Key Highlights

  • Harmony (ONE) was exploited on August 12, with attackers minting ~4 billion ONE tokens, equal to roughly 26–27% of prior supply.

  • ONE crashed 36.58% to ~$0.0007813, pushing its market cap to about $11.72 million.

  • ~97% of the minted tokens reached exchanges or deposit wallets, while four attacker-linked wallets have been identified.

  • Harmony released patch v2026.1.1, paused the bridge, and is working with exchanges to trace funds and assess recovery options.

Harmony’s ONE token has been hit by one of the most damaging supply-side exploits seen in the Layer 1 space in 2026 — an attack that did not steal existing tokens, but created entirely new ones out of thin air, diluting the supply by more than a quarter and triggering a cascade of selling that has sent the price down more than 36% in a single session.

At the time of writing, ONE is trading at approximately $0.0007813 — down 36.58% over 24 hours — with a market capitalization of approximately $11.72 million. The token was already a smaller-cap asset before the exploit; the dilution and subsequent sell-off have compressed its market value to a level that raises serious questions about near-term viability without decisive remediation action from the team.

Harmony (ONE) Price Crash on 12 Aug 2026 | Source: Coinmarketcap

What Happened — The Harmony ONE Exploit Explained

On August 12, 2026, Harmony’s Layer 1 blockchain was hit by a sophisticated exploit in which an attacker successfully minted approximately 4 billion ONE tokens through empty blocks — a method that exploits vulnerabilities in block production or consensus mechanisms to generate tokens without the corresponding economic activity that would ordinarily be required.

The scale of the unauthorized minting is significant in context. The 4 billion newly created ONE tokens represent approximately 26–27% of the token’s previous circulating supply — meaning the attacker effectively inflated the total supply by more than a quarter in a single attack, severely diluting the holdings of every existing ONE holder instantly.

The Speed of the Sell-Off

What followed the minting was equally damaging. The attacker moved with speed and apparent preparation — routing the newly created tokens toward exchanges rapidly, triggering a wave of selling pressure that overwhelmed any existing buy-side liquidity.

The price impact varied by venue and timeframe, but the range of 25–36% decline tells the story of a market structure that had no mechanism to absorb billions of newly created tokens hitting order books in a compressed window.

Why the Exploit Was Difficult to Detect Early

A particularly notable technical detail in the early stages of this exploit: Harmony’s standard totalSupply endpoint did not initially reflect the additional 4 billion ONE. This means that conventional supply data feeds — the tools most commonly used by exchanges, analytics platforms, and market participants to monitor token economics — showed no anomaly in real time.

The invisibility of the supply inflation through standard monitoring channels allowed the attacker to move tokens toward exchanges before the broader market had a clear picture of what had occurred — a design element of the attack that significantly amplified its impact.

Four Attacker Wallets Officially Identified

The Harmony team has officially identified four wallets linked to the attacker. These addresses are now under active on-chain monitoring:

  • 0xe7427699427821230177dd13f460d6ce43014510

  • 0xf722f7f6afffe8e0dda7b4a97b2c64bb6408efe5

  • 0xed2fc1bfc2a316c15c71a0ace3ad20cb73bb08eb

  • 0xbd357b1b7cebf824b1fe4f1f5c71ac58ff1a70ba

On-chain tracking of these wallets shows that the overwhelming majority — approximately 97% — of the 4 billion minted tokens have already been moved to exchanges or exchange deposit wallets. Only approximately 115 million ONE — roughly 2.9% of the minted amount — remain on-chain at the time of writing.

The near-complete transfer of minted tokens to exchanges in such a short window is an indicator of a pre-planned, operationally sophisticated attack rather than an opportunistic exploit discovered and acted upon in real time.

Official Response — Patch Released, Bridge Paused, Rollback Under Evaluation

The Harmony team has moved on multiple fronts simultaneously in response to the exploit:

Software Patch v2026.1.1

A software patch — version v2026.1.1 — has been released and all validators have been instructed to upgrade immediately. The patch is specifically designed to close the vulnerability that enabled unauthorized minting through empty blocks, preventing any further creation of unauthorized ONE tokens going forward.

The speed of the patch release is a positive operational signal, but its practical impact depends on the percentage of validators that upgrade in a timely manner. Until the network reaches sufficient validator adoption of v2026.1.1, the vulnerability window technically remains open.

