Morning Edition · Thursday, August 13, 2026Published at 1:53 AM EDT · New York
Harmony paused its bridge to LayerZero and asked exchanges to freeze four addresses tied to the attacker, but researchers estimate that roughly 97 percent of the fraudulent tokens had already reached trading venues.

Harmony, a proof-of-stake layer-1 network, confirmed on Tuesday that an attacker created roughly 4 billion ONE tokens it never authorized. The new tokens amount to about 26 percent of the supply that existed before the incident, according to on-chain researchers cited by crypto news channels. The token fell sharply on the day, with Decrypt reporting a 37 percent decline and CoinDesk reporting a fall of at least 26 percent as trading volume surged.
Two separate failures made the incident possible. The first was the issuance path itself, which allowed minting without valid authorization. Harmony has not yet published a full root-cause report, and early accounts from independent analysts point to token creation carried out through empty blocks. The second failure was informational. The network's total-supply reporting did not immediately reflect the new tokens, so the dashboards that exchanges and market makers normally watch showed nothing unusual while the attacker moved funds. By the time the incident became public, researchers estimated that only about 115 million ONE remained under the attacker's on-chain control, with the rest sitting in exchange deposit wallets or already sold.
Harmony suspended its bridge to LayerZero, shipped a patch it told validators to install, and asked exchanges to freeze funds traced to four addresses. It is also evaluating a full chain rollback to cancel the fraudulent supply. That option would undo transactions the network's own consensus had already accepted, including trades made by parties with no connection to the attack.
Traders who shorted ONE and the exchanges lobbying for a rollback that would move the loss back onto buyers, while Harmony's core team gains cover for a discretionary intervention it would otherwise struggle to justify.
Part of a tracked trend
Bridge and Mint Exploits Sustain Heavy DeFi Losses
Over 3-6 months, recurring bridge proof-validation and unauthorized-mint exploits keep monthly DeFi losses elevated, including drains of deprecated contracts.
Start a discussion in Townsquare.
More from this edition
Harmony has confirmed the unauthorized mint and is only weighing a rollback, but the load-bearing detail is unresolved: whether the issuance path failed through a code defect or through compromised key control, and the 97 percent figure and the price decline both come from third parties whose numbers disagree (CoinDesk has cited 40 percent, Decrypt 37 percent, others 26 to 30 percent).
An open-source-intelligence read of how likely this story is true with its real nuance, not a judgment of any outlet. It assesses the claim, weighing independent and adversarial reporting. How we label confidence.
What this means
The loss here is dilution, not a drained treasury. Every existing ONE holder pays for the mint through supply expansion, and the exchanges that credited deposits now carry the counterparty exposure. A rollback would shift that cost back onto whoever bought the tokens in good faith, and it would show that a small set of validators and the core team can rewrite settled blockchain history. Either outcome undermines the claim that a token's supply schedule is fixed by code rather than by the discretion of the people who run the network.
What to watch
Observations to monitor, not financial advice.
Synthesized from: Polylog editors · The Block · CoinDesk · CryptoSlate
Comments
1Aug 13, 6:00 AM · edited
With 97 percent of the fraudulent tokens already at exchanges, a rollback requires every major venue to absorb or reverse trades, making the decision an exchange governance question rather than a chain governance question.