Network Will Reverse Transactions to Remove Exploit-Created Supply
Harmony is preparing to roll back its blockchain after determining that attackers forged approximately 3.01 trillion ONE tokens through a vulnerability that allowed cross-shard transactions to be reused.
The Layer 1 network said validators will restore both Shard 0 and Shard 1 to checkpoints immediately before the first confirmed fraudulent mint, effectively deleting the affected blockchain history and rebuilding the network from its pre-exploit state.
Harmony selected block 92,730,034 on Shard 0 and block 94,978,278 on Shard 1, both corresponding to Aug. 11 at 11:25:37 p.m. UTC. New blocks will resume from the next block heights once validators complete the recovery process.
The first confirmed forged mint appeared on Shard 0 shortly after those checkpoints.
All transactions recorded after the selected blocks will be discarded, including legitimate activity that occurred alongside the exploit. More than 109,000 regular transactions and hundreds of staking transactions are expected to be affected by the rollback.
Harmony said it considered several alternatives, including burning the forged ONE, blacklisting wallets connected to the attacker and migrating the token to a new contract or network state.
It ultimately concluded that using a single rollback window was the safest option because the forged tokens had already spread across exchanges, decentralized trading pools, bridges and individual wallets.
Trying to destroy only the compromised tokens could therefore affect legitimate funds after fraudulent and genuine ONE became mixed through subsequent transactions.
Harmony said a fixed rollback applies the same rule across the network and avoids introducing additional technical complexity that could create new security or consensus problems.
The scale of the exploit turned out to be far greater than initially believed.
Harmony first confirmed unauthorized ONE creation on Aug. 12 after an independent researcher identified approximately 4 billion tokens minted through abnormal blocks.
A more extensive reconstruction later found that about 3.01 trillion ONE had been created across six forged cross-shard transactions and distributed among four attacker wallets.
One of the wallets moved approximately 2.385 trillion ONE through hundreds of successful transfers in less than two minutes. At prices prevailing before the attack, that quantity would have carried a theoretical value approaching $3 billion, although available market liquidity would have made it impossible to realize anything close to that amount without collapsing the token’s price.
Harmony said investigators have traced nearly all of the forged supply to wallets or services. That visibility has not made recovery straightforward.
Once ONE moved through decentralized exchanges, liquidity pools, bridges and other accounts, forged tokens became mixed with assets belonging to users who had no involvement in the attack. Burning the entire amount traced from the exploiter could therefore destroy legitimate balances as well.
The vulnerability involved Harmony’s cross-shard receipt system, which allows transactions and their results to move between different parts of the sharded network.
The exploit made it possible for previously valid transaction receipts to be processed again. Instead of recognizing that a receipt had already been consumed, the network could treat a modified version as new and credit additional ONE on the receiving shard without a corresponding debit elsewhere.
That effectively allowed the attacker to create new native tokens without supplying the economic value that should have existed on the originating side of the transaction.
Harmony also identified a weakness involving validator quorum verification. The project deployed Mainnet version 2026.1.1 on Aug. 12 to close the vulnerabilities and stop further unauthorized minting.
Bridge services were suspended while Harmony coordinated with validators, exchanges and other infrastructure providers to trace and freeze affected assets.
The rollback introduces a different problem: valid transactions completed after the restoration point will disappear along with the fraudulent ones.
Users who transferred ONE, interacted with decentralized applications, changed staking positions or completed other transactions during the affected period may therefore see those actions reversed and may need to repeat them after the network resumes.
Harmony is preparing replacement databases and recovery procedures for validators and has configured an updated client to reject the abnormal blockchain history associated with the exploit.
The incident adds another major security event to Harmony’s history.
In June 2022, attackers stole approximately $100 million from Harmony’s Horizon bridge after compromising private keys controlling its multisignature system. U.S. authorities later attributed that attack to North Korea’s Lazarus Group.
The latest incident is technically different. Rather than compromising bridge signing keys, the attacker exploited protocol-level weaknesses in the way Harmony validated and recorded cross-shard transactions.
That distinction makes the current attack potentially more damaging to confidence in the blockchain itself. The network is not simply attempting to recover assets stolen from a bridge. It is rewriting part of its ledger because the protocol allowed trillions of native tokens to be created without authorization.
The Rollback Solves the Supply Problem but Creates a Trust Problem
Harmony’s decision is understandable from a technical perspective.
If trillions of forged ONE remain distributed throughout the network, the integrity of the token supply becomes impossible to defend. Burning specific wallets sounds cleaner, but once those coins have passed through exchanges and liquidity pools, deciding which tokens are “bad” becomes much harder.
A rollback removes the problem at its origin.
The price is blockchain finality.
One of the central promises of a public blockchain is that a confirmed transaction eventually becomes history rather than a provisional database entry that developers can erase when something goes wrong.
Harmony is now asking users to accept that more than 109,000 legitimate transactions can disappear because reversing them is the least damaging way to eliminate the consequences of a protocol failure.
That may still be the correct choice. But correct does not mean painless.
Imagine a user who sold ONE during the affected period and withdrew another asset, a liquidity provider whose position changed, or someone who completed a payment and considered the transaction settled. Rolling back one side of those activities can create mismatches whenever another platform or blockchain does not reverse its corresponding action.
That is particularly difficult when bridges are involved. Harmony can rewrite Harmony. It cannot simply order another independent blockchain to rewrite its own history.
The extraordinary quantity of forged ONE also illustrates why the headline value of an exploit can be misleading.
Creating 3 trillion tokens does not mean the attacker obtained $3 billion. A market can only absorb as much selling as buyers and available liquidity permit. Trying to liquidate trillions of ONE would rapidly destroy the price.
But the inability to cash out the entire amount does not make the exploit less serious. The attacker compromised the mechanism that determines whether ONE exists at all.
That is a deeper failure than stealing tokens from an individual wallet.
The comparison with Harmony’s 2022 Horizon bridge hack is uncomfortable for the project. The earlier attack could be framed as a failure of bridge key security. Four years later, Harmony is dealing with a flaw in the chain’s own cross-shard verification logic.
For users, technical distinctions matter less each time another major incident occurs.
The rollback can restore the numerical supply of ONE. A patch can prevent the same receipt from being replayed again. Exchanges can freeze some of the assets that escaped.
None of those steps automatically restores confidence.
Harmony now needs to show precisely how the vulnerability survived until 2026, whether similar validation assumptions exist elsewhere in the protocol and what independent review will be performed before the network is treated as fully secure again.
The immediate challenge is restarting the blockchain without fragmenting validators or creating new inconsistencies.
The longer-term challenge is harder: convincing users that the next transaction they consider final will actually remain final.
