Particle.news

Unauthorized Mint Floods Harmony With Billions of ONE, Protocol Patch Issued

Recovery depends on exchange freezes or a controversial rollback to remove the excess tokens.

Overview

  • The Harmony mainnet experienced an apparent protocol exploit on Wednesday that on-chain analysts reported created roughly 4 billion ONE tokens, equal to about a quarter of the prior supply and triggering a sharp market sell-off.
  • Harmony published four implicated wallet addresses, told exchanges to block and freeze traced funds, and said some of the newly minted tokens were quickly routed to centralized exchanges though the exact amounts remain unconfirmed by the project.
  • The team released an emergency validator build, v2026.1.1, that it says stops further minting by fixing two protocol flaws: an empty-signer/quorum-calculation error that let receipts pass without proper approvals and a replay/spent-marker binding bug that allowed receipts to be credited multiple times.
  • Validators began installing the patch and the network paused its bridge, but the final scope of the affected block range, how many tokens have been frozen by exchanges, and whether to perform a blockchain rollback to erase the tokens are still under active evaluation.
  • The incident compounds past Harmony security failures and has real consequences for holders and users as ONE plunged heavily in price, trust in the chain’s governance faces renewed strain, and recovery will hinge on coordinated exchange action and whether stolen tokens are further dispersed.