Skip to content
Est. MMXXVIVol. VI · № 321RSS
Blockchain Breaches

An archive of cryptocurrency security incidents — hacks, exploits, bridge failures and rug pulls, documented with on-chain evidence.

Dossier № 319Other

Harmony Unauthorized ONE Minting

An attacker exploited a flaw in Harmony's block-production logic to mint roughly 4 billion unauthorized ONE tokens, worth about $3.2 million, and dumped most of them onto exchanges.

Date
Victim
Harmony
Chain(s)
Status
Status Unknown

On August 12, 2026, layer-1 network Harmony confirmed it had been exploited after an attacker minted roughly 4 billion unauthorized ONE tokens — about 26% of the circulating supply — worth approximately $3.2 million at the time. The token fell about 37% to near $0.0008 on the news, and roughly 97% of the freshly minted ONE was routed straight to exchanges for sale before the team could respond.

What happened

The exploit did not touch a smart contract or a bridge; it abused Harmony's own block-production and consensus logic. According to security researchers, a quorum-verification bug counted the public keys listed in a signature mask rather than the validators that had actually signed, so blocks carrying no valid signatures could still clear the quorum threshold. The attacker used this to push "empty block" transactions that minted ONE out of thin air. Compounding the damage, Harmony's totalSupply endpoint did not reflect the new tokens, so explorers and dashboards kept displaying the pre-exploit supply — a supply-masking effect — even as the counterfeit ONE moved on-chain and onto trading venues.

Aftermath

Harmony shipped a fix in mainnet release v2026.1.1 (merge commit e9a05f6b68f0), deployed at 06:30 UTC on August 12; once enough validators upgraded, further unauthorized minting was blocked. The team said it was coordinating with exchanges to freeze the offloaded tokens and, in September 2026, moved to roll the chain back to its August 11 state, discarding more than 109,000 regular transactions and 315 staking transactions to void the forged supply. Because the attacker had already dumped the bulk of the counterfeit ONE onto exchanges before the rollback, the net recovery remains unsettled, so the status here is left unknown.

Why it matters

Harmony had already suffered one of crypto's most infamous incidents — the $100M Horizon bridge theft attributed to North Korea's Lazarus Group in 2022 — and this second event struck at an even more fundamental layer: the chain's consensus itself. Unauthorized-mint bugs in base-layer code are especially corrosive because they debase every holder at once rather than draining a single pool, and a chain-wide rollback is a blunt, trust-eroding remedy that discards legitimate user activity alongside the attacker's. The episode is a reminder that quorum and signature-verification logic is as security-critical as any lending or bridge contract, and that on-chain supply endpoints can be gamed to delay detection while an attacker exits.

Sources & on-chain evidence

  1. [01]theblock.cohttps://www.theblock.co/news/defi/2026-08-12-harmony-confirms-exploit-one-token-411527
  2. [02]coindesk.comhttps://www.coindesk.com/markets/2026/08/12/harmony-s-one-falls-26-after-attacker-allegedly-mints-4-billion-tokens
  3. [03]halborn.comhttps://www.halborn.com/blog/post/explained-the-harmony-hack-august-2026
  4. [04]cryptorank.iohttps://cryptorank.io/news/feed/36e8b-harmony-blockchain-rollback-counterfeit-one-attack

Related filings