The Global Crypto Press Association, headquartered in Silicon Valley w/ correspondents in the US, Europe, and Asia, Highly trusted and respected world wide.
Harmony Exploit Forged 3.01 Trillion Tokens, They Want to Fix It By Reverting Blockchain to Pre-H...
Harmony's latest security incident has gone from bad to surreal. What initially looked like an unauthorized mint of about 4 billion ONE has turned into a reconstructed total of roughly 3.01 trillion forged tokens, and the network's chosen fix is equally dramatic: roll the blockchain back to a point before the exploit and throw away everything recorded after it. Harmony says the forged supply was created through six cross-shard transactions and sent to four attacker-controlled wallets. One wallet alone moved 2.385 trillion ONE through 477 successful transfers in just 106 seconds. At pre-attack prices, that quantity had a notional value measured in billions of dollars, although no attacker could realistically sell trillions of ONE anywhere near the pre-attack market price. The Original 4 Billion Figure Was Only the Beginning Harmony first acknowledged the incident on August 12 after researchers spotted unauthorized ONE appearing through empty blocks. The early analysis identified two records that created 1 billion and 3 billion ONE. That 4 billion figure was alarming on its own because it represented a large chunk of the legitimate token supply. A deeper reconstruction changed the scale completely. Harmony's later incident update said investigators found a flaw in cross-shard receipt verification that allowed valid receipts to be processed more than once. In plain English, a cross-shard receipt is evidence that something happened on one part of Harmony's sharded network and should be credited on another. If that receipt can be reused, the receiving side can credit value repeatedly without a matching debit happening again on the sending side. That turns a bookkeeping proof into a printing press, which is generally not a feature anyone wants in a monetary system. Harmony patched the vulnerability on August 12 with Mainnet v2026.1.1 and suspended bridge services while it worked with validators, exchanges and infrastructure providers to contain the damage. The project has said it traced more than 99.9% of the forged ONE pathways to wallets or service clusters. Tracing a path, however, is not the same thing as recovering the money or identifying the person behind the wallet. Why Harmony Chose a Full Rollback The team considered less disruptive options. Those included blacklisting wallets, trying to burn forged tokens, selectively replaying legitimate transactions and even migrating ONE to a new token. Harmony concluded that each option created its own problems, especially because forged tokens had already moved through exchanges, decentralized pools, bridges and other wallets. If an innocent user received ONE that had passed through an attacker-linked pool, a blunt blacklist or burn could punish the wrong person. Selectively restoring transactions sounds cleaner until smart contracts, balances, transaction nonces and dependent transactions no longer line up with the altered history. Harmony's answer is a fixed rollback window. Its rollback plan keeps Shard 0 at block 92,730,034 and Shard 1 at block 94,978,278, both timestamped August 11 at 23:25:37 UTC. New blocks would then be produced from replacement databases built around those checkpoints. The cost is real. Harmony says the discarded window contains 141,628 consecutive blocks, 109,126 regular transactions and 315 staking transactions. Those are not all attacker transactions. Legitimate activity after the checkpoint disappears too. Harmony says about 95.8% of the affected regular transactions were automated activity, much of it associated with decentralized exchange bots. The network also said only 22 of the 109,126 regular transactions were simple native transfers with no obvious dependency in its data. Even those cannot simply be dropped back into the replacement chain with complete confidence because the state around them may have changed. This Is What Blockchain Finality Looks Like Under Stress Rollback debates tend to become philosophical very quickly because blockchains market themselves around immutability. In practice, public chains are software systems run by human communities, validators and developers. When the ledger itself has accepted a catastrophic amount of forged supply, every available choice damages something. Do nothing, and trillions of unauthorized tokens remain part of the ledger. Blacklist aggressively, and innocent holders can get caught in the blast radius. Attempt a surgical reconstruction, and subtle state mismatches can create a second disaster. Roll back the chain, and valid transactions that users reasonably believed were final are erased. Harmony chose the last option because it believes one audited cutoff applied to everyone creates the lowest risk of another exploit or consensus failure. Whether validators, exchanges, bridges and users can coordinate the restart cleanly is now the practical test. Harmony Has Been Here Before, but This Attack Is Different The incident also lands on a network with painful security history. In 2022, Harmony's Horizon bridge lost about $100 million in crypto. The FBI later attributed that theft to North Korea's Lazarus Group. That attack targeted bridge infrastructure. This one is more fundamental because the vulnerability involved the network's own cross-shard verification logic and the creation of native ONE. There is no public evidence at this point linking the current exploit to Lazarus Group, and it would be irresponsible to imply otherwise. The relevant comparison is technical and reputational: Harmony is once again asking users and counterparties to trust its recovery process after a major security failure. The patch may have closed the bug, but the harder part is restoring a coherent ledger, reconciling exchange and bridge balances, and convincing users that the replacement history can be treated as final. A blockchain can survive a rollback. Restoring confidence after trillions of tokens appeared from nowhere is the more difficult job. --------------- Author: Dorian Fenwick Silicon Valley NewsroomBreaking Crypto News Subscribe to GCP in a reader
8日間です。それだけが、リップルと、競合の多くがまさに突っ込もうとしている規制の壁との間に存在していました。決済企業は火曜日、ルクセンブルクの金融規制当局である金融セクター監視委員会(Commission de Surveillance du Secteur Financier)が、EUの暗号資産(Markets in Crypto Assets)枠組みに基づく暗号資産サービス提供者ライセンスについて、同社に対して事前の「グリーン・ライト・レター」を発行したと発表しました。タイミングは偶然ではありません。7月1日にMiCAの最終期限(ハードデッドライン)が発効し、認可を得ていないまま欧州で事業を続ける暗号企業は、技術的には突然、法律違反となります。リップルは1週間の余裕をもってこのハードルをクリアしました。業界のトラッカーによる最新の集計では、同じことを言える企業はおよそ210社にとどまります。