Harmony confirms 4 billion ONE tokens were created through a missing block mining vulnerability
Harmony confirmed that their Layer-1 blockchain network had been hacked, allowing the attacker to illegally create approximately 4 billion ONE tokens (mint) and about 2.8 billion tokens were illegally generated.
8/12/20264 min read


Token creation (minting) mechanism through empty blocks
This attack used a technique to bypass Harmony's standard token validation process through empty blocks. This method allowed for the minting of ONE tokens outside the protocol's issuance rules, without triggering the validation mechanisms designed to prevent unauthorized supply increases. Juiceberg described this mechanism on X and stated that the endpoint displaying the network's total supply (`totalSupply`) concealed this inflation; meaning the supply increase was not immediately visible through the standard interface that token holders and exchanges typically use to track the circulating supply of ONE.
Harmony has not disclosed the exact technical vulnerability that allowed token creation via empty blocks to occur; they have only stated that the team is coordinating with exchanges, preparing a patch, and evaluating network rollback options. Not disclosing the root cause is standard procedure in ongoing incident response: if full technical details were released before a patch is deployed and before the affected exchanges have time to freeze the affected funds, the attacker (or imitators) could obtain the necessary information to carry out further unauthorized token creations.
The difference between the 4 billion tokens created and the approximately 115 million remaining on-chain is the most important data for assessing the immediate impact of the attack: about 97% of the unauthorized supply had already moved from source addresses and into the deposit systems of exchanges before market reaction could prevent further movements. In fact, tokens that have been converted to other assets or withdrawn from exchange accounts cannot be recovered through cooperation with the exchanges. Exchanges can freeze deposits that are still in their systems and have not been converted or withdrawn; therefore, Harmony's request to block the four identified wallet addresses is significant but recovery remains limited.
A momentous decision has no easy solution.
Harmony stated that they are considering "rollback" options. This means returning the network to a state before the attack and continuing operation from that block; essentially, this action would remove from the accepted blockchain history all transactions that occurred after the rollback. A rollback would erase the attack and the illegal tokens from the chain history, but the price is invalidating all valid transactions that occurred after that point, thereby affecting users completely unrelated to the attack.
Whether Harmony's validator group can reach a consensus on an undo strategy remains uncertain. The Ethereum community previously voted against undoing the chain after the 2016 DAO attack; this decision led to a fork creating Ethereum Classic, when a minority of validators disagreed with the majority's undo decision and continued to maintain the original chain. For Harmony, the key considerations include: the severity of the attack versus the damage an undo would cause to innocent users; the technical feasibility of establishing a "clean" undo point (before all transactions related to the attack occurred); and whether the validators can collectively agree to execute the chosen undo block.
Undoing the action would not recover the funds that the attacker had already converted to other assets on the exchanges. This is because those transactions occurred within the exchange's internal accounting system, not on the Harmony chain, and are therefore outside the scope of a chain undo process. The actual recovery limit from undoing would only cover approximately 115 million ONE tokens remaining on the chain, plus any funds that the exchanges managed to freeze before the conversion took place.
Harmony's third major security breach in four years.
The August 2026 vulnerability exploit was Harmony's third major security incident since 2022, creating a pattern of recurring protocol-level vulnerabilities that exacerbate reputational damage from each individual incident.
In June 2022, the Horizon bridge, Harmony's cross-chain link to Ethereum, was exploited, causing approximately $100 million in losses. In January 2023, the FBI identified the perpetrators behind this attack as the Lazarus Group and North Korea's APT38; these are the same state-sponsored hacking organizations that carried out the Ronin bridge attack. Later in 2023, Harmony faced an "infinite mint bug" affecting approximately 150 million ONE tokens, revealing a similar vulnerability related to unauthorized token creation outside the protocol's established rules.
The similarities between the 2023 infinite token generation vulnerability and the August 2026 exploit are particularly noteworthy; this suggests that Harmony's protocol either failed to fully address the conditions that allowed for unauthorized token generation after the 2023 incident, or that the 2026 attack exploited a different but related source code branch that the previous fix hadn't fully addressed. A protocol that experiences three critical security incidents within four years—two of which involved unauthorized token generation—will face a significant credibility challenge to its core claim that its security model adequately protects token holders.
Disclaimer: The content in this article is for informational, research, data analysis, and reference purposes only regarding the cryptocurrency market. All opinions, assessments, forecasts, or opinions reflect the author's perspective at the time of publication and do not constitute investment advice, solicitations for buying or selling, trading recommendations, advertising, marketing, or promotion of any financial products, services, or cryptocurrencies. Mentions of projects, tokens, protocols, exchanges, wallets, or cryptocurrency service providers (CASPs) are for research, analysis, or informational purposes only and should not be construed as endorsements, recommendations, or guarantees in any way. HCCVenture does not broker, advertise, market, promote, or connect users in Vietnam with any cryptocurrency services from CASPs. HCCVenture does not accept asset custody, investment mandates, manage assets, or execute transactions on behalf of clients. All investment decisions are made entirely through the reader's own research (DYOR), evaluation, and responsibility; HCCVenture is not liable for any losses or damages arising from the use of or reliance on the information presented in this article.
Compiled and analyzed by HCCVenture
Join our information channels: https://link3.to/holdcoincventure
Explore HCCVenture group
HCCVenture © 2023. All rights reserved.


Connect with us
Popular content
Contact to us
E-mail : sp_contact@hccventure.com
Register : https://linktr.ee/holdcoincventure
Disclaimer: The information on this website is for informational purposes only and should not be considered investment advice. We are not responsible for any risks or losses arising from investment decisions based on the content here.
TERMS AND CONDITIONS • CUSTOMER PROTECTION POLICY
ANALYTICAL AND NEWS CONTENT IS COMPILED AND PROVIDED BY EXPERTS IN THE FIELD OF DIGITAL FINANCE AND BLOCKCHAIN BELONGING TO HCCVENTURE ORGANIZATION, INCLUDING OWNERSHIP OF THE CONTENT.
RESPONSIBLE FOR MANAGING ALL CONTENT AND ANALYSIS: HCCVENTURE FOUNDER - TRUONG MINH HUY
Read warnings about scams and phishing emails — REPORT A PROBLEM WITH OUR SITE.


