Imagine waking up and discovering that billions of new tokens had suddenly appeared on a blockchain.

That's essentially what happened to Harmony's $ONE on August 12.

An attacker exploited a vulnerability in the Harmony network and reportedly minted roughly 4B ONE tokens without authorization. It's equivalent to about 26% of the supply that existed before the attack.

How it happen.
On-chain analyst Juiceberg reported that the attacker was able to create the tokens through empty blocks, blocks containing no normal transactions: https://x.com/i/status/2087353885765620127

However, Harmony has not yet publicly disclosed the exact technical vulnerability

From the on-chain investigation, 4 billion ONE were reportedly created, 2.8 billion ONE were sent toward, exchanges, Juiceberg estimated that roughly 97% of the newly minted tokens had already reached exchanges or exchange deposit wallets, leaving about 115 million ONE on-chain under the attacker's control at the time of the report.
Also, Harmony's public total Supply endpoint reportedly did not immediately reflect the newly created tokens even while the attack was unfolding.

What Harmony is doing.
The team released an emergency patch to stop further unauthorized minting and paused its bridge: https://x.com/i/status/2087428910829261013
Exchanges were asked to freeze funds connected to four identified wallet addresses: https://x.com/i/status/2087410115200889135
Harmony is also evaluating a potential blockchain rollback: https://x.com/i/status/2087395174263705704
Harmony said it has traced 10,288 transfers across 409 wallets where the fraudulently minted tokens had landed: https://x.com/i/status/2087487246148542527

The lesson learned.
It wasn't a normal wallet hack.
The attacker didn't simply steal existing ONE.
An existing holder got affected by the sudden dilution.
We need to actually know more about the code controlling the supply of the tokens we hold.
#Macro Insights#