The $4B #Harmony hack was actually a free money glitch. An attacker minted about 4 billion $ONE tokens out of thin air, diluting every existing holder by roughly 26% .

Here is what happened.

On August 12, an attacker exploited a vulnerability in Harmony's cross-shard validation logic to mint 4 billion ONE through empty blocks . The chain's totalSupply endpoint didn't reflect the new tokens immediately, giving the attacker a window to move funds before anyone noticed .

The damage was brutal. Around 2.8 billion tokens were funneled to exchanges within hours, and about 97% of the minted supply is now either sold or sitting in exchange deposit wallets . The price crashed 34-40%, hitting an all-time low of $0.00057 . The project's market cap was already only about $17 million before the attack, so the actual dollar loss is modest, but the dilution for holders was devastating .

Harmony responded by patching the bug, pausing its bridge, and asking validators to upgrade immediately to prevent further minting . They also named four attacker wallets and asked exchanges to freeze linked funds . The team is now weighing a chain rollback, a controversial move that would undo the exploit but also erase legitimate transactions made after the attack .

The lesson is simple. The attacker didn't steal existing tokens. They created new ones, flooding the market and crashing the price before anyone could react. If a chain can't guarantee its own supply integrity, trust in the whole system is the real casualty.