Harmony Investigates an Unauthorized 4 Billion ONE Mint and Weighs a Rollback
The network is trying to freeze funds and prepare a patch after an apparent exploit created tokens equal to roughly a quarter of supply, sending ONE to a record low.
Harmony is investigating an apparent exploit that created roughly 4 billion ONE tokens without authorization, an amount equal to about 26% of the network's reported supply. The team said it was working with exchanges to halt and freeze funds, preparing a security patch and evaluating whether recent chain history should be rolled back.
The market response was immediate. ONE fell sharply to a record low as traders tried to price both the new supply and the possibility that transactions could be reversed. An unauthorized mint is especially damaging because the attacker does not merely remove assets from a bounded pool. The exploit changes the monetary state of the network by creating balances that should not exist.
The first operational priority is containment. Exchanges can identify addresses associated with the incident, stop deposits and withdrawals, and prevent newly minted tokens from being converted into other assets. Those measures can limit losses, but they depend on fast coordination and do not repair the underlying vulnerability. A patch must identify the compromised component and prevent further issuance without introducing a new consensus split.
The rollback question is more difficult. Reorganizing the chain could remove the attacker's transactions, but it would also affect legitimate transfers completed after the chosen rollback point. Exchanges, bridges and decentralized applications may already have accepted those transactions as final. Reversal can therefore create losses for counterparties that acted honestly and undermine confidence in the chain's settlement guarantees.
Harmony must also establish what happened before stakeholders can assess the remedy. Early reports describe unauthorized minting, but the project had not yet published a full technical post-mortem within the research window. Important unanswered questions include which contract or privileged key was compromised, when the vulnerability entered the code, how much value left the network and whether related bridges or validators remain at risk.
The incident lands on a network with difficult security history. Harmony's Horizon Bridge lost about $100 million in 2022 in an attack later linked by authorities and researchers to North Korean actors. That earlier event already damaged confidence and prompted debates over reimbursement. A new failure makes transparent disclosure and independent verification essential.
For holders, supply inflation and exchange suspensions can impair liquidity even if funds are eventually recovered. For applications, uncertainty about finality can disrupt collateral calculations and settlements. For validators and developers, a rollback forces a governance decision about whether preserving ledger immutability is more important than reversing an exceptional exploit.
The wider lesson concerns administrative power. Networks that include upgrade keys, minting roles or emergency controls can respond quickly to bugs, but those same privileges become high-value attack surfaces. Security reviews need to map not only smart-contract logic but also who can change supply, pause transfers, upgrade contracts and authorize bridge messages.
Why it matters
The reported mint is large enough to alter Harmony's supply and threaten confidence in transaction finality. The response will show whether the network can coordinate exchanges, validators and developers without creating a second crisis through an unclear rollback.
The facts remain incomplete. The 4 billion figure and containment steps are based on the project's initial notice and early reporting. Until Harmony publishes a technical post-mortem and verifiable accounting, the attack path, realized losses and final remedy should be treated as unconfirmed.