How Hackers Minted ~4 Billion ONE on Harmony An attacker exploited a critical flaw in Harmony’s cross-shard receipt system, allowing the unauthorized creation of roughly 4 billion $ONE tokens (about 26% of the prior circulating supply). Technical breakdown of the “free money” glitch: ➫ Harmony is a sharded blockchain. Moving value between shards requires cryptographic “receipts” that prove a transaction occurred on the source shard.
➫ The attacker forged receipts that contained: > An extremely old epoch (epoch 100, while the network is currently in the 3000s)
> Completely empty (zero) signatures
> Transfers originating from a dead address (0x00…dEaD)

➫ Two overlapping bugs made the forgeries valid: 1. The signature-verification logic only checked the size of the validator committee rather than whether any actual signatures were present. As long as the committee had ≥4 members, empty signatures still passed the quorum check.
2. Replay-protection for older epochs relied on a field the attacker could control, allowing the same fake receipt to be reused repeatedly.

These forged receipts were processed through empty blocks, quietly inflating the ONE supply. Harmony’s public totalSupply endpoint did not immediately reflect the new tokens, delaying detection. The attacker rapidly moved ~2.8 billion of the newly minted ONE to exchanges. Only about 115 million remained on-chain at the time of reporting. Harmony has since released an emergency patch (v2026.1.1) that closes the receipt flaws, paused its bridge, and asked exchanges to freeze the identified wallets. A possible chain rollback is still under evaluation. Harmony’s Cross-Shard Receipt Flaw Let Attackers Mint Billions of ONE Out of Thin Air Does this kind of consensus-layer logic error change how you view the security of other sharded or multi-chain networks?

#BTC Price Analysis# #Bitcoin Price Prediction: What is Bitcoins next move?# $BTC #Macro Insights#