#HackerAlert
🚨 Critical bug in Harmony ($ONE ): under attack again, full network rollback considered
The Harmony network was compromised by a mathematical vulnerability at the protocol level, which allowed attackers to hoard billions of native $ONE tokens “out of thin air”.
🔍 What happened?
Mathematical flock: Thanks to two vulnerabilities in cross-shard receipts, attackers were able to pass quorum checks without proper validator signatures, as well as reuse already used receipts.
Emission scale: According to estimates by on-chain researcher Juiceberg, about 4 billion ONEs have been created (~26% of the total supply), of which at least 2.8 billion have already hit the exchanges. Harmony has not yet confirmed the exact numbers.
Emergency update: Harmony released patch v2026.1.1 for validators, which closed the verification holes and stopped further unauthorized minting.
📉 Market reaction and security measures
The bridge bridge.harmony.one has been temporarily suspended.
The Harmony team published the addresses of 4 wallets of attackers and called on exchanges to freeze the detected funds.
Price collapse: Against the background of the news, the $ONE token fell by almost 39% in 24 hours, and the total capitalization of the project decreased to $11.27 million.
Rollback possibility: The developers are considering the option of restoring the network state to the time of the attack, but a final decision has not yet been made.
⚠️ Unlike the Horizon bridge hack in 2022 (where multisig private keys were compromised), this time the problem arose directly in the logic of transaction confirmation and protocol quorum.
🚨 Critical bug in Harmony ($ONE ): under attack again, full network rollback considered
The Harmony network was compromised by a mathematical vulnerability at the protocol level, which allowed attackers to hoard billions of native $ONE tokens “out of thin air”.
🔍 What happened?
Mathematical flock: Thanks to two vulnerabilities in cross-shard receipts, attackers were able to pass quorum checks without proper validator signatures, as well as reuse already used receipts.
Emission scale: According to estimates by on-chain researcher Juiceberg, about 4 billion ONEs have been created (~26% of the total supply), of which at least 2.8 billion have already hit the exchanges. Harmony has not yet confirmed the exact numbers.
Emergency update: Harmony released patch v2026.1.1 for validators, which closed the verification holes and stopped further unauthorized minting.
📉 Market reaction and security measures
The bridge bridge.harmony.one has been temporarily suspended.
The Harmony team published the addresses of 4 wallets of attackers and called on exchanges to freeze the detected funds.
Price collapse: Against the background of the news, the $ONE token fell by almost 39% in 24 hours, and the total capitalization of the project decreased to $11.27 million.
Rollback possibility: The developers are considering the option of restoring the network state to the time of the attack, but a final decision has not yet been made.
⚠️ Unlike the Horizon bridge hack in 2022 (where multisig private keys were compromised), this time the problem arose directly in the logic of transaction confirmation and protocol quorum.