Harmony Hack Update: 2.385 Trillion ONE Token Set for Network Rollback

Harmony Hack Update: Full Rollback Confirmed

Harmony Hack Update: 109K Transactions to Be Discarded After ONE Hack

Harmony has confirmed a full network rollback to undo the effects of a major exploit that let an attacker illegally mint billions of ONE tokens. The plan restores Shard 0 and Shard 1 to their exact state at 23:25:37 UTC on August 11, 2026, wiping out 2.385 trillion forged tokens. 

Over 109,000 user transactions will be discarded in the process. This Harmony hack update breaks down what happened, why a rollback was chosen over other fixes, and what it means for holders and validators.

Harmony Hack Update: 2.385 Trillion ONE Illegally Minted in Exploit

Around August 12, 2026, an attacker exploited a flaw in Harmony's cross-shard system to mint native ONE tokens out of thin air. 

One forged-mint wallet alone attempted 534 transfers of 5 billion ONE each within just 106 seconds, successfully moving 2,385,000,000,000 ONE. 

The sudden flood of counterfeit supply sent ONE's price down by more than 30% at one point. 

Because the fake tokens quickly spread across exchanges, decentralized platforms, bridges, and staking pools, this incident became one of the more complex recovery cases in recent blockchain history, forcing Harmony Protocol toward a full-network rollback rather than a simple patch.

Harmony Rollback Plan

HarmonyProtocol X Post

How the Harmony ONE Hack Happened: Cross-Shard Receipt Replay Exploit

The root cause was a weakness in how it verified cross-shard receipts. Certain identity fields inside older Merkle proofs were never properly linked to the signed block header, meaning they could be altered without breaking the header's own signature. 

By tweaking these unauthenticated fields, the attacker made already-used receipts look brand new. The system then accepted the same receipt again, crediting one shard with new ONE without ever debiting the source shard. 

A second, separate weakness involved pre-staking quorum checks, where an empty validator signature set could still pass verification. Harmony hack has not confirmed whether the attacker used this second flaw, but it has since been closed as well.

Harmony Releases Emergency Patch to Stop Further ONE Minting

Harmony moved quickly, shipping Mainnet release v2026.1.1 on August 12 at 06:30 UTC. The patch ensures the spent-receipt marker always ties back to the authenticated shard ID and block number from the signed header, closing the replay loophole. 

The quorum-check flaw was also fixed so that only actively signing validators count toward consensus, with empty or missing signer sets now automatically rejected. As an added safety step, the Harmony bridge was paused. Once enough validators upgraded, the exploit path was fully shut down and no further unauthorized minting has occurred since.

Harmony Protocol Hack Update

Official X post

Harmony Confirms Full Rollback to August 11 Blockchain State

The centerpiece of this Harmony hack update is the confirmed rollback. Validators will revert to Shard 0 block 92,730,034 and Shard 1 block 94,978,278, both timestamped 23:25:37 UTC on August 11, one block before the first forged mint appeared. 

The protocol chose this exact block because it had no transactions, staking activity, or state changes of its own, giving a clean, safe cutoff point. A fixed-window rollback applies the same rule to every wallet equally, fully removes the forged supply, and avoids the fairness problems that come with picking and choosing individual transactions.

Why Harmony Rejected Token Burning, Blacklisting and Selective Recovery

The network considered several alternatives before settling on a rollback. Burning the forged tokens directly wasn't viable since they had already mixed into exchange balances, liquidity pools, bridge contracts, and staking positions, meaning a burn could destroy funds belonging to innocent users. Blacklisting wouldn't remove the fake supply and risked freezing unrelated wallets. 

Selectively replaying "legitimate" transactions was ruled out because chain state had already changed, so identical transactions could now produce different outcomes. Token migration was judged too disruptive, and a simple in-place database rewind wouldn't fully clear later receipts and indexes, potentially leaving the attack path open again.

