Skip to content

Invest3 publishers3 min readPublished Updated

Harmony's answer to a forged 4 billion ONE: delete 109,441 confirmed transactions

The layer-1 will rewind both shards to an Aug. 11 checkpoint and ship a client that rejects the exploit's blocks. Finality on Harmony is now whatever the team decides to keep.

The Investor · Invest desk

What happened

  • Harmony laid out a rollback plan to restore its blockchain to blocks timestamped 2026-08-11 23:25:37 UTC.
  • The restoration will wipe out the effects of an unauthorized mint of roughly 4 billion ONE.
  • All legitimate activity that took place after the stipulated time will be erased alongside the fraud, including buys, sells and transfers made by users.
  • The discarded window includes 109,126 regular transactions and 315 staking transactions.
  • Harmony said Monday that validators would revert to blocks recorded at 11:25 pm UTC on Aug. 11, with new blocks produced from the next heights using replacement databases.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

Harmony has published a plan to rewind its chain to blocks timestamped 2026-08-11 23:25:37 UTC, erasing an unauthorized mint of roughly 4 billion ONE and, with it, everything users confirmed afterwards [1][2][3]. The collateral list is 109,126 regular transactions and 315 staking transactions, or 109,441 confirmations that were settled until the team decided otherwise [4][1].

The mechanics are specific. Harmony says the first forged tokens appeared on Shard 0 in block 92,730,036 [6]; the plan rewinds shard 0 to block 92,730,034 and shard 1 to 94,978,278 using replacement databases, with new blocks produced from heights 92,730,035 and 94,978,279 [10][5][8]. A new client, v2026.1.2, refuses the block hashes tied to the exploit [9]. One checkpointed block was never attacked and is being rolled back anyway, which Harmony frames as preventing future problems [7].

Every alternative was considered and discarded, and the reasoning is internally consistent. A targeted burn was rejected because the forged ONE had already reached exchanges, trading pools and smart contracts, so burning risked confiscating money belonging to third parties [11]. A blacklist was rejected because it leaves the fake supply in the system, a token migration for user disruption, and selective replay was called unworkable [12]. Harmony said selectively restoring transactions was unsafe because balances, contract states and nonces would differ on the replacement chain [14], and warned that using the built-in revert tool could leave residual data and another failure [13]. An independent security firm reviewed the incident and agreed with the rollback, according to Harmony's report [15]. Read the list again: every option that preserved finality also preserved the fraud somewhere. The one chosen preserves neither, and pushes the cost onto users who did nothing.

The sums involved are small relative to the precedent being set. The forged mint was about 26% of supply [18], ONE trades near $0.0007 [19], and market capitalisation is roughly $10.8 million on CoinGecko data [20], which puts the nominal value of the fake tokens around $2.8 million [3]. Those two figures are at least mutually consistent, both implying a supply near 15.4 billion [2]. The transfer numbers are not: Harmony reports the attacker attempting 534 payments of 5 billion tokens each in 106 seconds, of which 477 landed, moving 2,385,000,000,000 ONE [21], roughly 596 times the size of the mint it is supposed to have come from [4]. The report does not reconcile that.

Cause, per on-chain analyst Juiceberg, was a flaw in cross-shard receipt verification that allowed a valid receipt to be processed more than once [16]. Harmony's Aug. 13 update describes crediting a shard without a matching debit inside empty, zero-gas blocks, with a second pre-staking quorum bug possibly involved [17]. This is the same network that accidentally minted 146.28 million ONE through a staking bug in December 2023, roughly 27 times smaller than this event [23][5], and that lost about $100 million from its Horizon bridge in June 2022 in a theft the FBI attributed to Lazarus Group [24].

Watch whether validators actually run v2026.1.2, since the checkpoint only binds the chain if they do [9][5]. Watch the recovery track: investigators say nearly all forged ONE has been traced to wallets or service boundaries, with exchanges, bridges and law enforcement engaged [22]. Neither report describes any compensation for holders whose legitimate transactions get discarded [6]. And watch Ravencoin, facing a potential three-day reorganisation after a consensus flaw, with pools controlling most of its hash rate building a competing chain [25].

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories