
Written by: Ma He, Foresight News
Hacker attacks are becoming the "number one killer" of crypto protocols.
On August 12, X user Juiceberg tweeted that on-chain data shows the Harmony protocol has suffered a vulnerability, with attackers illegally minting approximately 4 billion ONE tokens (valued at over 3 million USD) through empty blocks, accounting for 26% of its total supply. About 2.8 billion tokens were quickly transferred to exchanges during a price crash, while Harmony's total supply endpoint failed to reflect this issuance, leading to a discrepancy between actual on-chain supply and public data. The remaining on-chain amount of approximately 115 million (about 2.9% of the minted amount) is left with the attacker, while the vast majority has entered exchange accounts, either sold or stored in recharge wallets.
After the news broke, the price of ONE plummeted from $0.00118 to a low of $0.00056, and has since rebounded to $0.00078, with a 24-hour decline of nearly 38%.

Harmony's officials subsequently responded on the X platform, stating they are working with their team and several affiliated exchanges to stop and freeze the involved funds; at the same time, they are advancing software patch development and assessing network rollback options.
Officials later announced four groups of related wallet addresses, explicitly requesting exchanges to block and freeze funds traceable to these addresses:
- one1uap8dx2z0qsjxqthm5flgcxkeepsz3gsrghnfn
- one17u300a40ll5wphd8kj5hktryhdjq3ml9f4phy4
- one1a5hur07z5vtvzhr35zkw8tfqedemkz8t88xgd7
- one1h56hkxmua0uzfv07fu04cudvtrl35u96pq47vy
At around 2 PM, the officials announced the suspension of the bridge.harmony.one cross-chain bridge service due to the security incident, and requested all validating nodes to upgrade to the latest patch version v2026.1.1 immediately. The officials explained that this patch can prevent further illegal minting, with subsequent updates to handle the minted tokens. Relevant release records are already visible on GitHub.
This marks the third significant security or technical issue directly related to token supply for Harmony in recent years. In June 2022, its Horizon cross-chain bridge was attacked, resulting in the loss of approximately $100 million in assets, with the FBI later attributing the incident to North Korean hacker groups. In December 2023, a bug in the staking system led to the erroneous minting of approximately 146.3 million ONE across 74 addresses, with one address receiving over 51 million tokens, some of which were subsequently transferred to exchanges, prompting the officials to issue an emergency patch and take follow-up actions.
In terms of market size, although this incident caused significant supply dilution and price volatility, the absolute loss scale is limited. Before the incident, Harmony's market cap had fallen to around $17 million, and after the incident, it further dropped to the $12 million level, with a market cap evaporation of about $5 million. In 2022, Harmony's total TVL once peaked at over $1.4 billion, with the latest data from DefiLlama showing its TVL now under $170,000.

According to CertiK Alert monitoring, as of around 4 PM, the number of anomalously minted ONE tokens on the Harmony network has exceeded 3 trillion (valued at approximately $2.34 billion), involving six abnormal blocks.
Initially, the attackers exploited a total supply interface to hide the issuance data, and different blocks were packaged successively, so the initially reported 4 billion issuance was far from the actual data.

X account BlockWatchdog analyzed the incident, stating that the attackers took advantage of a severe logical error in Harmony's cross-shard receipt validation and signature checks, producing approximately 3 trillion coins in one go.

Harmony is a sharded chain, and transferring coins between different shards requires a "receipt" for proof. The hacker fabricated this receipt, which stated:
From a long-ago epoch (the 100th epoch, now over 3,000 epochs ago)
All signatures are empty (zero signatures)
Transferred from a dead address (0x00…dEaD)
Under normal circumstances, the system should directly reject this. However, the system has two vulnerabilities: the first is that the signature check is incorrect. When the system checks "Is there enough people signed?", it only looks at "how many people are on the committee," rather than "how many people actually signed." As a result: as long as the committee size ≥4, even empty signatures can pass. It's like a broken door lock that can be opened by just pushing it. Secondly, the uniqueness protection has vulnerabilities; the system's check for "has this receipt been used?" relies on fields that the attacker can fill in during the old epoch. Therefore, the attacker can repeatedly use the same fake receipt or bypass the check.
With both vulnerabilities combined, the attacker can mint trillions of coins at once.
As of the time of publication, officials have not confirmed whether they will execute a network rollback. A rollback means restoring the chain state to a certain point before the attack occurred, theoretically clearing some of the effects of illegal minting, but once a large number of tokens have entered centralized exchanges and completed transactions, the actual effect will be significantly limited. Whether exchanges effectively freeze the related funds, the progress of the patch's dissemination among validating nodes, and the subsequent handling of minted tokens will be the core variables of short-term market attention.
Harmony, as an early Layer 1 public chain focusing on high performance and low fees, once held a certain position in the DeFi and cross-chain narrative. Continuous security events combined with long-term market cap shrinkage have significantly reduced its visibility in the current crypto market.
This incident again exposes the vulnerability of low-market-cap public chains in consensus and supply mechanisms, and reminds market participants to more cautiously evaluate the historical security record and actual on-chain activity of similar projects.
免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。