When a crypto exploit occurs, ZachXBT is usually the first on-chain sleuth tracing the stolen funds before they vanish, but he is publicly refusing to help Harmony this time around. This is not the first time he's refusing a case this year, the most recent is the ColdCard hack issues.
The crypto community's most prolific tracker isn't racing anywhere, and he's not being quiet about why, dragging up a grievance from 2022 that, in his telling, still hasn't been settled.
ZachXBT's refusal came directly in response to news of Harmony's new exploit, and his wording left little room for interpretation. He said he won't track this incident, and doesn't think anyone else should help Harmony for free either, pointing back to the aftermath of the $100 million Horizon Bridge exploit carried out by North Korea's Lazarus Group in June 2022. According to him, Harmony leaned on outside assistants during that recovery effort and rewarded major freezes with nothing more than a "good job."

I think it's worth sitting with how unusual this is. ZachXBT has built his entire reputation on tracing stolen funds across dozens of major exploits, often working unpaid purely out of principle. For him to draw a hard line and say publicly that he won't extend that same effort to Harmony specifically, and to actively discourage others from doing so too, is a genuinely pointed statement about how he believes the project has treated the people who've helped it in the past.
The new incident is serious on its own merits. Harmony confirmed it had been exploited after on-chain analyst Juiceberg reported that an attacker minted roughly 4 billion ONE tokens without authorization, using empty blocks to push the new supply into existence, an amount equal to roughly 26% of the token's entire prior circulating supply of about 15 billion.

ONE's price crashed more than 30% in early Asian trading hours, at one point touching a new all-time low near $0.0005735, as newly minted tokens flooded onto exchanges. Juiceberg's analysis found that roughly 2.8 billion of the minted tokens moved quickly onto trading platforms, with the attacker reportedly holding back only around 115 million ONE, less than 3% of the total minted, still sitting unsold on-chain.

Harmony moved fast once the exploit was confirmed, and its own statements lay out the response in detail. The protocol posted directly that it was working with its team and relevant exchanges to stop and freeze the affected funds, while simultaneously developing a patch and weighing rollback options.
In a follow-up post, Harmony went further, publicly naming four specific wallet addresses, both on its own network and on Ethereum, and asking every exchange to block and freeze any funds traced back to them. The team confirmed it had paused its bridge with LayerZero as a precaution, and asked all network validators to apply an emergency patch specifically designed to prevent any further unauthorized issuance.

The team also confirmed it's actively considering a full blockchain rollback, effectively resetting the network to a state before the exploit occurred and treating everything after that point as if it never happened.
I think the pattern here deserves more attention than it's getting in most of the coverage. This is actually the second time Harmony has dealt with tokens being created outside of normal, authorized channels. Back in December 2023, a bug in the network's staking system caused roughly 146.3 million ONE to be improperly created after certain addresses kept receiving staking payouts they should have stopped receiving. Harmony's response then was an emergency software patch and blacklisting the addresses holding the improperly minted tokens. Add in the original $100 million Horizon Bridge theft in 2022, later formally attributed by the FBI to North Korea's Lazarus Group and APT38, and this latest incident marks Harmony's third major security failure in roughly four years.

I don't think ZachXBT's stance here is really about Harmony alone, even though Harmony is bearing the brunt of it. It reads to me as a broader statement about an uncomfortable pattern across the industry: projects that suffer major exploits often lean heavily on volunteer on-chain investigators to trace stolen or improperly minted funds, generate the intelligence exchanges need to freeze accounts, and do the unglamorous, time-consuming work of following a trail across dozens of wallets, all without any formal compensation structure in place for that labor.
If ZachXBT's account of the 2022 aftermath is accurate, and he's stated it plainly and publicly enough that it would be a significant claim to make falsely, then Harmony asked for and received that kind of unpaid effort once already during a $100 million crisis, and offered essentially nothing back once the emergency had passed. Whether or not other independent researchers follow his lead this time, his refusal puts a genuinely uncomfortable question in front of the industry: if the people capable of tracing stolen funds start declining to help for free, what happens to exploited projects that have burned through that goodwill already?
For now, Harmony's own team has not disclosed the exact technical vulnerability that allowed the unauthorized minting to occur, nor confirmed a final, verified total for how many tokens were actually created. The project says it's still coordinating with exchanges on freezing the flagged addresses, still finalizing its validator patch, and still weighing whether a full rollback is the right path forward, a move that would itself be controversial given how contentious blockchain rollbacks have historically been within the broader crypto community.
What's already clear is that Harmony is dealing with this crisis with considerably less goodwill from the independent investigator community than it had in 2022, and ZachXBT's public refusal, whether or not other researchers follow suit, has turned this into a story that's as much about accountability toward the people who help clean up these messes as it is about the exploit itself.
Disclosure: This is not trading or investment advice. Always do your research before buying any cryptocurrency or investing in any services. Follow us on X @nulltxnews