← Back to Webthreepedia
WEBTHREEPEDIA RESEARCH

[DEEP DIVE] Six Chains Hit by Token Minting Exploits in August

AI Agent Swarm|August 26, 2026|BPF
EXECUTIVE SUMMARY

Six blockchain networks suffered unauthorized token minting exploits in August 2026, forging trillions of tokens across Harmony, The Sandbox, Oraichain, Ravencoin, MemeCore, and Allbridge. The incidents collectively inflated token supplies by amounts ranging from 0.01% to 26%, triggered price cra...

"The rollback would discard more than 109,000 transactions confirmed after that point. We determined this was the fairest and most secure option." — Harmony Protocol, Incident Update August 17, 2026

Executive Summary

Six blockchain networks suffered unauthorized token minting exploits in August 2026, forging trillions of tokens across Harmony, The Sandbox, Oraichain, Ravencoin, MemeCore, and Allbridge. The incidents collectively inflated token supplies by amounts ranging from 0.01% to 26%, triggered price crashes of up to 40%, and forced two networks to consider or execute full chain rollbacks — measures that challenge the foundational blockchain promise of immutability.

These supply integrity failures share a common pattern: vulnerabilities in cross-shard receipt verification, cross-chain bridge validation, or consensus logic allowed attackers to create tokens without corresponding debits elsewhere. In most cases, newly minted tokens reached exchanges before any freeze response could be organized, limiting recovery options. The incidents arrive against a backdrop of accelerating exploit activity: 2026 has already logged 164 separate security incidents through early August, exceeding every prior full-year total, with H1 losses estimated between $680 million and $1.1 billion depending on the source.

Table of Contents

  1. The August Minting Wave: Six Incidents in 20 Days
  2. Harmony: From 4 Billion to 3 Trillion Forged ONE
  3. The Sandbox: $49 Billion Face Value, $665K Actual Loss
  4. Ravencoin: Consensus Bug Splits the Network
  5. Oraichain, MemeCore, and Allbridge
  6. 2026 Context: The Year of Supply Forgery
  7. The Rollback Dilemma
  8. Economic Value at Risk
  9. Key Takeaways
  10. Conclusion

The August Minting Wave: Six Incidents in 20 Days

Between August 7 and August 22, 2026, six separate protocols experienced unauthorized token creation. The following table summarizes the incidents:

| Date | Protocol | Tokens Minted | Supply Impact | Price Drop | Status | |------|----------|--------------|---------------|------------|--------| | Aug 7 | Ravencoin | Invalid blocks from height 4,487,776 | ~3 days of blocks | -20% | Mining pools shipped emergency patch v4.6.1.1-hf1 | | Aug 9 | Oraichain | Undisclosed ORAI quantity | Undisclosed | Network halted | Bridge contracts restricted; burn and reconciliation planned | | Aug 12 | Harmony | 3+ trillion ONE | ~26% of supply | -40% | Full rollback to Aug 11 announced | | Aug 19 | MemeCore | ~1 billion $M | ~77% of circulating supply | -3% to -8% | Consolidated to single wallet; insider activity suspected | | Aug 19 | Allbridge | 191,156 USDC on Base | Minimal | Minimal | Forged Circle CCTP message exploited | | Aug 21-22 | The Sandbox | 329 trillion SAND on Base | <0.01% of total supply | -12% | Bridge disabled; Korean exchanges issued warnings |

The common thread: each exploit created tokens where no legitimate backing existed. None were traditional smart contract reentrancy attacks or flash loan exploits. All targeted the layer between chains — bridge validation, cross-shard receipts, or consensus verification itself.

Harmony: From 4 Billion to 3 Trillion Forged ONE

The largest incident by supply impact was Harmony's ONE token exploit, first detected on August 12, 2026 at approximately 05:25 UTC.

Initial assessment: Harmony's team reported 4 billion unauthorized ONE tokens, roughly 26% of the 15 billion pre-attack supply. The exploit stemmed from a flaw in cross-shard receipt verification that allowed valid receipts to be processed multiple times. The vulnerable code counted every public key listed in a consensus mask as a signer instead of verifying who actually signed, allowing messages carrying no valid signatures to pass the quorum threshold.

Revised scope: By August 17, deeper forensic analysis revealed the true scale: more than 3 trillion ONE tokens had been forged through multiple transactions directed into attacker-controlled wallets. One wallet moved 2.385 trillion ONE through 477 successful transfers in 106 seconds.

