Harmony weighs a full blockchain rollback after unauthorized minting floods exchanges with billions in ONE

0
2
Harmony weighs a full blockchain rollback after unauthorized minting floods exchanges with billions in ONE


Harmony, the layer-1 blockchain network, has released an emergency validator patch that it says prevents further unauthorized minting of ONE, its native token. The project said it will address tokens already created in a later update, leaving their number and ultimate treatment unresolved.

Harmony told validators to install v2026.1.1 on Aug. 12. The notice confirms that minting occurred but does not disclose the amount.

Onchain researcher Juiceberg estimated that roughly 4 billion ONE, equal to about 26% of the supply figure used in the post, had been minted without authorization. Juiceberg also estimated that 2.8 billion ONE had reached exchanges. Harmony has not independently confirmed those figures.

Polkadot Hyperbridge April Fools’ joke comes true as over 1 Billion fake DOT tokens were minted on EthereumPolkadot Hyperbridge April Fools’ joke comes true as over 1 Billion fake DOT tokens were minted on Ethereum
Related Reading

Polkadot Hyperbridge April Fools’ joke comes true as over 1 Billion fake DOT tokens were minted on Ethereum

A proof replay bug let the attacker mint over $1 billion DOT tokens on Ethereum, yet shallow DOT pools capped the cashout near $240,000.

Apr 13, 2026 · Oluwapelumi Adejumo

How the patch blocks more minting

Harmony’s published code changes address two weaknesses in cross-shard receipts, which carry transaction results between parts of the network.

One flaw allowed an empty signer record and a mathematically neutral aggregate signature to pass a quorum check. The verifier counted the full committee instead of the validators represented in the signer record, allowing a receipt to be accepted without the required approvals.

The second flaw affected how the network recorded that a receipt had already been spent. Some proof fields were not bound to the signed block header, so changing those fields could make a previously processed receipt appear new. The destination could then be credited again without a corresponding debit from the source.

Crypto users told to pull funds after Ethereum L2 bridge failure exposes rollup exit riskCrypto users told to pull funds after Ethereum L2 bridge failure exposes rollup exit risk
Related Reading

Crypto users told to pull funds after Ethereum L2 bridge failure exposes rollup exit risk

The incident forced users to confront the part of rollup security that usually stays invisible: whether they can still withdraw when the bridge layer breaks.

Jun 23, 2026 · Liam ‘Akiba’ Wright

The signed v2026.1.1 release changes the quorum calculation and ties the spent marker to authenticated header data, closing both paths described in the patch.

CryptoSlate Daily Brief

Daily signals, zero noise.

Market-moving headlines and context delivered every morning in one tight read.