Harmony plans pre-attack rollback after exploiter forged 3 trillion ONE tokens

摘要:Harmony will roll back Shard 0 and Shard 1 to just before last weeks exploit, discarding all blocks and transactions after that point, after determining that more than 3 trillion native ONE tokens were forged through a cross-shard receipt verification flaw. The exploit, confirmed Aug. 12, involved six transactions into four wallets; nearly 2.4 trillion ONE were moved quickly via DEX pools and bridges. Harmony said almost all forged tokens have been traced, but many cannot be safely burned without harming innocent users. It considered token burns, blacklisting, and migration, but concluded that a single fixed rollback window was the “fairest and most secure” option, applying one rule to everyone and minimizing attack or consensus-failure risk.

Quick Take

  • Harmony said nearly all of the forged ONE has been traced, but much of it cannot be safely burned.
  • The exploit allowed the attacker to reuse transactions to create new ONE tokens.

Harmony plans to roll back its blockchain to a point before last week's exploit after concluding that more than 3 trillion of the blockchain's native ONE tokens were forged.

The Layer 1 blockchain said in its latest incident update that validators will roll back Shard 0 and Shard 1, the two chains that make up its sharded network, to just before the confirmed forged mint. All blocks and transactions after that point will be discarded.

Harmony said that it considered alternatives, including a token burn, blacklisting affected wallets or even a ONE token (ONE) migration, but concluded that a rollback was the “fairest and most secure” option.

“Of the options we studied, one fixed rollback window is the fairest and most secure,” Harmony said. “It applies one rule to everyone, removes the forged state, and carries the lowest risk of another attack or consensus failure.”

3 trillion forged ONE

Harmony first confirmed the exploit on Aug. 12 after an unauthorized minting of ONE tokens was discovered. An independent researcher initially identified 4 billion tokens minted through empty blocks, but Harmony later found that this was only the first wave.

A later reconstruction found 3.01 trillion ONE were forged across six transactions into four exploiter wallets.

One of those wallets successfully moved nearly 2.4 trillion ONE, worth almost $3 billion in pre-attack prices, in under two minutes.

Harmony said it has traced nearly all the forged tokens to wallets or services, though many of them passed DEX pools and bridges, making it difficult to safely recover or burn without affecting innocent users.

The exploit reportedly stemmed from a flaw in its cross-shard receipt verification that allowed valid receipts to be processed multiple times, allowing exploiters to mint new ONE tokens without a debit elsewhere. The vulnerability was patched on Aug. 12, when the attack was first discovered.

Disclaimer: The Block is an independent media outlet that delivers news, research, and data. As of November 2023, Foresight Ventures is a majority investor of The Block. Foresight Ventures invests in other companies in the crypto space. Crypto exchange Bitget is an anchor LP for Foresight Ventures. The Block continues to operate independently to deliver objective, impactful, and timely information about the crypto industry. Here are our current financial disclosures.

© 2026 The Block. All Rights Reserved. This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.

免责声明

本文观点仅代表作者个人观点,不构成本平台的投资建议,本平台不对文章信息准确性、完整性和及时性作出任何保证,亦不对因使用或信赖文章信息引发的任何损失承担责任
上一篇

美国财政部提议《GENIUS法案》稳定币规则

下一篇

即时更新:随着大型人工智能计算合同持续涌入,比特币价格突破64,000美元