Logo Daily Crypto Briefs
Open menu

Harmony Exploit Mints 4B ONE, Token Drops 40%

7 min read
Breaking News
Large official Harmony logo beside a greyscale fractured blockchain ledger and unbranded blank supply tiles on an off-white, cobalt and violet editorial background.

TL;DR

  • Harmony confirmed an exploit after reports that an attacker minted 4 billion unauthorized ONE tokens, roughly 27% of the pre-incident supply.
  • The project asked exchanges to freeze four linked addresses, paused its bridge and said it was preparing a patch while evaluating rollback options.
  • The Block, citing on-chain researcher Juiceberg, reported that roughly 115 million ONE remained on-chain while about 97% of the minted amount had reached exchanges or been sold.
  • ONE fell about 34% in a CoinGecko snapshot reviewed at 09:23 UTC and as much as 40% in contemporaneous market reporting.

CASABLANCA, Aug. 12, 2026

Harmony confirmed an exploit after an attacker reportedly minted 4 billion unauthorized ONE tokens, roughly 27% of the blockchain’s pre-incident supply, as the token fell as much as 40% and the project sought exchange freezes while weighing a patch and potential rollback.

The layer-1 network said it was working with exchanges to stop and freeze funds traced to four addresses, had paused its bridge, and was assessing rollback options. Harmony had not disclosed the technical root cause, a final loss total, an affected-wallet count, or whether a rollback would be carried out when this report was prepared.

The incident is more than a software warning. The reported 4 billion ONE is an inflationary issuance that could be sold into the market, while on-chain tracking cited by The Block said only about 115 million ONE, or 2.9% of the reported mint, remained on-chain. The same report said the overwhelming majority had already reached exchanges or been sold, a disposition estimate that Harmony had not independently quantified in its public statement.

ONE traded at about $0.000780 in a CoinGecko snapshot reviewed at 09:23 UTC, down roughly 34% from its Aug. 12 daily reference level of $0.001176. CoinDesk’s updated market report described a drop of about 40% during Asian trading, showing how quickly the small-cap token’s price was moving as the incident developed.

Harmony’s official notice said, “We are working on a patch and rollback options,” after naming the four addresses it asked exchanges to block and freeze. That is a response plan, not confirmation that the unauthorized tokens have been recovered or that a rollback has community or validator support.

Harmony

ONE
July 13 to Aug. 12, 2026 (UTC readings)
$0.0008
-33.5%
Jul 13 - Aug 12 | High $0.0014 Low $0.0008

Harmony Says 4 Billion ONE Were Minted

Harmony runs a proof-of-stake blockchain whose ONE token is used for transaction fees, staking and governance. The project’s documentation describes its sharded network and validator model, but it does not explain the Aug. 12 exploit path.

The reported scale sets this event apart from a temporary service outage. CoinDesk said roughly 15 billion ONE existed before the incident, which would put an additional 4 billion at about 26.7% of that base. A change of that size can disrupt the token’s supply assumptions even before the network completes a technical investigation.

The best available impact measure is therefore two-part: the unauthorized issuance and the money that may have escaped containment. The Block reported the 4 billion ONE were worth about $3.2 million at a contemporaneous price near $0.0008. That valuation should not be treated as a final theft total, because a token minted without authorization can be rolled back, frozen, recovered, sold at different prices, or remain in a deposit wallet.

Harmony’s own notice named four addresses and asked exchanges to freeze funds connected to them. It did not publish a victim count, a confirmed amount frozen, a recovery figure, or a claim process. Readers should treat social posts declaring that all 4 billion ONE were permanently lost as unsupported until the project supplies that accounting.

The rapid price reaction also distinguishes market impact from the funds-flow question. A price fall affects holders broadly, whereas the direct incident accounting depends on how many minted tokens were sold, where they landed, and which can still be frozen or invalidated.

Most Minted ONE Had Reached Exchanges, Report Says

The Block attributed its distribution estimate to on-chain researcher Juiceberg, who said the attacker had about 115 million ONE left to sell on-chain, or roughly 2.9% of the approximately 4 billion minted. The report said about 97% was already on exchanges, sold, or sitting in exchange deposit wallets awaiting sale.

