
Harmony, a Layer 1 blockchain, has confirmed a critical exploit in which approximately 4 billion ONE tokens were minted without authorization via empty blocks, representing roughly 26% of the token’s pre-existing supply.
On-chain analyst Juiceberg reported that the attacker quickly routed around 2.8 billion ONE to centralized exchanges as the token price collapsed. According to Juiceberg, the attacker retains only about 115 million ONE on-chain—roughly 2.9% of the illicit supply—while “the overwhelming majority, approximately 97%, is already on exchanges and has either been sold or is sitting in deposit wallets ready to sell.”
The market reaction was immediate. ONE plunged approximately 40% to trade near $0.0008, placing the nominal value of the stolen tokens at roughly $3.2 million. Compounding the opacity, Harmony’s totalSupply endpoint did not immediately reflect the inflation, potentially obscuring the dilution from users and monitoring systems.
In response, Harmony instructed validators to install an emergency patch preventing further minting, paused its token bridge, and published four wallet addresses linked to the incident, asking exchanges to freeze associated funds. The network stated it is developing a comprehensive patch and evaluating rollback options.
The incident has drawn renewed scrutiny to Harmony’s history of security lapses and its treatment of the investigator community. On-chain investigator ZachXBT publicly refused to assist with the current incident, stating: “I will not be tracking this incident and think no one should assist them for free.”
He cited Harmony’s handling of the 2022 Horizon Bridge exploit—attributed by the FBI to North Korea’s Lazarus Group—in which the network allegedly “took advantage of people who assisted” and “rewarded $0 for significant freezes which lead to LE seizures and simply said ‘good job.'”
This boycott emphasises a deepening trust deficit as Harmony considers a blockchain rollback, which would revert the network to a pre-exploit state but erase subsequent transactions—a measure widely viewed as antithetical to blockchain immutability. The task is further complicated by the fact that most funds have already reached exchanges.
The exploit also marks Harmony’s third major security failure in recent years, following a December 2023 staking bug that created 146.3 million ONE and the 2022 bridge attack that drained approximately $100 million. Harmony has not yet disclosed the technical root cause of the current breach.
The post Harmony Suffers Critical Exploit As 4B ONE Are Minted Without Authorization, ZachXBT Boycotts Recovery Efforts appeared first on Metaverse Post.