cryptocurrency widget, price, heatmap
arrow
Burger icon
cryptocurrency widget, price, heatmap
News/Harmony Confirms Unauthorized ONE Mint as Emergency Patch Halts Further Issuance

Harmony Confirms Unauthorized ONE Mint as Emergency Patch Halts Further Issuance

Van Thanh Le

Van Thanh Le

PublishedAug 12 2026

UpdatedAug 12 2026

6 hours ago4 minutes read
Harmony Confirms Unauthorized ONE Mint as Emergency Patch Halts Further Issuance

Exchange freezes and a possible blockchain rollback remain part of Harmony’s response

TL;DR

  • Harmony confirmed unauthorized ONE minting and deployed an emergency validator patch designed to stop additional issuance.
  • On-chain researcher Juiceberg estimated that billions of newly created ONE rapidly reached exchanges, while Harmony did not independently confirm his figures.
  • Harmony paused bridge operations, asked exchanges to freeze funds tied to four wallet pairs and continued evaluating rollback options.

Trade smarter on Jupiter, Solana’s leading DEX built for fast execution and deep liquidity. 

Swap tokens at competitive rates, route across multiple liquidity sources automatically, and access perpetuals, DCA, and advanced trading tools — all in one place!


Harmony confirmed unauthorized minting of its native ONE token after on-chain researcher Juiceberg said on Aug. 12, 2026, “Harmony exploited as on-chain data reveals unauthorized 4B ONE mint (26% of supply) via empty blocks, with 2.8B quickly funneled to exchanges as price crashed while totalSupply endpoint hides the inflation $ONE.” 

Harmony acknowledged that unauthorized minting occurred but did not independently confirm Juiceberg’s estimate, leaving the final amount of excess supply and its treatment unresolved.

Harmony responded by directing validators to install emergency release v2026.1.1, which the project said prevents further unauthorized minting. The validator notice confirmed that minting had occurred without stating an amount. Harmony separated the immediate containment effort from the treatment of tokens already created, saying, “We’ll follow up with another update to address already minted tokens.”

Juiceberg’s estimate was measured against roughly 15 billion ONE already circulating before the incident. Harmony’s ordinary block-reward mechanism provides 7 ONE for each confirmed shard block, so the scale of the alleged issuance pointed to a problem outside normal reward generation. The description of the tokens appearing through “empty blocks” did not itself establish how the mint occurred, and Harmony initially had not identified the affected component.

Patch targets cross-shard receipt verification and replay flaws

Harmony’s published code changes addressed two weaknesses involving cross-shard receipts, which carry transaction results between different parts of the network.

The first weakness involved quorum verification. An empty signer record paired with a mathematically neutral aggregate signature could pass a quorum check because the verifier counted the full committee rather than the validators actually represented in the signer record. That could allow a receipt to be accepted without the approvals normally required from participating validators.

The second weakness involved replay protection. Certain proof fields were not bound to the signed block header, allowing those fields to be changed so that an already processed receipt could appear new. The destination could then receive another credit without a corresponding new debit from the source. Harmony’s signed emergency release changed the quorum calculation and tied the spent marker to authenticated header data, closing both paths identified in the patch.

Harmony also paused bridge.harmony.one during the response. Separate coverage referred to the affected service as the LayerZero-Harmony bridge, but Harmony’s notice did not identify the bridge itself as the exploited component. The emergency software changes instead focused on receipt verification and replay behavior at the protocol level.


We’ve launched the all-new COIN360 Perp DEX, built for traders who move fast!

Trade 130+ assets with up to 100× leverage, enjoy instant order placement and low-slippage swaps, and earn USDC passive yield while climbing the leaderboard. Your trades deserve more than speed — they deserve mastery.


Exchange freezes target funds linked to four wallet pairs

Harmony escalated its exchange response by asking trading venues to identify and freeze funds connected to four implicated wallet pairs. Harmony posted, “We are asking all exchanges to block and freeze funds that traces back to these 4 wallet addresses:” before listing Harmony-format and Ethereum-format addresses associated with the incident.

