Intelligence Brief
Harmony has confirmed an exploit involving the unauthorised creation of approximately four billion ONE tokens, equal to more than one quarter of the token’s pre-incident supply. The figure originated from on-chain analysis and has not yet been independently finalised by Harmony.
The attacker reportedly transferred much of the newly created supply towards centralised exchanges. Harmony responded by identifying four associated wallet addresses, asking exchanges to block traced funds and pausing its bridge infrastructure. Validators were instructed to install an emergency software update intended to prevent further minting.
The project is also assessing whether to reverse affected blockchain activity. No final rollback decision has been announced. The technical root cause, the quantity successfully sold and the amount frozen by exchanges remain undisclosed.
We are working with our team and appropriate exchanges to stop and freeze the funds.
We are working on a patch and rollback options.
Will update when we have new information. https://t.co/XB0nCwTAyN
— Harmony ???? (@harmonyprotocol) August 12, 2026
Strategic Assessment
The immediate risk is dilution. Existing ONE holders now face a larger token supply unless Harmony can invalidate the unauthorised balances through a rollback or another network-level intervention.
Both responses carry costs. Leaving the minted tokens active protects chain finality but transfers the financial damage to holders. Reversing transactions may recover some value, but it would require validator coordination and could undermine confidence that settled Harmony transactions remain final.
Exchanges control part of the containment process because the attacker reportedly routed tokens through their infrastructure. Effective freezes would reduce immediate selling pressure, although they would not repair the supply defect on-chain.