Bridge Temporarily Paused

The Harmony bridge has been temporarily paused as a precautionary measure — limiting the ability to move assets cross-chain while the team assesses the full scope of the exploit and prevents additional attack vectors from being exploited during the investigation period.

Harmony Team Response to Hack/Source: @harmonyprotocol (X)

Exchange Coordination

The Harmony team confirmed it is actively working with exchanges to trace the flow of exploited funds and freeze related wallets and deposits where possible. Given that approximately 97% of the minted tokens have already reached exchange infrastructure, the effectiveness of exchange-level freezes will be a critical factor in determining how much of the minted supply can be immobilized before being converted to other assets and withdrawn.

Rollback Under Evaluation

The team has stated it is evaluating rollback options to address the already-minted tokens — a potential mechanism to reverse the unauthorized supply addition at the chain level. Chain rollbacks are among the most consequential and controversial decisions a blockchain team can make, as they raise fundamental questions about immutability and decentralization. The precise path forward on this front remains under active investigation.

How This Differs From the 2022 Horizon Bridge Hack

It is important to distinguish today’s exploit from Harmony’s most significant prior security incident. In 2022, Harmony’s Horizon Bridge was exploited for approximately $100 million in bridged assets — a theft that involved the unauthorized movement of existing tokens that had been locked in the bridge contract.

Today’s exploit operates on an entirely different attack vector. Rather than stealing existing tokens, the attacker created new native ONE tokens from scratch — directly inflating the circulating supply and diluting every existing holder without moving a single pre-existing token. The economic harm mechanism is fundamentally different: in 2022, existing assets were stolen; in 2026, the value of existing assets was diluted through unauthorized supply expansion.

This distinction matters for understanding the remediation challenge. In a bridge hack, the stolen assets are specific and identifiable — recovery involves reclaiming known tokens. In a minting exploit of this nature, the harm is diffuse — every existing ONE holder has been diluted — and remediation requires either a chain-level rollback or acceptance of the permanently expanded supply with corresponding token value destruction.

What to Watch — Key Developments in the Coming Hours

Several critical variables will determine how this situation develops:

Exchange freeze effectiveness: With 97% of minted tokens already at exchanges, the speed and coordination of exchange-level freezes will determine whether the attacker can fully liquidate the position. Any exchanges that have already processed withdrawals from the identified wallet addresses have effectively allowed conversion of unauthorized tokens into real economic value.

Validator upgrade rate for v2026.1.1: The patch stops future minting but does not address the 4 billion already created. How quickly the validator set adopts the upgrade determines when the vulnerability is fully closed.

Rollback decision: If the Harmony team pursues a chain rollback to remove the minted tokens from the ledger, it would need broad validator and community consensus — and would raise questions about the network’s immutability guarantees. If no rollback occurs, ONE’s circulating supply is permanently ~27% larger than it was before the exploit.

Price stability: With only ~115 million ONE remaining on-chain from the minted batch and 97% already at exchanges, the primary remaining sell pressure question is whether exchanges freeze the identified deposits before they are withdrawn and sold. If freezes are effective, the acute selling pressure may be near its peak. If not, additional downward pressure remains possible.

Bottom Line

The August 12 Harmony exploit is a severe and technically sophisticated attack that has inflicted immediate, measurable harm across two dimensions: a 36.58% token price collapse driven by the dumping of unauthorized supply, and a permanent 26–27% supply dilution of every existing ONE holder’s position — unless a chain rollback is executed.

The speed and organization of the attack — including the choice of a minting vector that evaded standard totalSupply monitoring, the pre-positioning of wallets to route tokens to exchanges rapidly, and the near-complete transfer of 97% of minted tokens within hours — points to a sophisticated, pre-planned operation rather than an opportunistic discovery.

The immediate focus for market participants and ONE holders is the same: exchange freeze coordination, validator patch adoption, and the team’s rollback decision. These three variables will determine whether today’s damage is the full extent of the harm or the beginning of a longer remediation process.

Disclaimer: The views and analysis presented in this article are for informational purposes only and reflect the author’s perspective, not financial advice. Technical patterns and indicators discussed are subject to market volatility and may or may not yield the anticipated results. Investors are advised to exercise caution, conduct independent research, and make decisions aligned with their individual risk tolerance.