Harmony confirms unauthorised mint of 4 billion tokens

Harmony, a layer-1 blockchain, confirmed an exploit that allowed an attacker to mint roughly 4 billion unauthorised ONE tokens through a series of empty blocks. Harmony said about 2.8 billion of the newly minted tokens were moved toward exchanges before the network could respond. The company is coordinating with exchanges to freeze funds tied to four wallets it has identified as belonging to the attacker.

Harmony paused its Horizon bridge and released a validator patch, version 2026.1.1, to block further unauthorised minting. The team said it is evaluating a full network rollback alongside additional measures to address the tokens already minted, though no final decision had been announced.

An unauthorised mint big enough to force a rollback under consideration is a reminder that a chain's supply is only as trustworthy as the validator software enforcing it, patch history included.