Harmony weighs a full blockchain rollback after unauthorized minting floods exchanges with billions in ONE

A math flaw let attackers mint 4 billion ONE out of thin air - and 2.8 billion already reached exchanges

Editorial collage of a fractured Harmony ONE token with emergency patch notes, exchange freezes, and disputed unauthorized minting estimates.
Image by CryptoSlate
2 min read

Quick Take

  1. Validator release v2026.1.1 closes two receipt flaws that could let a receipt be accepted without required approvals.
  2. Juiceberg estimated roughly 4 billion ONE were minted and 2.8 billion reached exchanges; Harmony has not confirmed it.
  3. The size of the excess supply, funds exchanges can freeze, and any rollback remain unresolved.

Harmony, the layer-1 blockchain network, has released an emergency validator patch that it says prevents further unauthorized minting of ONE, its native token. The project said it will address tokens already created in a later update, leaving their number and ultimate treatment unresolved.

Harmony told validators to install v2026.1.1 on Aug. 12. The notice confirms that minting occurred but does not disclose the amount.

Onchain researcher Juiceberg estimated that roughly 4 billion ONE, equal to about 26% of the supply figure used in the post, had been minted without authorization. Juiceberg also estimated that 2.8 billion ONE had reached exchanges. Harmony has not independently confirmed those figures.

Polkadot Hyperbridge April Fools’ joke comes true as over 1 Billion fake DOT tokens were minted on Ethereum
Related Reading

Polkadot Hyperbridge April Fools’ joke comes true as over 1 Billion fake DOT tokens were minted on Ethereum

A proof replay bug let the attacker mint over $1 billion DOT tokens on Ethereum, yet shallow DOT pools capped the cashout near $240,000.
Apr 13, 2026 · Oluwapelumi Adejumo

How the patch blocks more minting

Harmony's published code changes address two weaknesses in cross-shard receipts, which carry transaction results between parts of the network.

One flaw allowed an empty signer record and a mathematically neutral aggregate signature to pass a quorum check. The verifier counted the full committee instead of the validators represented in the signer record, allowing a receipt to be accepted without the required approvals.

The second flaw affected how the network recorded that a receipt had already been spent. Some proof fields were not bound to the signed block header, so changing those fields could make a previously processed receipt appear new. The destination could then be credited again without a corresponding debit from the source.

Crypto users told to pull funds after Ethereum L2 bridge failure exposes rollup exit risk
Related Reading

Crypto users told to pull funds after Ethereum L2 bridge failure exposes rollup exit risk

The incident forced users to confront the part of rollup security that usually stays invisible: whether they can still withdraw when the bridge layer breaks.
Jun 23, 2026 · Liam 'Akiba' Wright

The signed v2026.1.1 release changes the quorum calculation and ties the spent marker to authenticated header data, closing both paths described in the patch.

CryptoSlate Daily Brief

Daily signals, zero noise.

Market-moving headlines and context delivered every morning in one tight read.

5-minute digest 100k+ readers

Free. No spam. Unsubscribe any time.

You’re subscribed. Welcome aboard.

Harmony also paused bridge.harmony.one during the response, although its notice did not identify the bridge as the exploited component. The project published four implicated wallet addresses and asked exchanges to block and freeze traceable funds, without naming the venues or disclosing how much had been frozen.

Harmony's initial response said rollback options were under consideration. The project has not announced that a rollback will occur or specified the point from which transactions could be reversed.

The incident differs technically from the June 2022 Horizon bridge exploit, which involved compromised multisig control and about $100 million in stolen assets. The current patch instead addresses receipt verification and replay at the protocol level.

North Korea’s Lazarus Group linked to $100M Harmony exploit
Related Reading

North Korea’s Lazarus Group linked to $100M Harmony exploit

Elliptics says the strategies employed for the Harmony exploit are consistent with the ones used for the Ronin Bridge exploit a few months ago.
Jun 30, 2022 · Oluwapelumi Adejumo

Harmony says further minting is now blocked. The remaining risk centers on the size and location of the ONE already created, how much exchanges can freeze, and whether the network will attempt a rollback to remove the excess supply.

$0.00076 -38.53% 24 hour change
1H +0.89% 24H -38.53% 7D -38.17%
30D -34.02% 60D -49.75% 90D -67.30%

Harmony is -38.53% over the past 24 hours and currently sits at rank #846 by market cap.

Market cap $11.35M
Volume (24h) $59.96M +4,765.33%
Circ. supply 15.01B
FDV $11.35M
Crypto Market Summary

Where the broader market sits right now

Right now, the total crypto market is valued at $2.19T with $56.6B in 24-hour volume. Bitcoin dominance sits at 58.55%. Explore the market

Global market cap $2.19T
24H market volume $56.6B
Bitcoin dominance 58.55%