Security 5 min read

4 Billion Tokens Minted From Nothing: What the Harmony ONE Exploit Teaches Every Crypto User

A math flaw in cross-shard receipt validation let attackers mint 4 billion ONE tokens — 26% of the total supply. Exchanges froze 2.8 billion. The blockchain is now weighing a full rollback. Here is what went wrong.

Blockchain security incident 4B ACM77 Insights · Security
Key facts
  • Harmony released emergency patch v2026.1.1 on Aug 12, stopping further unauthorized minting
  • Onchain researcher Juiceberg estimated ~4 billion ONE minted (26% of supply), 2.8 billion reached exchanges
  • Two flaws in cross-shard receipt validation: empty signer record and unbound proof fields
  • Harmony has not confirmed the figures independently
01

What happened

On August 12, 2026, Harmony released an emergency validator patch (v2026.1.1) to halt ongoing unauthorized minting of ONE, its native token. The attack exploited a flaw in how Harmony's layer-1 blockchain validates cross-shard receipts — the data structures that carry transaction results between network shards.

Onchain researcher Juiceberg estimated that approximately 4 billion ONE tokens were minted without authorization, representing roughly 26% of the token supply figure used in public reporting. Of that, an estimated 2.8 billion tokens had already reached exchanges before freezes were implemented. Harmony has not independently confirmed these figures.

The project confirmed minting occurred but has not disclosed the total amount. A statement said it would address already-minted tokens "in a later update," leaving the ultimate treatment of excess tokens and the question of a rollback open.

02

Two flaws in cross-shard receipt validation

Harmony published the code changes for v2026.1.1. The patch addresses two distinct weaknesses in how the network processed cross-shard receipts.

Flaw 1: Empty signer record with neutral aggregate signature. One vulnerability allowed an empty signer record combined with a mathematically neutral aggregate signature to pass the quorum verification. Instead of counting only validators represented in the signer record, the verifier counted the full committee. This meant a receipt could be accepted without the required number of actual approvals from validators.

Flaw 2: Unbound proof fields enabling double-credit. The second flaw affected how the network recorded that a receipt had already been spent. Some proof fields were not bound to the signed block header — meaning those fields could be changed after signing. An attacker could make a previously processed receipt appear as new, crediting the destination address again without a corresponding debit from the source.

Both flaws operate at the consensus layer, not in a user-facing smart contract. That means no amount of checking token approvals in a wallet could have prevented this particular class of attack. The vulnerability existed in how nodes verified inter-shard communication.

03

How exchanges responded

Once the unauthorized minting became visible onchain, exchanges began freezing accounts holding the suspected excess ONE tokens. The freeze targeted tokens that had moved from the attacker addresses to exchange deposit wallets, following standard anti-money laundering logic: if tokens cannot be proven to originate from legitimate transactions, they are treated as potentially fraudulent.

The freeze is not a guaranteed outcome. Whether exchanges can actually claw back funds depends on whether the tokens were already traded for other assets. In many cases, once illicit tokens are exchanged for clean ones, the trail becomes legally and technically complex.

Exchange freezes are a reactive measure. They reduce immediate damage but do not fix the underlying vulnerability or restore tokens that were already exchanged and withdrawn.

04

The rollback question

Harmony has not ruled out a full blockchain rollback — a mechanism that would effectively re-execute the chain from a block before the exploit occurred, discarding all transactions after that point including legitimate ones. Rollbacks are politically and technically controversial: they undo valid transactions, raise questions about decentralization guarantees, and set precedents for future interventions.

Whether to rollback is ultimately a governance decision for the Harmony network's validators and community. From a user perspective, a rollback means transactions that appeared confirmed could disappear. Deposits, trades, and withdrawals that happened after the exploit block could be reversed.

The alternative — accepting the excess supply — means ONE tokenholders hold assets that were created outside the protocol's rules, potentially diluting the value of legitimate tokens. Neither option is clean.

05

What this means for every crypto user

Incidents like the Harmony ONE exploit are not abstract. They have direct implications for community managers, Telegram group admins, Discord moderators, and content creators who advise others on crypto platforms.

Smart contract audits are necessary but not sufficient. This exploit was not a bug in a smart contract's token logic — it was a flaw in the blockchain's core consensus layer. Even projects with clean audits from reputable firms can have vulnerabilities at deeper levels that only show up in production under specific conditions.

Cross-chain bridges and cross-shard mechanisms carry elevated risk. The complexity of inter-chain and inter-shard communication creates attack surface that single-chain protocols do not have. Each additional handoff between systems multiplies the places where something can go wrong.

Not your keys not your coins applies to more than just custody. While the saying is usually about self-custody versus exchange custody, this incident adds another layer: even tokens held in a legitimate wallet are ultimately backed by the security guarantees of the underlying blockchain. If those guarantees fail at the protocol level, tokens in your wallet can be diluted or rendered unreliable.

Community managers should know the incident facts before they are asked about them. When exploits happen, Telegram groups and Discord servers fill with speculation, panic, and misinformation within hours. Community leaders who can explain what actually happened — not what rumors claim — provide real value to their members.

06

Common questions

Could a wallet check have prevented this?
No. The vulnerability was in blockchain consensus, not in token contract logic. User-side checks like approving only specific token amounts do not protect against protocol-layer exploits.
Are my ONE tokens safe if I hold them in my own wallet?
Your tokens exist on a blockchain that has had its supply integrity compromised. Whether this matters depends on how Harmony resolves the incident. A rollback could undo recent transfers; acceptance of excess supply could dilute value. Monitor official announcements from the Harmony team.
Does this affect other layer-1 blockchains?
Each blockchain has its own implementation of cross-shard or cross-chain messaging. The specific flaws in Harmony's code are unique to that protocol. However, the incident highlights that consensus-layer vulnerabilities are an industry-wide concern and are typically found through real-world usage rather than in test environments.
Where can I follow official updates?
Harmony's official channels are the primary source. Be cautious of social media posts claiming to have definitive information immediately after an incident — initial estimates are often revised.
Published byACM77 InsightsEnglish edition

Educational content about Bitcoin, cloud-mining infrastructure, blockchain systems and safer digital-asset habits.

Explore ACM77

Move from learning to the official platform pages.

Compare product information, review common questions or access the ACM77 mobile APP.

Compare plans Read the FAQ