Harmony Protocol’s native ONE token crashed as much as 40% on Wednesday after the Layer-1 blockchain confirmed an exploit that let an attacker mint roughly 4 billion unauthorized tokens, equal to about 26% of ONE’s existing supply of roughly 15 billion. The token fell to a new all-time low of $0.0005735 during early Asian trading before partially recovering, as nearly all of the newly created tokens were rapidly funneled to exchanges for sale.
An Unauthorized Mint Through Empty Blocks
On-chain analyst Juiceberg first flagged the exploit at 01:42 UTC, reporting that an attacker minted approximately 4 billion ONE tokens using empty blocks, transactions that appeared on the network without corresponding value entering the system. Juiceberg noted that Harmony’s own totalSupply endpoint did not immediately reflect the additional tokens, delaying public confirmation of the scale of the inflation. Roughly 2.8 billion of the minted tokens, about 97% of the total, were quickly moved to exchanges and either sold or parked in deposit wallets ready for sale, leaving the attacker with only about 115 million ONE, or 2.9% of the minted amount, still sitting on-chain hours after the exploit began.
Harmony confirmed the exploit publicly at 04:26 UTC, roughly three hours after Juiceberg’s initial report, stating it was working with its team and appropriate exchanges to stop and freeze the funds while developing both a patch and rollback options. The protocol shared four specific wallet addresses tied to the exploit, including both Harmony-native ONE addresses and corresponding Ethereum addresses, and asked exchanges to block and freeze any funds traced to them. Harmony also paused its cross-chain bridge to prevent the minted tokens from moving to other blockchains, and later told validators to upgrade to a released patch designed to prevent any further unauthorized minting, with a separate update planned to address the tokens already created.
A Second Major Security Failure for Harmony
Wednesday’s incident marks Harmony’s third publicly disclosed token-supply security failure. The network’s Horizon cross-chain bridge was exploited for nearly $100 million in 2022, and a separate staking bug in 2023 improperly minted approximately 146.3 million ONE tokens. ONE’s price has failed to reclaim its pre-2022 levels since the bridge hack, and Wednesday’s exploit pushed the token to a fresh record low.

- ONE traded near $0.000759 following the crash, down from a 24-hour high of $0.00124 to a low of $0.000535
- Trading volume surged more than 4,000% as holders rushed to sell amid the sudden supply expansion
- Coinglass data showed ONE futures open interest fell 5% to $9 million within four hours, with open interest on Binance and OKX down more than 28% and 18%, respectively, reflecting sharply bearish derivatives positioning
Conclusion
Harmony’s confirmation that the exploit was real, rather than an unverified on-chain claim, removes any ambiguity about the scale of the damage but leaves the network’s next steps unresolved. A rollback would mean reverting the blockchain to its pre-exploit state and discarding all transactions that occurred afterward, a technically disruptive option that Harmony has not yet committed to executing. Until the protocol confirms whether it will pursue a rollback or rely solely on exchange freezes and the newly deployed patch, ONE holders face uncertainty over how much of the diluted supply will ultimately be clawed back versus permanently absorbed into circulation.
Sources & Methodology
Primary-source standard: Market-moving facts should link to original data releases, regulator notices, company filings or official project announcements whenever available. Secondary reporting is used for additional context, not as a substitute for original evidence.
Page last reviewed:
