Harmony’s ONE token fell about 26% in Asian morning hours Wednesday after an apparent exploit created roughly 4 billion new tokens, an amount equal to more than a quarter of the token’s existing supply.
Harmony confirmed the attack in an X post and said it is working with exchanges to freeze the funds and preparing a software fix.
“We are working on a patch and rollback options,” Harmony said, adding that it would provide another update when more information is available.
Harmony is a blockchain network whose ONE token is used to pay for transactions and help secure the chain. Roughly 15 billion ONE existed before the incident, meaning another 4 billion represents a sudden increase of about 26% against that supply.
A rollback would mean getting the network to return to a point before the exploit and continue from there, effectively removing some transactions that happened afterward from the blockchain’s accepted history.
That can prevent an attacker from keeping newly created tokens still on the network, but becomes harder once funds have reached exchanges or moved onto other systems.
The apparent exploit comes a day after Ravencoin, another smaller blockchain built from Bitcoin’s code, faced its own possible rollback after invalid blocks were accepted by parts of its network.
In that case, miners moved to rebuild the chain from before the flaw, putting several days of transactions at risk of reversal. Ravencoin is separate from Harmony, but the two incidents show the trade-off involved in a rollback — that undoing an attack can also undo legitimate transactions made after it.
Not the first hit
Harmony has dealt with unauthorized creation of ONE before.
In December 2023, a bug in its staking system caused about 146.3 million ONE to be created when tokens that should have stopped receiving payouts continued doing so. Harmony said at the time that 74 addresses were involved, with one receiving 51.2 million ONE and about 16.4 million subsequently moved to an exchange.
The network responded to that incident with an emergency software update and blacklisted addresses holding the improperly created tokens.
Harmony was also hit by one of crypto’s biggest bridge attacks in 2022, when about $100 million was stolen from its Horizon bridge after attackers compromised private keys controlling it. The FBI later attributed that theft to North Korea’s Lazarus Group.
forbes.com
coinedition.com