Summary
Harmony's ONE token fell about 40% in Asian morning hours Wednesday after an apparent exploit created roughly 4 billion new tokens, an amount equal to more than a quarter of the token's existing supply. The company confirmed the attack and told network operators to install an emergency software update to prevent further minting, while separately working on how to deal with tokens already created. Harmony also paused its token bridge and asked exchanges to freeze funds traced to four addresses linked to the incident.
Key Facts
- Harmony's ONE token plunged ~40% after an apparent exploit created ~4 billion new tokens
- The minted amount equals more than a quarter of the token's existing supply (~15 billion ONE existed before)
- Harmony confirmed the attack and issued an emergency software update to prevent further minting
- Paused its token bridge and asked exchanges to freeze funds traced to four addresses
- Working on a patch and rollback options
- A rollback would return the network to a state before the exploit, removing subsequent transactions
- Harmony is a layer 1 blockchain for DeFi protocols and marketplaces
- Follows a Dec 2023 bug that created ~146.3 million ONE
- Harmony was hit by a ~$100 million bridge attack in 2022, attributed to North Korea's Lazarus Group
- Comes a day after Ravencoin faced a possible rollback after accepting invalid blocks
Why It Matters
The Harmony exploit highlights persistent security vulnerabilities in blockchain networks and the difficult trade-offs involved in responding to attacks. The incident — which involved unauthorized token creation on the chain itself rather than assets stolen from a bridge — raises questions about the integrity of token supply and the immutability principle that underpins blockchain. A potential rollback would prevent the attacker from keeping newly created tokens but becomes harder once funds reach exchanges, and many in the industry view rollbacks as antithetical to blockchain's core principle of immutability. The episode, coming a day after Ravencoin's similar issue, underscores the recurring challenge of token-creation bugs and the security risks facing smaller layer 1 networks.