the precise number of tokens created, or the total volume transferred to exchanges. However, the mere consideration of a rollback presents a profound governance dilemma for the network and its institutional investors.
Reversing blockchain transactions contradicts the core immutability promise of decentralized ledger technology. For market professionals, such interventions introduce significant settlement risk and uncertainty regarding the finality of trades executed on the platform.
This incident compounds existing security concerns surrounding the network's infrastructure. The protocol previously suffered a massive breach in June 2022 when its Horizon Bridge was compromised, resulting in the theft of about $100 million in cryptocurrency.
Federal authorities later attributed that specific attack to the Lazarus Group, a state-sponsored cyber syndicate based in North Korea. Recurring vulnerabilities of this scale force asset managers to apply steep risk premiums to layer-1 tokens lacking robust security architectures.