Harmony plans pre-attack rollback after exploiter forged 3 trillion ONE tokens

요약:Harmony will roll back Shard 0 and Shard 1 to just before last weeks exploit, discarding all blocks and transactions after that point, after determining that more than 3 trillion native ONE tokens were forged through a cross-shard receipt verification flaw. The exploit, confirmed Aug. 12, involved six transactions into four wallets; nearly 2.4 trillion ONE were moved quickly via DEX pools and bridges. Harmony said almost all forged tokens have been traced, but many cannot be safely burned without harming innocent users. It considered token burns, blacklisting, and migration, but concluded that a single fixed rollback window was the “fairest and most secure” option, applying one rule to everyone and minimizing attack or consensus-failure risk.

Quick Take

  • Harmony said nearly all of the forged ONE has been traced, but much of it cannot be safely burned.
  • The exploit allowed the attacker to reuse transactions to create new ONE tokens.

Harmony plans to roll back its blockchain to a point before last week's exploit after concluding that more than 3 trillion of the blockchain's native ONE tokens were forged.

The Layer 1 blockchain said in its latest incident update that validators will roll back Shard 0 and Shard 1, the two chains that make up its sharded network, to just before the confirmed forged mint. All blocks and transactions after that point will be discarded.

Harmony said that it considered alternatives, including a token burn, blacklisting affected wallets or even a ONE token (ONE) migration, but concluded that a rollback was the “fairest and most secure” option.

“Of the options we studied, one fixed rollback window is the fairest and most secure,” Harmony said. “It applies one rule to everyone, removes the forged state, and carries the lowest risk of another attack or consensus failure.”

3 trillion forged ONE

Harmony first confirmed the exploit on Aug. 12 after an unauthorized minting of ONE tokens was discovered. An independent researcher initially identified 4 billion tokens minted through empty blocks, but Harmony later found that this was only the first wave.

A later reconstruction found 3.01 trillion ONE were forged across six transactions into four exploiter wallets.

One of those wallets successfully moved nearly 2.4 trillion ONE, worth almost $3 billion in pre-attack prices, in under two minutes.

Harmony said it has traced nearly all the forged tokens to wallets or services, though many of them passed DEX pools and bridges, making it difficult to safely recover or burn without affecting innocent users.

The exploit reportedly stemmed from a flaw in its cross-shard receipt verification that allowed valid receipts to be processed multiple times, allowing exploiters to mint new ONE tokens without a debit elsewhere. The vulnerability was patched on Aug. 12, when the attack was first discovered.

Disclaimer: The Block is an independent media outlet that delivers news, research, and data. As of November 2023, Foresight Ventures is a majority investor of The Block. Foresight Ventures invests in other companies in the crypto space. Crypto exchange Bitget is an anchor LP for Foresight Ventures. The Block continues to operate independently to deliver objective, impactful, and timely information about the crypto industry. Here are our current financial disclosures.

© 2026 The Block. All Rights Reserved. This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.

면책 성명

본 기사의 견해는 저자의 개인적 견해일 뿐이며 본 플랫폼은 투자 권고를 하지 않습니다. 본 플랫폼은 기사 내 정보의 정확성, 완전성, 적시성을 보장하지 않으며, 개인의 기사 내 정보에 의한 손실에 대해 책임을 지지 않습니다.
전편

미국 재무부, GENIUS 법안 스테이블코인 규제안 제시

다음

컴파운드, 기관 투자자 중심 전환 위해 5,200만 달러 투자 및 신규 리더십 팀 구성