Harmony ONE exploit

Harmony has confirmed that its blockchain was hit by a serious security breach, after an attacker managed to mint 4 billion unauthorized ONE tokens and began dumping them across exchanges. The Harmony ONE exploit triggered a sharp price crash within hours and has reignited concerns about the network’s security record, just years after one of the largest cross-chain bridge hacks in crypto history.

Key takeaways

  • Harmony confirmed an exploit involving the unauthorized minting of 4 billion ONE tokens.

  • X user Juiceberg first flagged the minting and tracked the attacker’s token movements onchain.

  • About 97% of the minted tokens have already reached exchanges and been sold or parked for sale, leaving roughly 115 million ONE still to offload.

  • ONE’s price fell 34% in 24 hours to around $0.0008, putting the stolen tokens’ value at roughly $3.2 million.

  • Harmony’s Horizon bridge was previously drained of nearly $100 million in 2022, an attack the FBI later tied to North Korea’s Lazarus Group and APT 38.

Unauthorized Minting Exploit on Harmony Blockchain

The breach came to light after an independent observer, not Harmony itself, spotted unusual activity on the network. An X user going by Juiceberg reported that an attacker had minted 4 billion ONE tokens without authorization, exploiting what appeared to be a gap involving empty blocks. Harmony later confirmed the exploit directly, addressing Juiceberg’s post in its own statement on X.

Details of the Exploit and Token Impact

According to Juiceberg’s tracking, the totalSupply endpoint did not immediately reflect the sudden increase in tokens, which made the unauthorized minting harder to detect in real time. That delay likely gave the attacker a window to begin moving funds before the wider market caught on. Unauthorized minting of this scale directly inflates the circulating supply of ONE, diluting the value held by every other holder even before a single token is sold.

Market Reaction and Token Valuation

The market reaction was immediate. ONE token dropped 34% in 24 hours, trading at around $0.0008, according to figures reported by The Block. At that price, the stolen tokens carry a current value of roughly $3.2 million — a relatively modest dollar figure by crypto-hack standards, but one that still represents a meaningful hit to a token already trading at fractions of a cent. This price collapse illustrates why unauthorized minting is treated as such a severe threat: it doesn’t just steal funds, it actively erodes the token’s market value for every holder simultaneously.

Scope of Token Movement Post-Exploit

Most of the stolen supply has already left the attacker’s control. Juiceberg’s onchain analysis found that the attacker has roughly 115 million ONE left to sell, which represents about 2.9% of the roughly 4 billion tokens originally minted. In other words, the overwhelming majority of the exploit has already played out.

“The overwhelming majority (~97%) is already on exchanges and has either been sold or is sitting in deposit wallets ready to sell,” Juiceberg wrote, describing how quickly the attacker moved to convert the illicit tokens into liquid funds. That speed suggests the attacker anticipated detection and moved to cash out before exchanges or Harmony could react.

Ongoing Response and Investigation

Harmony says it is now working with its internal team and relevant exchanges in an effort to halt and freeze the stolen funds before more of the remaining 115 million tokens can be liquidated. The platform also confirmed it is developing a patch for the vulnerability and evaluating rollback options, though no timeline has been given for either fix.

Status of Root Cause Analysis and Investigation

What remains unclear is exactly how the attacker pulled this off. Harmony has not disclosed the technical root cause of the exploit, and the incident is still under investigation. The Block reported that it had reached out to Harmony for further details, underscoring how much about this incident is still unconfirmed even as the financial fallout is already visible in ONE’s price chart.

Context: Harmony’s Previous Major Hack and Security Challenges

This is not Harmony’s first brush with a large-scale security failure. In June 2022, the project’s Horizon cross-chain bridge was exploited, with attackers making off with crypto assets valued at nearly $100 million, including Ethereum and various stablecoins. Security researchers at the time linked that breach to a compromise of the bridge’s multi-signature wallet.

2022 Horizon Cross-Chain Bridge Exploit Details

The Horizon bridge hack remains one of the more notorious DeFi exploits of its era, both for its size and for what investigators eventually uncovered about who was behind it.

FBI Attribution of 2022 Hack to North Korean State-Backed Hackers

In January 2023, the FBI formally attributed the 2022 attack to North Korean state-backed hacking groups Lazarus Group and APT 38. That attribution placed Harmony among a growing list of crypto platforms targeted by state-sponsored actors, and it raised broader questions at the time about the security of cross-chain infrastructure across the industry.

Harmony launched its mainnet in 2019 as a proof-of-stake blockchain, positioning itself as a faster and cheaper alternative to Ethereum. ONE serves as the network’s native token, used for transaction fees, staking, and governance — which is precisely why any threat to its supply integrity carries outsized weight for the ecosystem built on top of it.

Whether this newest breach turns out to be an isolated technical flaw or a sign of deeper structural weaknesses will likely shape how exchanges, developers, and holders view Harmony’s long-term security posture going forward. For now, the priority for Harmony’s team is straightforward: stop the remaining tokens from hitting the market before the patch is ready.

FAQ

What happened in the recent Harmony ONE token exploit?

An attacker minted 4 billion ONE tokens unauthorizedly, causing a significant price drop and movement of tokens to exchanges.

How is Harmony responding to the exploit?

Harmony is working with teams and exchanges to freeze stolen funds, develop a patch, and is investigating the root cause.

What impact did the exploit have on the ONE token price?

The ONE token price fell 34% within 24 hours and was trading around $0.0008 at the time of the report.

Has Harmony experienced similar security incidents before?

Yes, in June 2022, Harmony’s Horizon cross-chain bridge was exploited, resulting in nearly $100 million stolen, an attack the FBI later attributed to North Korea’s Lazarus Group and APT 38.

Article produced with the assistance of artificial intelligence and reviewed by the editorial team.