The exploit expanded circulating supply by roughly 26 per cent through empty blocks, and 2.8 billion of the newly minted tokens reached exchanges before Harmony could freeze anything. A network rollback is on the table for the second time in Harmony's history.
Harmony's native token ONE fell to an all-time low of $0.0005735 during Asian trading hours on Wednesday after an attacker used empty blocks to mint roughly 4 billion new ONE without authorisation. Roughly 15 billion ONE existed before the incident, meaning the mint expanded circulating supply by about 26 per cent in a matter of minutes and pushed the price down more than 50 per cent intraday before recovering to about $0.0008.
Harmony confirmed the exploit on X and said it is working with exchanges to freeze the funds. According to the on-chain analyst Juiceberg, who flagged the incident first, roughly 2.8 billion of the 4 billion minted tokens reached exchanges before any coordinated response — either already sold into the drop or sitting in deposit wallets ready to sell. The attacker still holds approximately 115 million ONE on-chain, about 2.9 per cent of what was minted. At the depressed price, the stolen amount is worth around $3.2 million, but the damage is more accurately measured in the destruction of ONE's market cap and the confidence of anyone still staking on the network.
The Harmony team paused the Horizon bridge, released a validator patch labelled v2026.1.1 to block further unauthorised minting, and said it is evaluating a rollback. A blockchain rollback returns the network to a state before the exploit and continues from there, dropping every transaction that followed. It only works while the stolen tokens remain on-chain; once they have crossed to another blockchain or been sold through a centralised exchange, the rollback can undo the mint but not recover the proceeds. Most of the 4 billion ONE has already crossed that threshold.
There is also the philosophical cost. Immutability is the property that separates a blockchain from a database, and a rollback voluntarily suspends it. Ravencoin's community faced the same choice a day earlier, when miners rebuilt the chain to erase four days of transactions after a critical block-header flaw. The industry generally treats rollbacks as an act of last resort because they punish every legitimate user who transacted after the exploit alongside the attacker.
This is not the first supply crisis Harmony has managed. In June 2022, its Horizon cross-chain bridge was drained of nearly $100 million after attackers compromised the multi-signature wallet controlling it. The FBI subsequently attributed the theft to North Korea's Lazarus Group and APT 38. In December 2023, a bug in Harmony's staking system created roughly 146.3 million ONE that should never have existed, and the network responded with an emergency software update and a blacklist. Wednesday's incident is a third and larger event, and the pattern begins to look structural rather than incidental.
What is different this time is the class of vulnerability. The 2022 theft was custody: someone compromised private keys. The 2023 mint was a bug in staking rewards logic. Wednesday's incident, based on Juiceberg's read of the chain, appears to have exploited how Harmony's consensus handles empty blocks, a lower-level protocol issue than either earlier failure. Harmony has not yet disclosed the technical root cause, but the fact that the fix is a validator patch rather than a smart-contract update points to something in the chain's block production or validation logic.
The market response has been unforgiving. ONE was already trading below a penny before the attack; the token is now worth less than a tenth of a cent, and any rollback proposal will be complicated by the fact that legitimate holders and speculators have been buying at the depressed price. Any state chosen for the rollback penalises somebody. If Harmony rolls back too far, it wipes out legitimate transactions; if it does not roll back far enough, the attacker keeps proceeds already off-ramped.
Harmony launched in 2019 as a proof-of-stake layer 1 marketed as a faster, cheaper Ethereum alternative. The 2022 bridge attack cost it roughly $100 million in user funds, followed by a controversial 2022 proposal to mint billions of ONE to reimburse victims — a proposal ultimately abandoned. The comparison writes itself. A network whose response to a $100 million exploit was to propose printing tokens has now had four billion of those tokens printed for it, without permission, by an attacker who exploited a fault in the chain itself.