Points of Focus
- An attacker allegedly minted 4 billion unauthorized ONE tokens.
- Around 2.8 billion tokens were routed to exchanges.
- Harmony asked exchanges to freeze funds linked to four suspect wallets.
Harmony Protocol is confronting another major security crisis after an attacker allegedly minted 4 billion unauthorized ONE tokens, triggering severe dilution and sending the cryptocurrency down as much as 38%.
The newly created tokens were equivalent to approximately 26% of ONE’s previous supply.
Around 2.8 billion were transferred rapidly to exchanges, creating intense selling pressure and pushing the token to lows near $0.00056.
Harmony confirmed the incident and said it was working with exchanges to freeze the stolen assets while validators deployed an emergency patch to prevent additional minting.
Unauthorized mint floods exchanges
Onchain investigators identified the apparent creation of 4 billion ONE through empty blocks. The attacker subsequently routed the tokens through more than 10,000 transfers, complicating attempts to track and contain the funds.
The scale of the mint represents a direct blow to existing holders. Unlike an exploit involving only previously circulating assets, unauthorized token creation expands the supply and immediately dilutes every legitimate token in circulation.
We are working with our team and appropriate exchanges to stop and freeze the funds.
We are working on a patch and rollback options.
Will update when we have new information. https://t.co/XB0nCwTAyN
— Harmony 💙 (@harmonyprotocol) August 12, 2026
Nearly 70% of the newly minted ONE was reportedly sent toward exchanges, where the additional supply contributed to the sharp price decline.
Harmony published four suspected wallet addresses and asked centralized exchanges to block and freeze any funds traceable to them. The project has not yet disclosed how many tokens were successfully sold or whether any assets have been recovered.
Validators deploy emergency patch
More than half of Harmony’s validators have reportedly applied an emergency patch designed to halt further unauthorized minting.
The response appears to have contained the immediate threat, although the network must still determine how the attacker gained the ability to create new tokens.
We are asking all exchanges to block and freeze funds that traces back to these 4 wallet addresses:
one1uap8dx2z0qsjxqthm5flgcxkeepsz3gsrghnfn
0xe7427699427821230177dd13f460d6ce43014510one17u300a40ll5wphd8kj5hktryhdjq3ml9f4phy4
0xf722f7f6afffe8e0dda7b4a97b2c64bb6408efe5… https://t.co/wiR6uQOazW— Harmony 💙 (@harmonyprotocol) August 12, 2026
Harmony said its team was assessing both a technical patch and possible rollback options. Reversing the affected transactions could restore the supply but would also raise difficult questions about transaction finality and decentralized governance.
Any rollback would require sufficient validator support and a clear method for separating illicit transfers from subsequent transactions involving exchanges and potentially unsuspecting buyers.
The 2022 hack casts a long shadow
The exploit revives memories of Harmony’s Horizon Bridge breach in 2022, when North Korean-linked attackers stole around $100 million. That incident damaged confidence in the ecosystem and led to a controversial recovery plan.
Blockchain investigator ZachXBT said he would not assist with the latest case, alleging that Harmony failed to compensate people who helped trace and freeze funds following the earlier attack. Harmony has not publicly addressed that criticism in its initial incident updates.
The latest breach leaves the protocol facing more than a technical recovery.
Even if validators stop further minting and exchanges freeze part of the funds, restoring confidence will require a full explanation of the vulnerability, transparent accounting of the inflated supply, and a credible decision on whether the chain should be rolled back.
Unlock premium content
Create a free account to continue reading AlphaClub articles and access exclusive features.
Share


