An attacker minted approximately 4 billion ONE tokens on August 12, 2026, inflating Harmony's circulating supply by roughly 26% in a single transaction burst. The exploit leveraged two previously undisclosed flaws in Harmony's consensus verification — a pre-staking quorum bypass and a cross-shard...
"Harmony took advantage of people who assisted during the $100M Harmony Bridge exploit by DPRK in 2022 and rewarded $0 for significant freezes which lead to LE seizures and simply said 'good job'." — ZachXBT, On-Chain Investigator
An attacker minted approximately 4 billion ONE tokens on August 12, 2026, inflating Harmony's circulating supply by roughly 26% in a single transaction burst. The exploit leveraged two previously undisclosed flaws in Harmony's consensus verification — a pre-staking quorum bypass and a cross-shard receipt replay vulnerability — allowing unauthorized token creation through empty blocks. Harmony's own totalSupply API endpoint failed to reflect the inflated supply, masking the exploit long enough for 2.8 billion ONE (70% of the minted tokens) to reach centralized exchanges before any freeze response.
ONE fell to an all-time low of $0.0005735, a decline exceeding 37% within hours, pushing the project's market capitalization below $13 million. Harmony released emergency validator patch v2026.1.1, paused the Horizon bridge, asked exchanges to freeze four attacker wallets, and began evaluating a full blockchain rollback — a measure that would reverse all legitimate transactions processed after the exploit. The incident marks Harmony's second major security failure after the $100 million Horizon Bridge hack in June 2022, which the FBI attributed to North Korea's Lazarus Group.
The attack exploited two distinct flaws in Harmony's consensus layer, both patched in validator release v2026.1.1:
Pre-staking quorum bypass. Harmony's verifier compared the full committee size against the threshold but did not count which validators were actually enabled in the signer bitmap. An all-zero bitmap combined with an all-zero identity aggregate BLS signature could satisfy quorum for pre-staking-epoch committees. This allowed the attacker to produce blocks that appeared valid but had no genuine validator signatures.
Cross-shard receipt replay. The second flaw concerned cross-shard receipts — records used to credit assets arriving from another Harmony shard. For receipts from older epochs, the marker indicating a receipt had already been spent relied on proof fields that were not authenticated against the signed block header. A genuine, already-applied receipt could be resubmitted with changed proof identifiers, crediting assets multiple times.
The attacker minted roughly 4 billion ONE tokens through empty blocks — blocks containing no standard transactions, only the consensus-layer operations needed to generate new tokens. According to on-chain analysis shared by blockchain researcher Juiceberg, the minting occurred in rapid succession before the fraudulent tokens were distributed across 409 wallets through 10,288 transfers.
A compounding failure made the exploit substantially worse. Harmony's totalSupply API endpoint did not reflect the newly minted tokens. Third-party data aggregators — CoinGecko, CoinMarketCap, and exchange compliance dashboards — rely on this endpoint to calculate circulating supply and market capitalization. With the supply figure unchanged, the inflated tokens appeared indistinguishable from legitimate circulating supply.
According to TechTimes, 97% of fraudulently minted tokens reached exchanges before any freeze response was initiated. By the time the exploit became public, only approximately 115 million ONE — under 3% of the minted total — remained in the attacker's wallets. The remaining 2.8 billion ONE had already been deposited on centralized exchanges where they could be sold directly into order books.
This represents a failure not only of consensus security but of on-chain accounting transparency. The totalSupply endpoint functioned as a de facto camouflage layer, buying the attacker critical time.
The sell pressure from 2.8 billion newly minted ONE tokens hitting exchange order books produced immediate results:
For context, ONE's all-time high was $0.38 in January 2022. The token had already lost more than 99% of its value before this exploit.
Harmony's response unfolded in stages:
Validator patch v2026.1.1 — Released within hours, the signed patch closes both the quorum calculation flaw and the receipt replay vulnerability. The quorum fix ensures the verifier counts actual enabled validators in the signer bitmap rather than comparing against the full committee size. The receipt fix ties the spent marker to authenticated header data.
Horizon bridge pause — The cross-chain bridge was paused to prevent further outflows.
Exchange coordination — Harmony identified four groups of attacker wallet addresses and requested exchanges freeze associated funds.
On-chain forensics — The team traced 10,288 transfers across 409 wallets, according to Crypto Briefing.