Two full wallet pairs reproduced in the available reports were one1uap8dx2z0qsjxqthm5flgcxkeepsz3gsrghnfn paired with 0xe7427699427821230177dd13f460d6ce43014510, and one17u300a40ll5wphd8kj5hktryhdjq3ml9f4phy4 paired with 0xf722f7f6afffe8e0dda7b4a97b2c64bb6408efe5. Two additional abbreviated trails were one1a5hur07z…73bb08eb and one1h56hkx…58ff1a70ba.

Juiceberg later wrote, “The attacker has roughly 115M ONE left to sell onchain — about 2.9% of the ~4B they minted,” adding, “(~97%) is already on exchanges and has either been sold or is sitting in deposit wallets ready to sell.” Harmony had not verified those figures.

Sending tokens to an exchange did not establish that they had been sold. Funds could remain in deposit wallets, be exchanged internally or be withdrawn before a freeze request was implemented. Harmony also had not disclosed which exchanges received the suspected funds, how much each venue received or how much had ultimately been frozen.

Harmony’s exchange-freeze strategy and its consideration of a blockchain rollback addressed different parts of the incident. Exchanges can restrict assets under their control, while a rollback changes the blockchain’s transaction history. Harmony said rollback options were under consideration but had not announced that one would occur or identified a recovery point.

Removing an attacker’s remaining balance on-chain would be comparatively narrow, while a wider rollback would require Harmony to determine how many blocks to reverse and how to handle legitimate transactions inside that range. A rollback could eliminate unauthorized tokens still present on Harmony but would not automatically retrieve assets already deposited or sold through centralized exchanges.

According to COIN360ONE price fell sharply during the incident, moving from around $0.00117 to approximately $0.00057 and setting a new all-time low.

Harmony traces funds as rollback gains support

Harmony said it traced 10,288 transfers across all 409 wallets that received fraudulently minted ONE and alerted exchange partners to hundreds of suspicious deposit transactions. According to the project, exchanges “promptly blocked the hacker’s wallets.”

Harmony also said 53% of its validators had completed the emergency patch upgrade within four hours of its release. The project added that it was still developing a broader remediation plan, saying “a rollback seems to be the most favored practical solution so far,” with further details expected later.

Harmony previously faced token-creation and bridge security incidents

Harmony disclosed another unintended token-creation problem in December 2023, when a staking-logic vulnerability generated 146.28 million ONE across 74 delegator addresses. Matured undelegations were not being deleted from the network’s state, allowing the same underlying tokens to be distributed multiple times. Harmony responded to that incident with an emergency hard fork.

The newly reported mint was described as about 27 times larger than the earlier staking-related event. The mechanisms were different, but both involved flaws capable of creating new ONE rather than simply transferring tokens that already existed.

Harmony also suffered the Horizon bridge exploit in June 2022, when roughly $100 million in existing assets were stolen after multisignature control and private keys were compromised. The FBI later attributed that attack to North Korea’s Lazarus Group. The current emergency patch instead addresses protocol-level receipt verification and replay.

Another bridge security incident occurred shortly before Harmony’s latest problem, involving the XRPL-Coreum bridge. Nearly 200,000 XRP were stolen after an attacker tricked the bridge’s deposit-checking system into treating a wallet-to-wallet transfer as a legitimate deposit. The incident was presented as contemporaneous security context rather than as technically connected to Harmony.

The broader spillover from Harmony’s latest crisis was described as more limited because the ecosystem is smaller than at its 2022 peak, reducing external liquidity through which a ONE supply shock could spread. Billions of newly created tokens reaching exchange infrastructure can still affect ONE holders, market makers and exchange risk systems, while Harmony’s remaining response centers on the excess supply already created, the amount exchanges can freeze and whether the network ultimately proceeds with a rollback.

This article has been refined and enhanced by ChatGPT.

cryptocurrency widget, price, heatmap
v 5.13.12
© 2017 - 2026 COIN360.com. All Rights Reserved.