Meet the Top 101 in Crypto
News
5 min read

Harmony Hacked Again: ONE Crashes 38% After 4B Tokens Minted in Fresh Exploit

Published 13 August 2026
Dr. Guneet Kaur
Authors

Key Takeaways

  • Early reports indicate roughly 4 billion ONE tokens were illicitly minted, an amount equal to about 27% of Harmony’s previously reported token supply.
  • ONE reportedly plunged as much as 38% as the market priced in the potential dilution and risk that newly created tokens could be sold.
  • Harmony has dealt with two major security crises before: the $100 million Horizon Bridge hack in 2022 and a 2023 staking bug that generated 146.3 million unintended ONE.

Harmony’s ONE token plunged on Thursday after reports of a fresh exploit involving the unauthorized minting of roughly 4 billion ONE, reopening security concerns around a blockchain already scarred by two previous major incidents.

ONE fell as much as 38.2% during the initial reaction, according to market data circulating alongside the exploit reports, as traders confronted the possibility of billions of newly created tokens entering circulation.

The scale is particularly significant. CoinMarketCap most recently reported Harmony’s circulating supply at approximately 15 billion ONE. On that basis, another 4 billion tokens would represent potential dilution of roughly 26.7%, assuming the newly minted supply is valid on-chain and is not subsequently frozen or burned.

Try Our Recommended Crypto Exchanges
Sponsored
Disclosure
Opened in 2011
Promotions
Get $10 in Bitcoin when you register through a referral link from an existing member.
Coins
Bitcoin Ethereum Tether Build'N'Build USD Coin +81
Promotions
Receive up to $100,000 worth of exclusive gifts for newcomers upon registration.
Coins
Bitcoin Ethereum Tether USD Coin Solana +76
Opened in 2017
Promotions
Experience a 1-minute swap on a non-custodial platform.
Coins
Bitcoin Ethereum Tether Build'N'Build USD Coin +217
Show More
 

4B ONE Mint Would Dwarf Harmony’s Previous Token Bug

This is not Harmony’s first encounter with unintended token creation.

In December 2023, a vulnerability in the network’s staking logic caused 146.28 million ONE to be generated improperly. Harmony’s subsequent technical report traced the problem to undelegations that were not correctly removed from state, allowing affected balances to receive repeated payouts across epochs.

If the newly reported 4 billion ONE figure is confirmed, the latest incident would be more than 27 times larger than the entire 2023 unintended mint.

Blockchain investigator ZachXBT said he would not track the latest Harmony incident or assist the project for free, citing his experience following the $100 million Horizon Bridge exploit in 2022. He claimed Harmony failed to compensate people who helped trace and freeze stolen funds that later contributed to law-enforcement seizures, and instead offered little more than a “good job.”

His comments add another layer of reputational pressure around the latest exploit, suggesting Harmony may struggle to attract independent security researchers willing to help unless clearer incentives or formal arrangements are offered.

But the comparison matters because Harmony responded to the earlier bug with an emergency hard fork. Of the 146.3 million ONE generated at the time, one address alone received 51.2 million tokens, while millions of ONE were transferred or sold before mitigation measures took effect.

The critical question this time is therefore how much of the reported 4 billion ONE remains under the attacker’s control and whether any tokens have reached exchanges or decentralized liquidity pools.

Harmony Still Carries the Scars of Its $100M Bridge Hack

The latest incident also revives memories of the Horizon Bridge attack in June 2022, when an attacker drained approximately $97 million in assets after gaining sufficient control over the bridge’s multisignature system.

CertiK identified 12 attack transactions involving assets including ETH, USDC, WBTC, USDT, and DAI.

Harmony later concluded that its bridge smart contracts and underlying blockchain had not themselves been broken, pointing instead to compromised internal infrastructure and privileged access.

There is another uncomfortable historical parallel.

Following the Horizon exploit, Harmony initially proposed minting 4.97 billion ONE to fully reimburse victims, or 2.48 billion for a 50% reimbursement.

The proposal faced strong opposition due to its inflationary consequences and was eventually replaced by a recovery approach that proposed zero additional ONE issuance.

The roughly 4 billion tokens reportedly created in the latest incident are therefore approaching the size of the controversial supply expansion Harmony itself rejected four years ago.

What Happens to ONE Next?

Harmony said it has now traced 10,288 transfers across 409 wallets that received fraudulently minted tokens and alerted exchange partners to hundreds of suspicious deposits.

According to the project, exchanges have already blocked wallets linked to the attacker, reducing the immediate risk that all of the newly created ONE can be liquidated.

The network is also moving quickly on remediation. Harmony said 53% of validators had completed an emergency upgrade within four hours of the patch’s release, while the team works on a broader recovery plan.

That shifts the immediate question from whether the exploit can continue to how much of the damage can be reversed.

Harmony said a rollback is currently the most favored practical solution, although the team has not yet published final details on how such a rollback would work, which transactions would be affected, or how it would handle tokens that have already moved through exchanges or other wallets.

For ONE, the next major catalysts are therefore the pace of validator adoption, confirmation that suspicious funds remain frozen, and the final decision on whether the network proceeds with a rollback.

Until those details are clear, the market is likely to remain focused on whether the fraudulent supply can be neutralized rather than simply on the original 4 billion-token mint.

 

Disclaimer: The information provided in this article is for informational purposes only. It is not intended to be, nor should it be construed as, financial advice. We do not make any warranties regarding the completeness, reliability, or accuracy of this information. All investments involve risk, and past performance does not guarantee future results. We recommend consulting a financial advisor before making any investment decisions.
Dr. Guneet Kaur

Dr. Guneet Kaur is a senior editor at CCN.com and a Science Fellow at Exponential Science. She is a fintech and blockchain expert with extensive experience in digital finance education, blockchain ecosystems, and cryptocurrency markets. She has worked with global media such as Cointelegraph, as well as education and blockchain platforms, to design and lead strategic content and learning initiatives. As an educator and assessor for top-tier executive programs, she bridges real-world fintech trends with academic insight.

Dr. Kaur is also a published researcher and peer reviewer across fintech and data science journals, including Financial Innovation Journal and International Journal of Big Data Intelligence and Applications. Her work spans data-driven analysis, Web3 innovation, and technical content development. With a strong foundation in both industry and academia, she translates complex financial technologies into practical applications, empowering learners, professionals, and institutions across the rapidly evolving digital finance landscape.

Related

Survey Icon
Help us improve
1 of 4
Is this your first time here?
What brought you here today?
What are you most interested in?
Would you be interested in:
Thank you icon
Thank you for your feedback!
DMCA.com Protection Status