BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
DeFi

Someone Minted 4 Billion Harmony Tokens Out of Nothing. The Supply Counter Did Not Notice

An attacker created roughly 4 billion ONE tokens on August 12. That is around 26% of Harmony’s entire supply, conjured through empty blocks. By the time the exploit was public, about 97% of t

AnonymousCryptoCompass newsroom
August 16, 2026
5 min read
NEWS
Someone Minted 4 Billion Harmony Tokens Out of Nothing. The Supply Counter Did Not Notice
CryptoCompass editorial visual for defi coverage.

An attacker created roughly 4 billion ONE tokens on August 12. That is around 26% of Harmony’s entire supply, conjured through empty blocks.

By the time the exploit was public, about 97% of those tokens had already reached exchanges.

The freeze request came after the money left.

What Actually Happened

On-chain analyst Juiceberg flagged the unauthorized mint early on Wednesday. Harmony confirmed the exploit the same day.

The mechanism was empty blocks. The attacker produced blocks containing no transactions and extracted newly minted ONE from them.

Harmony’s totalSupply endpoint did not immediately reflect the increase. That endpoint is the standard interface wallets, exchanges and data aggregators use to check how many tokens exist.

So for a window, every automated system that queries supply was reporting a number that was no longer true. Two systems failed at once: minting and the reporting that would have exposed it.

The specific vulnerability has not been publicly disclosed.

Why the Freeze Request Was Already Too Late

Harmony published four wallet addresses and asked exchanges to block and freeze funds tracing back to them.

Juiceberg’s accounting shows why that has limited reach. The attacker had roughly 115 million ONE left on-chain, about 2.9% of the total minted.

The other 97% was already on exchanges, either sold or sitting in deposit wallets ready to sell. Roughly 2.8 billion were funnelled to venues during the price collapse.

Once tokens are inside an exchange, an on-chain freeze does nothing. It becomes a request to a company rather than a technical control, and no exchange has publicly confirmed acting on it.

ItemFigureTokens minted without authorizationabout 4 billion ONEShare of previous supplyabout 26%Moved to exchangesabout 97%Remaining on-chainabout 115 million, roughly 2.9%Wallets named by Harmony4Exchange freezes publicly confirmedNoneRoot cause disclosedNo

The Price Reaction Is Reported Four Different Ways

Coverage puts the drop at 26%, 30%, 37% and 38.2% depending on the outlet and the measurement window.

CoinGecko data cited in one report put ONE around $0.00077 after a 37% fall. CoinDesk’s own headline used 26% while its article described a 40% fall.

These are not contradictions so much as different snapshots of a fast-moving intraday collapse. Anyone quoting a single figure should say when it was measured.

Harmony’s Response

The team pushed an emergency validator patch to stop further minting and asked all validators to upgrade.

It paused bridge.harmony.one, though its notice did not identify the bridge as the exploited component. That distinction matters and most coverage has blurred it.

A separate fix for the tokens already created has not been released. Harmony said it is working on a patch and rollback options.

No rollback has been announced, and no point of reversal has been specified.

The Rollback Problem

A rollback would neutralize the fraudulent supply. It would also erase every legitimate transaction made after the chosen block.

Anyone who traded, bridged or transferred ONE in that window would have those actions reversed. Exchanges that credited deposits would face reconciliation problems.

So the choice is between accepting 26% dilution and invalidating ordinary users’ transactions. Neither option is clean, which is presumably why no decision has been announced.

Harmony has run an emergency hard fork before, at block 51,118,080, to contain the 2023 minting bug.

The Third Incident in Four Years

In June 2022, Harmony’s Horizon bridge was drained of nearly $100 million through compromised multisig control. The FBI attributed that attack to North Korea’s Lazarus Group and APT 38 in January 2023.

Optimisus covered that attribution when the FBI linked the $100 million Harmony hack to Lazarus, and the laundering that followed in the piece on $27.18 million in ETH being cleaned.

In 2023 a staking bug generated 146.3 million unintended ONE, with roughly 16.4 million reaching an exchange before containment.

The current incident is more than 27 times the scale of the 2023 mint. It is also technically distinct from 2022, which involved stolen keys rather than a protocol-level minting flaw.

The Reputational Cost Is Now Operational

Blockchain investigator ZachXBT publicly declined to track this incident or assist for free.

His stated reason was the 2022 aftermath. He says people who helped trace and freeze stolen funds, work that contributed to law-enforcement seizures, received nothing beyond acknowledgment.

That is one investigator’s account of a past dispute rather than an established fact. But the practical effect is immediate.

Independent researchers are how most exploits get traced quickly, and the pool of people willing to do that unpaid for this particular project has visibly shrunk. Exchange cooperation has worked before here, including when Binance and Huobi seized funds tied to the bridge theft.

What Holders Should Watch

Three disclosures are outstanding: the root cause, the rollback decision, and whether any exchange actually froze anything.

Until those land, the dilution is real and the recovery path is unknown. Harmony’s official account is the only place those updates will be confirmed.

This is not an isolated month either. WEMIX confirmed a separate breach tied to unauthorized stablecoin issuance in late July, and three protocols lost a combined $35.55 million in bridge exploits in the same window.

The broader pattern Optimisus examined after the Bybit breach and the security overhaul that followed applies here too. The technical failure is usually recoverable. The speed at which value exits rarely is.

Sources

This is not financial advice.

Optimisus covers crypto and technology news for readers who want the detail behind the headline.