Harmony released an emergency validator patch on Aug. 12 to stop further unauthorized minting of ONE, after an onchain researcher estimated that roughly 4 billion tokens — about 26% of supply — were created out of thin air. The patch, v2026.1.1, closes two cross-shard receipt vulnerabilities that could be exploited to bypass quorum checks and replay forged proofs. The team hasn't confirmed the numbers, and it's still deciding whether to roll back the chain entirely.
Inside the patch
The first vulnerability let an attacker bypass the quorum check by submitting an empty signer record and a neutral aggregate signature. The second was a replay flaw: proof fields weren't bound to the signed block header, so a valid proof could be reused. The patch fixes both by changing how quorum is calculated and tying the spent marker to authenticated header data.
That's the technical side. The practical effect is that the network can now reject the kind of forged receipts that allowed the unauthorized minting in the first place.
The scale of the mint
Onchain researcher Juiceberg put the unauthorized mint at approximately 4 billion ONE, with 2.8 billion of that moving to exchanges. Harmony has not independently confirmed those figures, and the team hasn't said which venues received the funds. The exchange response so far has been limited to a request: block and freeze traceable funds.
Four wallet addresses have been published, but no amounts frozen have been disclosed. The bridge, bridge.harmony.one, was paused during the response, though it wasn't explicitly identified as the exploited component.
Rollback on the table
Harmony is considering a full blockchain rollback, but hasn't announced whether it will happen or from which point transactions would be reversed. That's a heavy decision — a rollback would undo legitimate transactions made after the exploit, and it's not clear how far back the chain would go.
The incident is technically distinct from the June 2022 Horizon bridge exploit, which involved compromised multisig control and about $100 million in stolen assets. This time, the attack targeted cross-shard receipt validation, not the bridge's signing keys.
For now, validators are being asked to apply the patch, and the network is waiting on a rollback decision. The next concrete step is Harmony's announcement on whether it will rewind the chain — and if so, to which block.