Over 109,000 Transactions Will Be Permanently Discarded

The rollback affects 109,126 regular transactions, 315 staking transactions, and 109,441 matched receipts across 141,628 blocks. Notably, 95.80% of these were automated, largely DEX bots executing swaps, meaning transaction volume doesn't equal the number of real affected users. 

Only 22 transactions were simple, dependency-free transfers, and even those weren't necessarily safe to restore given changed balances and nonces. Every block created after the rollback checkpoint will be discarded entirely.

Harmony Traces 2.385 Trillion Forged ONE Across Exchanges and Wallets

Investigators built a time-ordered flow map tracing the forged funds through wallets, exchanges, DEX pools, bridges, and staking addresses, reconciling nearly 100% of the movement to specific wallet or service boundaries. 

However, it stresses a key distinction: tracing funds to a wallet cluster is not the same as identifying individual bad actors or having funds that are safely burnable. It is working alongside exchanges, bridge operators, and law enforcement, with an independent security firm confirming the core findings.

What the Harmony Rollback Means for ONE Holders, Traders and Validators

After the rollback, balances, nonces, swap deadlines, approvals, and staking states will reset to their August 11 condition. Validators must follow Harmony's published recovery steps before relaunch, and exchanges and bridges are coordinating separately to manage user impact. Traders should watch for official relaunch confirmation, updated balances, and exchange announcements before resuming activity.

Timeline for the Article

  • August 11, 2026 — 23:25:37 UTC: Harmony's selected rollback point: Shard 0 block 92,730,034 and Shard 1 block 94,978,278.

  • August 11 — 23:25:41 UTC: First confirmed forged mint activity appears on Shard 0 at block 92,730,036.

  • August 12 — 00:02:59 UTC: A first-wave unauthorized mint of 1 billion ONE is recorded.

  • August 12 — 01:01:17 UTC: Another 3 billion ONE is minted through an empty-block credit.

  • August 12 — 01:02:31 UTC: Around 2.8 billion ONE is transferred from one exploiter wallet.

  • August 12 — 01:05:24 UTC: Nearly the entire transferred amount moves to another wallet.

  • August 12 — 06:30 UTC: Harmony deploys v2026.1.1, fixing the vulnerable receipt-verification and quorum-checking logic.

  • August 12 — 12:32:54 UTC: Shard 0 is halted at block 92,753,555 while protocol works on recovery and rollback planning.

  • August 13, 2026: It publishes its incident update detailing the technical root cause, exploit reconstruction, and emergency response.

  • August 18, 2026: Harmony ONE confirms the full rollback plan, permanently discarding more than 109,000 transactions after the selected checkpoints.

Conclusion

Harmony rollback marks one of the largest coordinated recovery efforts in blockchain history, aiming to fully erase 2.385 trillion illegitimately minted ONE tokens while treating every wallet under one consistent rule. 

Though over 109,000 transactions will be lost, the protocol argues this fixed-window approach carries the lowest overall risk compared to burning, blacklisting, or selective recovery. The coming days will be critical as validators, exchanges, and bridges align for network relaunch.

Disclaimer: This article is for informational purposes only and does not constitute financial, investment, or trading advice. Always do your own research.

Sakshi Jain

About the Author Sakshi Jain

English News Writer at coingabbar.com

Sakshi Jain is a crypto news writer focused on delivering fast, data-driven coverage of the digital asset market. Her articles consistently track daily market movements, token launches, airdrops, exchange listings, and institutional signals, helping readers stay ahead of short-term trends. She simplifies complex crypto developments—such as regulatory updates, Bitcoin allocation strategies, and emerging blockchain projects—into clear, actionable insights. Her work reflects a strong emphasis on timeliness, SEO-driven structuring, and trader-focused narratives, often highlighting price momentum, market sentiment, and risk factors. Sakshi primarily writes for active crypto participants seeking concise, reliable, and opportunity-oriented market updates.

Leave a comment

Frequently Asked Questions (FAQ)

Faq Got any doubts? Get In Touch With Us