
Harmony's ONE token crashed to an all-time low of $0.0005735 during early Asian trading on Wednesday, representing a 29% decline from previous levels. The token had earlier touched its record low before recovering slightly to trade near $0.00087 at press time. This dramatic price action follows an apparent exploit that created approximately 4 billion new tokens without authorization, with the minted amount equal to about 26% of ONE's total supply. The sell pressure from the exploit has sent the token tumbling as trading volume surged above $36.9 million on Wednesday, with the token's market capitalization standing near $13.7 million during the trading session.
Harmony's ONE token experienced a dramatic 32% decline over 24 hours following an apparent exploit that created approximately 4 billion new tokens. According to on-chain analyst Juiceberg, the unauthorized mint occurred through empty network blocks, with about 2.8 billion ONE reportedly reaching centralized exchanges. The exploit created tokens equal to more than a quarter of the token's existing supply, significantly impacting the blockchain's security and token economics. As reported by crypto.news, the reported mint would represent roughly 27% of ONE's previously reported circulating amount of approximately 15 billion tokens, though Harmony has not independently confirmed these figures. Another 115 million ONE remained available for on-chain sales, representing nearly 3% of the fraudulently minted supply. Most minted tokens had reached exchanges, been sold, or remained in deposit addresses, with the remaining balance suggesting the exploit's full impact is still being realized.
Harmony confirmed the attack in an X post and announced immediate action to address the security breach. The team stated it is working with exchanges to freeze the funds and preparing a software patch while evaluating rollback options. Harmony has now named four wallet addresses tied to the incident and asked all exchanges to block and freeze funds traced to them: one1uap8dx2z0qsjxqthm5flgcxkeepsz3gsrghnfn (0xe7427699427821230177dd13f460d6ce43014510), one17u300a40ll5wphd8kj5hktryhdjq3ml9f4phy4 (0xf722f7f6afffe8e0dda7b4a97b2c64bb6408efe5), one1a5hur07z5vtvzhr35zkw8tfqedemkz8t88xgd7 (0xed2fc1bfc2a316c15c71a0ace3ad20cb73bb08eb), and one1h56hkxmua0uzfv07fu04cudvtrl35u96pq47vy (0xbd357b1b7cebf824b1fe4f1f5c71ac58ff1a70ba). The network has not disclosed the root cause of the incident yet, with BeInCrypto reaching out to Harmony for comment. A rollback would involve returning the network to a point before the exploit and continuing from there, effectively removing some transactions from the blockchain's accepted history, though no public timetable has been provided for either patch deployment or potential rollback.
While Harmony was seeking collaboration with exchanges and investigators, prominent on-chain investigator ZachXBT took a different stance. ZachXBT urged others not to help Harmony for free, citing the network's treatment of investigators during the $100 million Harmony Bridge exploit in 2022 by North Korea's Lazarus Group. According to AMBCrypto, ZachXBT stated that Harmony took advantage of people who assisted during the previous exploit by DPRK, rewarding $0 for significant freezes which led to LE seizures and simply saying "good job." However, ZachXBT's take received mixed reactions from the community, with some backing the stance while others opposed it. A user who opposed the request wrote, "I assisted with dozens of incidents and I don't remember ever getting anything but recognition out of it." As of press time, 53% of validators had completed Harmony's call to action, which stated that all validators should upgrade to prevent further minting.
The Harmony incident follows similar security challenges across the blockchain industry, with crypto exploits causing $12.37 million in losses during August's first 12 days according to AMBCrypto. The apparent exploit comes after Ravencoin faced its own possible rollback after invalid blocks were accepted by parts of its network. The two incidents highlight the trade-off involved in rollbacks — while undoing attacks can prevent attackers from keeping newly created tokens, it also risks undoing legitimate transactions made after the exploit occurred. Harmony has not yet explained the vulnerability or provided details on how far back any proposed rollback would go, with the next verified update needing to establish the root cause, actual amount created, and whether the network will deploy a patch or pursue a rollback. The incident underscores the ongoing security challenges facing blockchain networks as they continue to evolve and expand their functionality.