arbitrarily minting 3 trillion $ONE tokens
The veteran public chain Harmony has been breached again. This time it’s not about losing private keys; the attacker directly minted over 3 trillion ONE tokens out of thin air, treating the on-chain rules like their own printing press. If you still have ONE tokens in your wallet, you should check your balance now.
This is not the first time Harmony has had issues. Back in 2022, about $100 million was stolen from its cross-chain bridge, where locked funds on the bridge were exploited. This time, the attack was even more severe, directly manipulating the protocol layer. A public chain that claims to be secure but whose core code can be altered at will shows that governance and permission controls have long been compromised.
Here are some key points to be wary of from this incident. Public chains are not absolutely secure; decentralization in some projects is just a slogan. When multiple keys (multisig) are controlled by a few people, a single person can still bring it down. Inflation-type attacks are the most insidious—they don’t steal tokens from your address but dilute everyone’s share. Your balance number doesn’t change, but your purchasing power has been secretly cut.
When something like this happens, don’t wait for official announcements. On-chain data is faster than any statement, and being able to read the blockchain explorer is a life-saving skill. Many people don’t even know which chain their tokens are on or who holds the keys, and only think to ask in groups after the damage is done—by then it’s too late.
To be blunt, most people buy altcoins just by looking at price charts and group hype, never checking who controls the keys, whether there’s an audit, or if minting permissions are locked. Harmony paid a tuition fee of 3 trillion tokens for this lesson. When it happens to other projects, there might not be anyone to warn you in advance.
Ordinary users can do very little, but at least spread your tokens across several wallets you truly understand. Don’t put your entire fortune on a single unknown chain. Security is something you find troublesome until disaster strikes and you realize its value.
In the short term, ONE holders will likely face selling pressure and a collapse of trust. The rebound of such tokens is often just a dead cat bounce—don’t get tempted to buy just because the price has dropped a lot. In the long run, public chain security has no endpoint. The older the chain, the more likely old vulnerabilities will be targeted. Passing audits doesn’t mean permanent safety. Being a bit more cautious can save you from total loss, and that’s a worthwhile trade.
Have you really verified who controls the keys of the altcoins you hold? Don’t wait until one day you wake up to find your tokens were the batch arbitrarily minted by someone else.