The Harmony blockchain, already marked by the Horizon bridge hack in 2022, faces a second security shock in four years. On August 12, a flaw in the inter-shard receipt verification allowed an attacker to mint ONE without ever debiting another account in return. The result is beyond comprehension: over 3 trillion tokens created from nothing. The follow-up is set to be as radical as the diagnosis.
Key points of this article:
The mechanism can be summed up in one line, but its consequences took five days to measure. The flaw allowed the same valid receipt to be processed multiple times between the two fragmented chains (shards) of Harmony, effectively permitting a monetary minting without counterpart. An initial estimate on August 12 mentioned 4 billion ONE created. That was just the tip of the iceberg.
Indeed, a complete reconstruction eventually established that 3.01 trillion ONE had been minted in six transactions, sent to four distinct wallets, reports The Block. One of these wallets managed to transfer nearly 2.4 trillion ONE, worth about 3 billion dollars at pre-attack prices, in less than two minutes. 477 successful transfers out of 534 attempted, all within 106 seconds. The software fix arrived on the same day as the hack.
Faced with such volume, burning tokens or blacklisting certain wallets was no longer sufficient: too many minted ONE had already passed through decentralized exchange pools, bridges, and contracts mixing legitimate and stolen funds.
Harmony thus opted for a complete rollback of shards 0 and 1 to a checkpoint dated August 11 at 11:25 PM UTC, followed by a restart on new databases, a task that Harmony estimated would involve 141,628 affected blocks, rather than a simple software cancellation deemed too partial to cleanly erase traces of the attack. The cost of the operation: over 109,000 regular transactions and 315 staking transactions were simply canceled, according to Harmony's own figures. Many were related to automated trading bots, but not all, and no one can guarantee that no innocent user was harmed in the process.
Unsurprisingly, the market did not warmly welcome the episode. The ONE token lost 42.3% over seven days, with its total market capitalization now weighing in at around 10.7 million dollars. An almost negligible amount compared to the 3 billion dollars theoretically created by the hacker in a matter of minutes, but it speaks volumes about the gap between the value displayed on paper and the actual liquidity of a token already in poor shape.
This case is not unique in its kind: in 2016, the Ethereum ecosystem had already settled a similar debate, pushing the network to rewrite its history after the hack of 3.6 million ETH that gave birth to Ethereum Classic.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.





























