Harmony weighs a full blockchain rollback after unauthorized minting floods exchanges with billions in ONE
Harmony, the layer-1 blockchain network, has released an emergency validator patch that it says prevents further unauthorized minting of ONE, its native token. The project said it will address tokens already created in a...
Watchlist
Published in the last two hours. Multiple named entities are involved.
Harmony, the layer-1 blockchain network, has released an emergency validator patch that it says prevents further unauthorized minting of ONE, its native token. The project said it will address tokens already created in a later update, leaving their number and ultimate treatment unresolved.
Harmony told validators to install v2026.1.1 on Aug. 12. The notice confirms that minting occurred but does not disclose the amount.
Onchain researcher Juiceberg estimated that roughly 4 billion ONE, equal to about 26% of the supply figure used in the post, had been minted without authorization. Juiceberg also estimated that 2.8 billion ONE had reached exchanges. Harmony has not independently confirmed those figures.
Related Reading Polkadot Hyperbridge April Fools’ joke comes true as over 1 Billion fake DOT tokens were minted on Ethereum A proof replay bug let the attacker mint over $1 billion DOT tokens on Ethereum, yet shallow DOT pools capped the cashout near $240,000. Apr 13, 2026 · Oluwapelumi Adejumo How the patch blocks more mintingHarmony's published code changes address two weaknesses in cross-shard receipts, which carry transaction results between parts of the network.
One flaw allowed an empty signer record and a mathematically neutral aggregate signature to pass a quorum check. The verifier counted the full committee instead of the validators represented in the signer record, allowing a receipt to be accepted without the required approvals.
The second flaw affected how the network recorded that a receipt had already been spent. Some proof fields were not bound to the signed block header, so changing those fields could make a previously processed receipt appear new. The destination could then be credited again without a corresponding debit from the source.
Related Reading Crypto users told to pull funds after Ethereum L2 bridge failure exposes rollup exit risk The incident forced users to confront the part of rollup security that usually stays invisible: whether they can still withdraw when the bridge layer breaks. Jun 23, 2026 · Liam 'Akiba' WrightThe signed v2026.1.1 release changes the quorum calculation and ties the spent marker to authenticated header data, closing both paths described in the patch.
Harmony also paused bridge.harmony.one during the response, although its notice did not identify the bridge as the exploited component. The project published four implicated wallet addresses and asked exchanges to block and freeze traceable funds, without naming the venues or disclosing how much had been frozen.
Harmony's initial response said rollback options were under consideration. The project has not announced that a rollback will occur or specified the point from which transactions could be reversed.
The incident differs technically from the June 2022 Horizon bridge exploit, which involved compromised multisig control and about $100 million in stolen assets. The current patch instead addresses receipt verification and replay at the protocol level.
Related Reading North Korea’s Lazarus Group linked to $100M Harmony exploit Elliptics says the strategies employed for the Harmony exploit are consistent with the ones used for the Ronin Bridge exploit a few months ago. Jun 30, 2022 · Oluwapelumi AdejumoHarmony says further minting is now blocked. The remaining risk centers on the size and location of the ONE already created, how much exchanges can freeze, and whether the network will attempt a rollback to remove the excess supply.
The post Harmony weighs a full blockchain rollback after unauthorized minting floods exchanges with billions in ONE appeared first on CryptoSlate.
Why this matters
Ethereum is showing up inside the Security Incidents theme, so this story is worth tracking for follow-through rather than treating it as a one-off headline.
Original source
Read on CryptoSlateRelated market context
BTCPay Server Patches Critical LND Credential Bug After Lightning Wallet Drain
BTCPay Server has released version 2.4.2 to patch a critical vulnerability that allowed unauthenticated remote access to LND crede...
Strategy’s $4.6 billion cash buffer gives it almost 3 years before Bitcoin sales create real stress
Strategy said it held 840,447 BTC as of Aug. 9 and has begun treating its Bitcoin reserve as a source of balance-sheet flexibility...
Franklin Crypto CIO Says Ethereum’s Yield-Cut Plan Is “a Solution Looking for a Problem”
The chief investment officer of Franklin Crypto has come out against a proposal to slash Ethereum’s staking rewards, saying he see...
BitMine Pushes Ethereum Treasury Past 5.8M ETH
BitMine Immersion Technologies has added another 7,391 ETH to its balance sheet, pushing its Ethereum treasury to about 5.81 milli...
SharpLink Reports $394M Q2 Loss As Ethereum Revaluation Hits Results
SharpLink reported a $394.3 million net loss for the second quarter of 2026, with the result driven largely by non-cash Ethereum r...
Trump Media’s 14,139 Bitcoin stash faces options exposure and a looming $1 billion debt test
Trump Media's second-quarter results have drawn attention for a $238.1 million loss and a Bitcoin treasury that expanded to 14,139...