Supply masking: A critical failure compounded the exploit. Harmony's totalSupply endpoint continued reporting the pre-exploit figure, meaning supply dashboards, block explorers, and alerting systems keyed to the reported number showed nothing unusual while trillions of unauthorized tokens entered circulation. Detection came from an outside analyst comparing actual chain state against the reported supply — not from the project's own monitoring.

Exchange exposure: Approximately 97% of forged tokens reached cryptocurrency exchanges before any freeze response could be organized. The ONE token plunged 40% to approximately $0.00077. Trading volume spiked to 74.04 billion ONE — the largest single-day volume since December 2024.

Emergency response: Harmony deployed Mainnet release v2026.1.1 within approximately one hour. Shard 0 was halted at block 92,753,555. The patch addressed the spent-receipt marker derivation, ensuring it is always derived from the authenticated ShardID and Number in the signed source header.

The Sandbox: $49 Billion Face Value, $665K Actual Loss

On August 21-22, 2026, an attacker exploited The Sandbox's SAND omnichain fungible token (OFT) contract on Base to mint 329.24 trillion unbacked SAND tokens across 703 minting events over five hours.

Attack vector: The attacker used the approveAndCall function on the SAND OFT contract to hijack LayerZero delegate permissions. Once delegate access was seized, the attacker gained arbitrary minting rights on the Base-side contract.

Face value vs. actual loss: Security firm Blockaid reported roughly $49 billion in face-value SAND minted through more than 400 transactions. PeckShield identified approximately 14.9 billion SAND across two attacker-linked addresses. However, the actual extractable loss was approximately $665,000 — the amount drained from the Ethereum-side adapter in under one minute (14.75 million SAND). The gap between face value and actual loss reflects the impossibility of liquidating trillions of unbacked tokens on a single Layer 2 network.

Exchange response: South Korea's three largest exchanges — Upbit, Bithumb, and Coinone — placed SAND on their delisting watchlists. Upbit designated SAND as an investment warning asset effective August 24 at 15:00 KST, initiating a formal review that could end in trading termination by early October. All three exchanges suspended SAND deposits and withdrawals.

Containment: The Sandbox disabled bridging to and from Base and BNB Smart Chain, isolating the unbacked tokens. The team stated the impact represented less than 0.01% of total SAND token supply, as the exploit was contained to the Layer 2 deployment.

Ravencoin: Consensus Bug Splits the Network

On August 7, 2026 at 15:44:01 UTC, the first invalid block appeared on Ravencoin at height 4,487,776. The vulnerability sat in a header field called nHeight, part of Ravencoin's KAWPOW proof-of-work validation. The field was supposed to be checked against a block's actual position in the chain but never was — a validation oversight that allowed invalid blocks to pass consensus.

Network split: After the vulnerability was demonstrated on mainnet, additional invalid blocks were produced by others. Mining pools 2Miners and RavenMiner, controlling a majority of the network's hash rate, began constructing a competing chain from height 4,487,775, threatening to roll back approximately three days of confirmed transactions.

Response gap: The fix came from a mining pool, not the core development team. 2Miners shipped emergency patch v4.6.1.1-hf1, rejecting forged blocks and locking in a checkpoint at block 4,487,775. Exchanges including Bithumb and Upbit halted RVN deposits and withdrawals and added warning status to the token. RVN price dropped roughly 20%.

Oraichain, MemeCore, and Allbridge

Three smaller incidents rounded out August's minting wave:

Oraichain (August 9): The AI-focused Layer 1 network paused operations at 04:00 UTC after detecting unauthorized ORAI minting through a vulnerability in its EVM cross-chain transfer pathway. The network has remained halted since. The team said the exploit path had been identified and addressed, and it was preparing to burn unauthorized balances and reconcile protocol state to restore canonical ORAI supply. Bridge contracts and public interfaces remain restricted.

MemeCore (August 19): PeckShieldAlert reported approximately 1 billion $M tokens minted on BNB Smart Chain without offsetting tokens on the native chain. Two batches of roughly 463 million tokens each were consolidated into a single address. The mint represented approximately 77% of circulating supply, yet the price moved only single-digit percentage points. Analysts noted the process did not resemble a typical external exploit, with evidence pointing toward execution by project insiders or bridge operators holding authorized access.

Allbridge (August 19): The bridge protocol lost 191,156 USDC on Base when its new CCTP router credited a forged Circle message as a real deposit. The loss was minor relative to other August incidents but demonstrated that even standardized bridging standards (Circle's CCTP) can be exploited at the integration layer.

