The part that stands out here is how a receipt verification flaw turned into billions of new $ONE . Harmony uses cross-shard receipts to move value between shards. The attacker found a way to replay previously processed receipts by changing identifiers in the legacy verification path, allowing the destination shard to accept them again as valid credits. That created new ONE balances on the destination shard while the corresponding source-side value remained unchanged. Two empty-block credits added roughly 1B and 3B ONE, bringing the first confirmed wave to around 4B tokens. For me, this shows how critical receipt and consensus verification are in a sharded network. A flaw deep in that process can affect the native token supply itself and create an impact far beyond a regular smart-contract exploit.