That estimate is the clearest public exploitation evidence found for this report, but it has limits. It is an analyst’s reading of addresses and transfers, not an audited statement by Harmony or a public confirmation by named exchanges. It also cannot establish how much was frozen after the transfers, how much was sold, or the attacker’s realized proceeds.

The project paused its bridge and said it was coordinating with “relevant exchanges.” Those actions can reduce further movement, but transfers made before an exchange intervention are harder to reverse than balances still visible on the native chain. This is the operational difference between an unauthorized mint and a loss that remains fully inside a protocol-controlled contract.

Harmony has faced a much larger but different security incident before. The FBI confirmed that North Korea-linked Lazarus Group actors were responsible for the June 2022 theft of $100 million from Harmony’s Horizon bridge. The new case concerns unauthorized ONE issuance, not a confirmed breach of the old bridge’s reserves, and there is no public attribution to Lazarus in the sources reviewed.

For comparison, a recent Taiko bridge exploit involved an estimated $1.7 million loss after faulty proof validation, while the current Harmony incident centers on supply creation and the race to stop tokens from reaching venues where they can be exchanged. Both cases show how an application or protocol failure can become a liquidity event before a post-mortem is ready.

The timing also extends a heavy year for user-facing crypto security failures. TRM Labs’ H1 tally counted 207 hacks in the first six months of 2026, a record in its dataset, even though its reported aggregate losses were below the prior year’s level. Harmony’s final accounting will show whether this event adds mainly a token-supply shock, realized exchange sales, or both.

ONE Price Drop Raises Rollback Stakes

A rollback would attempt to restore Harmony to a state before the unauthorized issuance and continue from that history. It could eliminate tokens that remain on Harmony, but it would also raise questions about ordinary transfers and smart-contract activity after the chosen point. Harmony has not said what rollback height, if any, it favors.

That uncertainty is meaningful for exchanges, wallets and users. A bridge pause and address blocks are reversible containment tools; a rollback changes the accepted chain history. Any completed plan will need to say how validators are expected to act, whether exchanges will support the resulting history, and how the team will reconcile funds that crossed out of Harmony before the response.

The broader market backdrop was also cautious. The Crypto Fear and Greed Index read 27, classified as Fear, on Aug. 12. It does not measure Harmony’s incident or predict a recovery, but sharp moves in thinly traded tokens can be amplified when confidence is already low.

Fear & Greed Index

Aug. 12, 2026
27 Fear

The next verifiable milestones are Harmony’s root-cause report, the amount exchanges have frozen, an address-by-address recovery accounting, and a clear validator or governance decision on rollback. Until then, the established facts are a confirmed exploit, a reported 4 billion unauthorized ONE mint, a material token-price decline, and evidence that most of the reported mint may have reached exchange infrastructure before containment.

Stay up to date

Get the latest crypto insights delivered to your inbox

Fact-checked by: Daily Crypto Briefs Fact-Check Desk

Frequently Asked Questions

How many ONE tokens were minted in the Harmony exploit?

Harmony confirmed an exploit after reports of 4 billion unauthorized ONE tokens. Contemporary reporting put pre-incident supply at roughly 15 billion ONE, making the reported mint about 27% of that amount.

How much money was lost in the Harmony ONE exploit?

A final loss total was not disclosed. The Block reported that 4 billion ONE were worth roughly $3.2 million at its publication-time price of about $0.0008, but this is a mark-to-market estimate of the unauthorized issuance, not a final recovery or victim-loss accounting.

Did Harmony halt its network after the exploit?

Harmony said it had paused its bridge, asked exchanges to freeze linked funds, and was preparing a patch while evaluating rollback options. The sources reviewed did not announce a full chain halt or a completed rollback.

What happens if Harmony rolls back the blockchain?

A rollback would restore the chain to a point before the exploit and remove later activity from the accepted history. It could help invalidate minted tokens still on Harmony, but the result would depend on the selected rollback point, validator action and whether funds had already left the chain.