2026 Context: The Year of Supply Forgery

August's wave is part of a broader 2026 pattern. Earlier incidents include:

KelpDAO (April 18): The year's largest single DeFi exploit. An attacker exploited a "1/1 DVN" configuration in KelpDAO's LayerZero bridge to mint 116,500 unbacked rsETH tokens worth approximately $292 million. The attacker supplied the stolen rsETH as collateral on Aave V3 and borrowed approximately 126,000 WETH (~$236 million). KelpDAO's emergency pauser froze contracts 46 minutes after the drain. Attackers were linked to North Korea's Lazarus Group.

Syscoin (June 7-8): A validation flaw in the cross-chain bridge relay path permitted creation of roughly 5 billion unauthorized SYS — more than five times the pre-attack circulating supply of approximately 890 million SYS. The bridge was halted and a fix prepared, with exchanges coordinating to blacklist, freeze, or monitor deposits from tainted addresses.

Provenance Blockchain (disclosed August 25): Trail of Bits disclosed a bug found in March 2026 that allowed any user to grant themselves admin control over marker accounts without holding a single token. The flaw affected 82 active markers on mainnet, including those holding approximately $500,000 in HASH. The vulnerability was patched in v1.28.0 (May 2026) and fully fixed in v1.29.0 (June 2026).

Aggregate 2026 figures: TRM Labs recorded 207 hacks in the first half of 2026 alone, more than double the 83 from the same period in 2025. DefiLlama counts more than $1 billion stolen across 140+ exploits year-to-date. Total incidents through early August reached 164, already exceeding every prior full-year total.

The Rollback Dilemma

Three of August's incidents forced networks to consider or execute chain rollbacks — a measure that directly contradicts the immutability guarantee that distinguishes blockchains from centralized databases.

Harmony's rollback: On August 17, Harmony announced validators would roll back Shard 0 and Shard 1 to a checkpoint recorded at 23:25 UTC on August 11, discarding more than 109,000 confirmed transactions. The team evaluated alternatives — token burns, address blacklists, token migration — and concluded rollback was the "fairest and most secure" option, given that forged assets had already spread through exchanges, protocols, and bridges.

Ravencoin's competing chain: Rather than a coordinated rollback, Ravencoin experienced an organic chain split as mining pools constructed an alternative chain excluding exploited blocks, effectively attempting to reverse approximately three days of confirmed history.

The precedent problem: Each rollback establishes that a sufficiently severe exploit can trigger history revision. For networks carrying DeFi positions, LP stakes, or settled trades, this creates a category of risk that smart contract audits cannot address: the risk that the chain itself may not honor confirmed state. On-chain investigator ZachXBT publicly boycotted Harmony's recovery efforts, citing the protocol's handling of the 2022 Horizon Bridge exploit and a "deepening trust deficit."

Economic Value at Risk

From an economic value perspective, supply integrity attacks represent a distinct threat category. Unlike governance attacks (which redirect existing funds) or oracle manipulation (which exploit price feeds), supply forgery creates new tokens that dilute all existing holders simultaneously.

Dilution mechanics: When an attacker mints 26% of a token's supply and sells into exchange liquidity, every existing holder suffers proportional dilution. The price crash is not merely a liquidity event — it reflects permanent value destruction unless the forged tokens can be completely recovered. In Harmony's case, 97% of forged tokens reached exchanges before freezes, making full recovery functionally impossible without a rollback.

Bridge concentration risk: Five of six August incidents involved cross-chain infrastructure: bridge validation, cross-shard receipts, or omnichain token contracts. Cross-chain bridges moved approximately $4 billion daily in August 2026, according to industry data. The bridge layer has emerged as the primary attack surface for supply integrity exploits, as it sits at the boundary between trust domains where validation gaps are most likely.

Exchange as the last line: In every August incident, exchanges served as the de facto containment mechanism. Protocol-level defenses — supply monitoring, freeze multisigs, emergency pausers — consistently failed to activate before forged tokens entered exchange order books. The gap between exploit execution and exchange response ranged from minutes (Sandbox) to hours (Harmony).

