Key Takeaways:
- ONE fell 26% after roughly 4 billion tokens were minted, a quarter of supply.
- Harmony is working with exchanges to freeze funds and preparing a rollback.
- The exploit follows a $100 million bridge hack in 2022 and a 2023 minting bug.
Key Takeaways:

Harmony's ONE fell about 26% Wednesday after an attacker minted roughly 4 billion tokens, more than a quarter of existing supply.
Harmony confirmed the attack in an X post and said it is working with exchanges to freeze the funds and preparing a software fix. "We are working on a patch and rollback options," Harmony said, adding that it would provide another update when more information is available.
Roughly 15 billion ONE existed before the incident, meaning the 4 billion new tokens represent a sudden supply increase of about 26 percent. A rollback would return the network to a point before the exploit and continue from there, effectively removing transactions that occurred afterward from the blockchain's accepted history. That can prevent an attacker from keeping newly created tokens still on the network, but becomes harder once funds have reached exchanges or moved onto other systems.
The apparent exploit comes a day after Ravencoin, another smaller blockchain built from Bitcoin's code, faced its own possible rollback after invalid blocks were accepted by parts of its network. In that case, miners moved to rebuild the chain from before the flaw, putting several days of transactions at risk of reversal. Ravencoin is separate from Harmony, but the two incidents show the trade-off involved in a rollback — that undoing an attack can also undo legitimate transactions made after it.
A history of security failures
Harmony has dealt with unauthorized creation of ONE before. In December 2023, a bug in its staking system caused about 146.3 million ONE to be created when tokens that should have stopped receiving payouts continued doing so. Harmony said at the time that 74 addresses were involved, with one receiving 51.2 million ONE and about 16.4 million subsequently moved to an exchange. The network responded with an emergency software update and blacklisted addresses holding the improperly created tokens.
Harmony was also hit by one of crypto's biggest bridge attacks in 2022, when about $100 million was stolen from its Horizon bridge after attackers compromised private keys controlling it. The FBI later attributed that theft to North Korea's Lazarus Group.
Wednesday's incident appears different because the reported damage involves the creation of ONE on Harmony itself rather than assets being stolen from a bridge. Harmony has not yet explained the vulnerability, how the 4 billion figure was calculated, or how far back any proposed rollback would go.
The scale of the minting — equivalent to a quarter of the entire token supply — raises questions about Harmony's long-term viability as a network. Token supply integrity is foundational to any blockchain's value proposition, and a single exploit that inflates supply by 26 percent can trigger sustained selling pressure as holders reassess the token's scarcity. Exchanges may also tighten listing requirements or delist ONE if the rollback fails to fully reverse the unauthorized minting.
This article is for informational purposes only and does not constitute investment advice.