Harmony Plans Rollback After Exploit Forged 3.01 Trillion ONE

Network would erase post-attack transactions and restart both shards from clean checkpoints
TL;DR
- Harmony plans to roll back both shards to a pre-exploit state after determining that an attacker forged 3.01 trillion ONE.
- The recovery would erase legitimate transactions alongside malicious activity because forged tokens had already spread through wallets and services.
- Harmony traced the exploit to reusable cross-shard receipts and chose a fixed rollback over burns, blacklisting, selective replay or token migration.
Trade smarter on Jupiter, Solana’s leading DEX built for fast execution and deep liquidity.
Swap tokens at competitive rates, route across multiple liquidity sources automatically, and access perpetuals, DCA, and advanced trading tools — all in one place!
Harmony plans to roll back its blockchain to its last clean state before an unauthorized ONE mint, erasing all subsequent blocks and transactions after determining that an attacker forged 3.01 trillion ONE. The Layer 1 network said the exploit stemmed from a cross-shard receipt-verification flaw that allowed valid receipts to be reused, creating new ONE without a corresponding debit elsewhere.
The network disclosed the detailed recovery plan on Aug. 17, 2026. Harmony intends to restore both chains in its sharded network to their state at Aug. 11, 2026, 23:25:37 UTC, before the first confirmed forged mint. Legitimate user transfers, purchases, sales and other transactions confirmed after the cutoff would be removed together with the malicious activity.
Harmony selected that recovery point because the first forged tokens appeared in the next relevant Shard 0 block, numbered 92,730,036. The recovery would use replacement databases rather than simply moving the existing chain head backward. Harmony's upgraded client, v2026.1.2, is designed to reject block hashes associated with the exploit, while the team warned that a simpler built-in revert could leave unwanted state behind and contribute to another failure.
Harmony said an independent security firm reviewed the exploit and agreed with the rollback approach. The network considered a targeted burn first, but the forged ONE had already moved into exchanges, trading pools and smart contracts. Harmony determined that destroying those tokens where they currently sat could remove assets belonging to innocent users who had subsequently received or interacted with them.
A wallet blacklist was rejected because it would leave the illegitimate supply in the network. Selectively replaying legitimate transactions was deemed “unworkable” because blockchain state had already changed, while a full token migration was rejected because Harmony concluded it would cause excessive disruption across the user base.
“Of the options we studied, one fixed rollback window is the fairest and most secure,” Harmony said. “It applies one rule to everyone, removes the forged state, and carries the lowest risk of another attack or consensus failure.”
Initial mint estimate expanded dramatically
Harmony first confirmed the exploit on Aug. 12 after an independent researcher initially identified roughly 4 billion ONE created through empty blocks. That figure, described at the time as about 26% of the token's supply, later proved to represent only the first detected wave of unauthorized issuance.
Harmony's subsequent reconstruction found that the attacker had actually forged the much larger total across six minting transactions into four exploiter wallets. One wallet moved nearly 2.4 trillion ONE in under two minutes, an amount valued at almost $3 billion using pre-attack prices.
Harmony said it traced nearly all of the forged tokens to wallets or services, although substantial amounts had passed through decentralized trading pools and bridges. The network said it was working with exchanges, crypto bridges and law-enforcement authorities to preserve records, track the flow of assets and identify the people responsible.
We’ve launched the all-new COIN360 Perp DEX, built for traders who move fast!
Trade 130+ assets with up to 100× leverage, enjoy instant order placement and low-slippage swaps, and earn USDC passive yield while climbing the leaderboard. Your trades deserve more than speed — they deserve mastery.
Receipt reuse allowed ONE to be created without matching debits
The exploit centered on how Harmony verified cross-shard receipts. Valid receipts could be processed more than once, allowing a receiving shard to repeatedly credit ONE without the corresponding value being debited elsewhere. The unauthorized issuance occurred inside empty, zero-gas blocks, according to Harmony's account of the incident.
On-chain expert “Juiceberg,” who first noticed the exploit, estimated that the attacker was reusing cross-shard receipts to create tokens from the verification flaw. Harmony's Aug. 13 update also said a second pre-staking quorum bug may have been involved, leaving that issue as a possible contributing element rather than the confirmed primary minting mechanism.
Harmony patched the cross-shard receipt vulnerability when the attack was discovered. The software fix addressed the minting flaw itself, while the proposed rollback is intended to remove the forged supply and blockchain state already produced before remediation.
ONE price fell sharply after the unauthorized mint became public. For crypto price references, COIN360 data showed ONE price around $0.0008 after a roughly 37% to 40% decline, with the coin market cap at approximately $11.5 million. A later ONE price reference placed the token near $0.0007.
Harmony has dealt with earlier supply and security incidents. A staking-system bug in December 2023 accidentally created 146.28 million ONE and forced a network update. Separately, Harmony's Horizon bridge lost about $100 million in a June 2022 theft that the FBI attributed to North Korea's Lazarus Group.
FAQ
Why did Harmony choose a rollback instead of burning the forged ONE?
Forged tokens had reached exchanges, pools and smart contracts, creating risks for innocent holders.
Why was a blacklist rejected?
Harmony said blacklisting wallets would leave the forged supply embedded in the network.
What made selective transaction replay impractical?
Harmony called it “unworkable” because blockchain state had already changed.
Who first identified the exploit mechanism?
On-chain expert “Juiceberg” linked it to repeated processing of cross-shard receipts.
This article has been refined and enhanced by ChatGPT.