Harmony confirmed Wednesday that an attacker exploited its ONE token contract to mint roughly 4 billion unauthorized tokens. That is about a quarter of the existing supply. The confirmation came after a pseudonymous researcher flagged the mint on social media.
ONE fell sharply once the mint became public. How sharply depends on the outlet and the clock. CoinDesk put the drop at about 40% during the Asian morning session. The Block cited a 34% slide over 24 hours. Cointelegraph, pulling CoinGecko data, reported a 33.9% decline over the same window.
X user “Juiceberg” first reported the mint, writing that the attacker had produced roughly 4 billion ONE using empty blocks and that the token’s totalSupply endpoint did not immediately reflect the increase. “The attacker has roughly 115M ONE left to sell onchain — about 2.9% of the ~4B they minted,” Juiceberg wrote. “The overwhelming majority (~97%) is already on exchanges and has either been sold or is sitting in deposit wallets ready to sell.”
Harmony responded to Juiceberg directly in an X statement. It confirmed the exploit and said it was working with its team and exchanges to stop and freeze funds, developing a patch, and evaluating rollback options. What the team has not confirmed: the number of tokens created, the amount sent to exchanges, or the technical root cause.
CoinDesk noted that roughly 15 billion ONE were in circulation before the incident, making the 4 billion new tokens a roughly 26% increase against that supply. The stolen haul’s current value sits near $3.2 million, according to The Block.
Harmony told network operators to install an emergency software update to prevent further minting. It said it was working separately on how to handle the tokens already created. The team paused its token bridge. It asked exchanges to freeze funds traced to four linked wallet addresses. The first was listed as 0xf722f7f6afffe8e0dda7b4a97b2c64bb6408efe5.
Cointelegraph, citing Juiceberg, reported that about 2.8 billion tokens were funneled to exchanges as the price fell. It said the claims could not be independently verified.
Harmony has been here before. In June 2022, an attacker drained about $100 million in ether and stablecoins from the network’s Horizon cross-chain bridge after compromising its multi-sig wallet. The FBI later attributed that attack to North Korea’s Lazarus Group. In December 2023, a separate staking bug created roughly 146.3 million ONE. The network responded with an emergency update and blacklisted 74 addresses.
A day before the ONE mint surfaced, Ravencoin faced its own possible rollback after parts of its network accepted invalid blocks, prompting miners to rebuild the chain.
Whether a Harmony rollback could cleanly handle tokens already sold on exchanges remains unclear. The team has not said which option it will pursue.