Harmony to Roll Back Its Blockchain After Attacker Transferred 2.385 Trillion ONE Tokens in 106 Seconds
Harmony announced on August 17 that it will revert its blockchain to checkpoints recorded before a consensus-layer exploit allowed an attacker to generate roughly 3 trillion ONE tokens, nearly 200 times the network's legitimate circulating supply of approximately 15 billion.
Reports across several outlets, including TechTimes, defimon.xyz, and CoinDesk, cited a figure of approximately 4 billion ONE tokens minted, likely reflecting the volume of tokens meaningfully distributed or sold at the exchange level rather than the full consensus-layer forgery total. Both figures describe aspects of the same attack but measure different stages of the incident.
The attack occurred at 23:25 UTC on August 11, 2026. Within 106 seconds, 2.385 trillion of the forged tokens moved across 477 on-chain transfers.
By the time Harmony issued a public statement, an estimated 97 percent of the minted supply had already reached exchange deposit wallets or been sold. Only around 115 million ONE tokens remained on-chain at disclosure. Users who sold ONE on exchanges during the attack window may face complications if those exchanges pursue recovery measures in coordination with investigators.
The token's price fell roughly 40 percent over seven days, dropping to approximately $0.0008 and leaving the network's market capitalization near $11.5 million.
How the Exploit Worked
The attacker exploited a logic flaw in Harmony's quorum verification code, the mechanism that confirms a sufficient number of validators have signed off on a block before it is accepted. The bug caused the software to count public key slots in a signature mask rather than check whether those keys had actually produced valid signatures. This meant a consensus message carrying zero legitimate signatures could pass the quorum check entirely.
Harmony paused its cross-chain bridge immediately after the attack was identified and deployed a patched software version, labeled 2026.1.1, on August 12 to close the vulnerability.
A compounding monitoring blind spot added to the damage: Harmony's own totalSupply endpoint continued reporting the pre-exploit token count throughout the attack window. Anyone monitoring chain health through the protocol's native interface would have seen no anomaly while trillions of tokens circulated and were sold.
Why Harmony Chose a Rollback
The team evaluated four recovery options before settling on a rollback to two pre-exploit block checkpoints. Shard 0 will revert to block 92,730,034 and Shard 1 to block 94,978,278, both timestamped at 23:25:37 UTC on August 11.
Harmony described the rollback as "the fairest and most secure" resolution available. All communications regarding the incident have been issued collectively by the Harmony Team, with no named executives or spokespeople identified as of publication.
The alternatives were each rejected for practical reasons. Burning the forged tokens was not viable because they had already dispersed across exchange wallets, decentralized exchange pools, smart contracts, and individual wallets. A targeted burn risked destroying tokens held by users who had no connection to the attack.
Blacklisting attacker wallets was ruled out because the forged supply would remain technically intact and legitimate wallets could be caught in the filter.
Selectively replaying transactions onto a clean chain was dismissed due to the risk of producing inconsistent state outcomes.
Token migration was judged more disruptive than a rollback outright.
The rollback will discard 109,126 regular transactions and 315 staking transactions processed after the exploit. The team noted that 95.80 percent of those transactions were bot-generated, with automated DEX systems accounting for 99,863 of the discarded records including 75,430 completed swaps.
The recovery process uses replacement databases rather than the blockchain's built-in rewind function, because the native rewind "mainly moves chain heads and does not fully clear later receipts, indexes, snapshots, and cross-shard information," according to the development team.
Exchanges, bridges, and law enforcement agencies are cooperating with the investigation, and Harmony has requested freeze orders on two wallets linked to the attacker. Smart contracts, NFT marketplaces, and DeFi protocols that processed transactions during the approximately five-day post-exploit window will be left in an inconsistent state after the rollback, a significant consequence for developers who built active applications on the network.
Impact on Users in South Asia and Africa
The timing and structure of the exploit carry specific consequences for retail users in high-adoption markets across South Asia and Africa. India ranked first globally in the 2025 Chainalysis Global Crypto Adoption Index, with Pakistan in the top five.
Harmony marketed itself as a low-cost DeFi (decentralized finance) network, with staking accessible at as little as 100 ONE for delegators and transaction fees of fractions of a cent. Those features positioned it as an accessible option in cost-sensitive markets.
The attack unfolded late at night in UTC, which corresponds to early morning hours in India and Pakistan. Users who traded ONE in good faith during that window will have their transactions erased by the rollback. No compensation mechanism for those users has been announced.
The totalSupply monitoring blind spot is a particular concern in African markets, where retail participants may rely on protocol-native dashboards rather than third-party analytics platforms to gauge a network's health. Professional-grade monitoring tools are not uniformly available across the region. Sub-Saharan Africa recorded 52 percent growth in crypto activity in the most recent measurement cycle, reflecting deepening retail participation across the continent. Harmony's low-fee DeFi applications and DeFi Kingdoms had attracted users in West and East Africa specifically as alternatives to expensive centralised exchanges and remittance corridors. Nigeria and Kenya, two of the region's most active markets, already contend with periodic regulatory restrictions on crypto activity, and the collapse of Harmony's supply integrity is expected to compound skepticism toward smaller Layer-1 chains in those jurisdictions.
Third Major Incident in Four Years
This is the third significant security incident on Harmony in four years. In June 2022, attackers confirmed by the FBI in January 2023 as North Korea's Lazarus Group exploited a weak multisig configuration on the Horizon bridge to drain approximately $100 million. Following that hack, Harmony put forward a controversial proposal to mint more than 2 billion new ONE tokens to compensate victims, a remediation approach that drew public criticism and highlighted a recurring pattern: governance-first solutions that treat chain state as adjustable rather than inviolable.
In December 2023, a staking system bug produced around 146.3 million unauthorized tokens across 74 addresses.
The current exploit is the most technically sophisticated of the three, targeting the consensus layer rather than a bridge or smart contract, according to security analysts who reviewed the incident.
The decision to roll back the chain is rare in the industry. The closest comparable event is the 2016 Ethereum hard fork reversing the DAO hack, which caused a permanent community split into Ethereum and Ethereum Classic. Ethereum developers rejected similar proposals after the 2025 Bybit hack, citing immutability as a core principle.
Harmony's smaller validator set and more centralized development coordination made execution here more tractable, but the rollback confirms a governance posture where chain state is not treated as unconditional. Security analysts note that developers building settlement-critical applications on ONE will need to weigh that precedent carefully.