Harmony has not publicly disclosed the exact vulnerability path the attacker used to trigger the quorum bypass in a live production environment, stating only that the patch addresses the root causes.
Harmony is evaluating a full blockchain rollback — a measure that would revert the chain state to a point before the exploit. According to CryptoSlate, the team is weighing this option as part of its broader remediation strategy.
The trade-offs are substantial:
Arguments for rollback:
Arguments against:
The size of the excess supply, the volume exchanges can freeze, and the finality of any rollback remain unresolved as of publication.
The exploit triggered a notable refusal from ZachXBT, one of the most prominent on-chain investigators. ZachXBT publicly declined to assist Harmony and urged other researchers to avoid working on the case without compensation. His stated reason: after the 2022 Horizon Bridge hack attributed to North Korea's Lazarus Group, investigators who helped trace and freeze funds received no financial compensation from Harmony. According to ZachXBT's public statements, Harmony's response to significant investigative work that led to law enforcement seizures was to say "good job" and pay $0.
This refusal highlights a structural problem in crypto incident response. On-chain forensic investigators operate on a largely informal basis. Projects that fail to compensate investigators after major exploits lose access to the community's best forensic resources when the next incident occurs. Harmony's reputational deficit from 2022 is now producing measurable consequences in 2026.
This is Harmony's second major security failure in four years:
| Incident | Date | Loss | Attack Vector | Attribution | |---|---|---|---|---| | Horizon Bridge hack | June 2022 | $100M | 2-of-5 multisig compromise | Lazarus Group (FBI confirmed Jan 2023) | | ONE token mint exploit | August 2026 | ~$2.3M* (at post-exploit prices) | Consensus quorum bypass + receipt replay | Unknown |
*The dollar value of the 2026 exploit is difficult to calculate precisely because the minted tokens themselves caused the price collapse. At pre-exploit prices (~$0.001), 4 billion ONE would have been worth approximately $4 million. At the post-exploit low ($0.0005735), the total minted supply was worth roughly $2.3 million. The economic damage to existing holders through dilution was substantially larger.
After the 2022 hack, Harmony offered a $1 million bounty for the return of funds. The stolen assets — including WETH, SUSHI, AAVE, DAI, USDT, and USDC — were swapped for Ether and laundered through Tornado Cash. None were recovered through the bounty.
The 2026 exploit is technically distinct — it targeted the consensus layer rather than a bridge multisig — but both incidents point to persistent under-investment in security infrastructure for a protocol that once reached a $4.7 billion fully diluted valuation.
The Harmony exploit adds to a pattern identified across the 2026 DeFi security landscape. According to CCN, more than $1 billion was lost to DeFi hacks during the first four months of 2026 alone. Three of the four largest incidents this year — including KelpDAO's $292 million exploit and Drift Protocol's $285 million heist — did not involve flawed smart contract code. The contracts executed as programmed; they received fraudulent instructions from compromised infrastructure layers.
Harmony's exploit follows this pattern. The consensus verification logic functioned as coded — it simply contained a logic error in how it counted validator signatures. The distinction matters because it suggests that auditing smart contracts alone is insufficient. Protocol-level consensus code, validator infrastructure, and supply-reporting APIs all represent attack surfaces that receive less systematic scrutiny.
For protocols with low validator counts, limited active development teams, or aging codebases, the Harmony incident serves as a case study in compounding risk: a small validator set makes quorum attacks feasible, limited engineering resources delay patch deployment, and an unmaintained supply API masks the attack during the critical response window.
Harmony's second major exploit in four years demonstrates the compounding cost of security underinvestment. The technical vulnerabilities — a quorum calculation error and an unauthenticated receipt marker — are individually straightforward. Their combined exploitation, masked by a supply-reporting endpoint that failed to reflect unauthorized minting, created a window in which the attacker liquidated the majority of fraudulent tokens before any response.
The pending rollback decision will define what remains of Harmony as a protocol. A rollback recovers the supply but fractures immutability guarantees and creates reconciliation problems with exchanges holding minted tokens. No rollback preserves chain integrity but leaves existing holders permanently diluted by 26%.
Neither outcome restores the project's depleted credibility. With a market capitalization below $13 million, an all-time-low token price, and its most experienced potential investigator publicly refusing to assist, Harmony faces an existential question that no validator patch can address.