Harmony weighs rollback after bug mints billions of ONE

Harmony issued an emergency validator patch after a math flaw allowed about 4 billion ONE to be minted; on-chain researcher Juiceberg estimates 2.8 billion reached exchanges, numbers not confirmed by Harmony.

Harmony released an emergency validator update, v2026.1.1, on Aug. 12 after a math flaw allowed unauthorized creation of an estimated 4 billion ONE tokens. On-chain researcher Juiceberg estimated about 2.8 billion of those tokens were routed to exchanges; Harmony has not confirmed those figures.

The flaw affected cross-shard receipts, the messages that carry transaction results between parts of Harmony’s network. One vulnerability let an empty signer record and a mathematically neutral aggregate signature pass a quorum check because the verifier counted the full validator committee rather than the validators listed in the signer record. A second problem left some proof fields for spent receipts unbound to the signed block header, allowing a previously processed receipt to be altered so it could be credited again without a corresponding debit.

The signed v2026.1.1 release changes the quorum calculation to use the validators actually listed in signer records and binds the spent marker to authenticated header data. Harmony paused bridge.harmony.one during the response, published four wallet addresses linked to the incident and asked exchanges to block and freeze traceable funds. The project did not name any exchanges or disclose how much, if any, has been frozen.

Harmony said it will address tokens already created in a later update and is weighing whether to perform a full rollback, but it has not announced a decision or specified how far back the network could revert state if a rollback is chosen. The project told validators to install the patched release to prevent further unauthorized minting.

Market reaction was immediate: the ONE token fell sharply, with price drops reported in the tens of percent over a 24-hour period. The incident differs from a June 2022 bridge theft that involved compromised multisig control and stolen funds; the current issue stems from protocol-level receipt verification and replay rather than stolen keys or custodial access.

Outstanding facts include the exact size and location of the excess supply, how much of the minted tokens exchanges can or will freeze, and whether a rollback is technically feasible and operationally acceptable. Harmony has not provided a timeline for further technical disclosures or a final decision on remediation.

Articles by this author