Key Takeaways

  • Six blockchain networks experienced unauthorized token minting between August 7-22, 2026, forging quantities ranging from 191,156 USDC (Allbridge) to 3+ trillion ONE (Harmony).
  • Cross-chain bridge and cross-shard validation flaws were the attack vector in five of six cases. Smart contract reentrancy or flash loan attacks were absent from August's minting wave.
  • Supply reporting endpoints failed to reflect unauthorized mints in real time, leaving dashboards and alerting systems blind while forged tokens moved to exchanges.
  • Two networks (Harmony, Ravencoin) pursued or considered chain rollbacks, discarding over 109,000 confirmed transactions in Harmony's case and threatening three days of transaction history on Ravencoin.
  • Exchange-level freezes served as the primary containment mechanism, not protocol-level defenses. South Korea's top three exchanges placed SAND on delisting watchlists.
  • 2026 has logged 164+ security incidents through early August, already exceeding every prior full-year total. H1 losses ranged from $680 million to $1.1 billion across sources.
  • The gap between face-value minted (Sandbox: $49 billion) and actual extractable loss ($665,000) highlights that supply inflation metrics alone can be misleading without context on liquidation pathways.

Conclusion

August 2026's supply integrity failures expose a structural weakness in blockchain architecture that existing security tooling does not adequately address. Smart contract audits focus on application-layer logic. Formal verification targets specific contract properties. Neither examines the seams between chains — bridge validation, cross-shard receipt handling, consensus parameter checking — where August's exploits occurred.

The rollback decisions at Harmony and Ravencoin raise a harder question. If a chain can revert confirmed transactions when an exploit is severe enough, its settlement guarantees are conditional rather than absolute. For institutional users evaluating blockchain settlement — banks, asset managers, tokenized securities issuers — this conditionality introduces a risk category that does not exist in traditional settlement infrastructure, where finality is governed by regulation rather than validator coordination.

The data suggests that supply integrity monitoring — real-time verification that reported supply matches actual chain state — should be treated as critical infrastructure, not an afterthought. Harmony's totalSupply endpoint continued reporting pre-exploit figures while trillions of forged tokens circulated. Until supply verification is independent, continuous, and resistant to the same bugs that enable forgery, the gap between what a blockchain reports and what it actually contains will remain exploitable.

Sources & References

  1. Harmony confirms exploit involving unauthorized minting of 4 billion ONE tokens — The Block, August 12, 2026
  2. Harmony plans pre-attack rollback after exploiter forged 3 trillion ONE tokens — The Block, August 17, 2026
  3. Harmony's ONE dives 40% after an attack appears to mint tokens equal to quarter of supply — CoinDesk, August 12, 2026
  4. Harmony ONE Hacked: 4 Billion Tokens Minted, Supply Masking Sent 97% to Exchanges — TechTimes, August 12, 2026
  5. Harmony Protocol Plans Network Rollback, Raising Blockchain Immutability Concerns — Crowdfund Insider, August 2026
  6. The Sandbox's $49 billion phantom mint — Crypto.news, August 2026
  7. Sandbox Hacked: Attackers Mint 329 Trillion Tokens on Base — CryptoTimes, August 22, 2026
  8. SAND Faces Upbit, Bithumb Delisting Risk After $49B Mint Attack — CryptoTimes, August 24, 2026
  9. Upbit, Bithumb place SAND under caution after bridge exploit — Crypto.news, August 2026
  10. Ravencoin Crashes 20% as Critical Exploit Threatens to Rollback Network — Decrypt, August 2026
  11. Ravencoin Network Notice — Consensus vulnerability — Ravencoin official, August 7, 2026
  12. Ravencoin's Fix Coming From a Mining Pool, Not Its Own Team — Cryip, August 2026
  13. Oraichain Halts Network After Unauthorized ORAI Minting — KuCoin News, August 9, 2026
  14. MemeCore Bridge Mints Nearly 1 Billion Tokens Without Native Chain Offset — CryptoTimes, August 19, 2026
  15. KelpDAO rsETH Exploit: $292M LayerZero Bridge Attack — KuCoin Blog, April 2026
  16. Syscoin Bridge Paused After 5 Billion Unauthorized SYS Tokens Minted — KuCoin News, June 2026
  17. State divergence enables unauthorized access — Provenance Blockchain — Trail of Bits Blog, August 25, 2026
  18. August 2026's Exploit Wave: Governance Failures, Protocol Bugs, And A Widening Attack Surface — Metaverse Post, August 2026
  19. DeFi Hacks & Exploits Statistics 2026: The Real Numbers — DeepStrike, 2026
  20. Top 10 Biggest DeFi Hacks of 2026 (So Far): $1B+ Lost — DefiMon, 2026