# Attacker Mints 4 Billion Harmony ONE Tokens and the Network Weighs a Rollback

Harmony paused its bridge to LayerZero and asked exchanges to freeze four addresses tied to the attacker, but researchers estimate that roughly 97 percent of the fraudulent tokens had already reached trading venues.

- Published: 2026-08-13T05:53:29.271Z
- Canonical: https://polylog.news/crypto/2026-08-13/attacker-mints-4-billion-harmony-one-tokens-and-the-network
- Publisher: Polylog (Crypto desk)
- Section: crypto
- Sources: [Polylog editors](https://polylog.news), [The Block](https://www.theblock.co/news/defi/2026-08-12-harmony-confirms-exploit-one-token-411527), [CoinDesk](https://www.coindesk.com/markets/2026/08/12/harmony-s-one-falls-26-after-attacker-allegedly-mints-4-billion-tokens), [CryptoSlate](https://cryptoslate.com/harmony-weighs-a-full-blockchain-rollback-after-unauthorized-minting-floods-exchanges-with-billions-in-one/)

Harmony, a proof-of-stake layer-1 network, [confirmed on Tuesday](https://www.theblock.co/news/defi/2026-08-12-harmony-confirms-exploit-one-token-411527) that an attacker created roughly 4 billion ONE tokens it never authorized. The new tokens amount to about 26 percent of the supply that existed before the incident, [according to on-chain researchers cited by crypto news channels](https://t.me/GokuCryptoNews/20350). The token fell sharply on the day, with [Decrypt reporting a 37 percent decline](https://decrypt.co/375390/harmonys-one-sinks-37-after-attacker-mints-4-billion-tokens) and [CoinDesk reporting a fall of at least 26 percent](https://www.coindesk.com/markets/2026/08/12/harmony-s-one-falls-26-after-attacker-allegedly-mints-4-billion-tokens) as trading volume surged.

Two separate failures made the incident possible. The first was the issuance path itself, which allowed minting without valid authorization. Harmony has not yet published a full root-cause report, and early accounts from independent analysts point to token creation carried out through empty blocks. The second failure was informational. The network's total-supply reporting did not immediately reflect the new tokens, so the dashboards that exchanges and market makers normally watch showed nothing unusual while the attacker moved funds. By the time the incident became public, researchers estimated that only about 115 million ONE remained under the attacker's on-chain control, with the rest sitting in exchange deposit wallets or already sold.

Harmony suspended its bridge to LayerZero, shipped a patch it told validators to install, and asked exchanges to freeze funds traced to four addresses. It is also [evaluating a full chain rollback](https://cryptoslate.com/harmony-weighs-a-full-blockchain-rollback-after-unauthorized-minting-floods-exchanges-with-billions-in-one/) to cancel the fraudulent supply. That option would undo transactions the network's own consensus had already accepted, including trades made by parties with no connection to the attack.

## What this means

The loss here is dilution, not a drained treasury. Every existing ONE holder pays for the mint through supply expansion, and the exchanges that credited deposits now carry the counterparty exposure. A rollback would shift that cost back onto whoever bought the tokens in good faith, and it would show that a small set of validators and the core team can rewrite settled blockchain history. Either outcome undermines the claim that a token's supply schedule is fixed by code rather than by the discretion of the people who run the network.

## What to watch

- Whether Harmony publishes a technical post-mortem identifying the exact issuance path that failed, which would tell holders whether the defect was in the code or in key control.
- How many exchanges actually freeze the flagged deposits, since that determines whether the attacker realizes the proceeds or is left holding an illiquid position.
- Whether validators accept a rollback, which would set a precedent other small layer-1 networks can be expected to follow after future mint exploits.
