An attacker forged roughly 4 billion ONE tokens out of thin air overnight, exploiting the Harmony blockchain to create new coins equal to more than a quarter of the entire existing supply — and sending the token plunging to an all-time low before most investors had even finished their morning coffee.
By Jennifer Kim | August 12, 2026
The Hook: A Supply Explosion Nobody Authorized
If you held Harmony’s ONE token going into Tuesday night, you woke up Wednesday to a nightmare scenario. Someone found a way to mint new ONE tokens through empty blocks — essentially printing money on a network that was supposed to have a fixed set of rules about how new coins are created. According to CoinDesk, the attacker churned out approximately 4 billion ONE tokens, which represented about 26% of the roughly 15 billion ONE that existed before the attack.
To put that in everyday terms: imagine if someone suddenly printed counterfeit dollars equal to a quarter of all the cash in circulation. Even if the counterfeit bills were eventually tracked down, the sheer shock would shake confidence in the currency. That is exactly what happened to Harmony, a layer-1 blockchain that was once valued at around 4 billion in market cap during its 2022 peak.
On-Chain Evidence: How the Attack Unfolded
The exploit targeted Harmony’s block creation process. The attacker used empty blocks — blocks on the blockchain that contain no real transactions but can still issue validator rewards — to mint ONE tokens that should never have existed. Once created, the attacker did not sit on them. According to reports, roughly 2.8 billion of the counterfeit tokens were quickly sent to cryptocurrency exchanges, presumably to sell them for other assets before anyone noticed.
That flood of new supply hitting exchanges caused ONE to drop as much as 40% in a matter of hours, reaching a record low. The speed of the crash was brutal: this was not a gradual sell-off over days or weeks, but a sudden injection of massive supply that overwhelmed buy orders almost instantly.
- 4 billion ONE minted — equal to roughly 26% of the pre-attack supply
- 2.8 billion ONE sent to exchanges — the attacker moved fast to cash out
- 40% price crash — ONE hit a record low in Asian morning trading
- 4 wallet addresses flagged — Harmony published them and asked exchanges to freeze funds
The Core Conflict: Roll Back or Live With It
Harmony now faces one of the most controversial decisions in crypto: should the network roll back the blockchain to a point before the attack, effectively erasing the counterfeit tokens from history? The team confirmed it is “working on a patch and rollback options,” according to a post on X (formerly Twitter). But rollbacks are deeply divisive in the crypto community.
Think of a rollback like a bank deciding to undo all transactions from the past few hours — not just the fraudulent ones, but every legitimate transfer too. If you bought groceries with your debit card during that window, your purchase would vanish. On a blockchain, a rollback means every transaction made after the attack point could be reversed, including ones made by innocent people who had no idea anything was wrong.
This is not just a Harmony problem. Just a day earlier, Ravencoin — another smaller blockchain project — faced its own potential rollback after parts of its network accepted invalid blocks. These back-to-back incidents highlight a uncomfortable truth about smaller blockchain networks: when something goes catastrophically wrong, the “code is law” principle often gets quietly set aside in favor of manual intervention.
Market Implications: Why This Matters Beyond Harmony
If you do not hold ONE, you might think this story does not affect you. But it does, in two important ways. First, it reinforces the risk profile of smaller altcoins. Harmony was once a top-50 project. Its token is now in freefall because of a single exploit. If you hold altcoins in the same market-cap range, you are exposed to the same category of risk — a sudden, unforeseen technical failure that can wipe out significant value in hours.
Second, the broader altcoin market was already under pressure before the Harmony exploit. According to CoinDesk’s market coverage, most of the 25 largest cryptocurrencies were showing negative cumulative volume deltas over the past 24 hours, meaning sellers were more aggressive than buyers across the board. The Harmony incident adds to a climate of fear that can trigger further selling in unrelated tokens as investors de-risk.
Bitcoin, by contrast, barely flinched. BTC was trading around 63,900 according to CoinDesk data, roughly flat over the past 24 hours. The Fear and Greed index sat at 38 — firmly in fear territory, but not panic. This is the pattern crypto investors have seen before: major exploits on smaller chains rattle altcoin holders while bitcoin increasingly behaves like a separate, more resilient asset class.
The Verdict: What Should Altcoin Holders Do?
The Harmony exploit is a textbook reminder of why diversification matters in crypto. Holding a portfolio of only small-cap altcoins means concentrating your risk in the exact assets most vulnerable to catastrophic failures like this. It does not mean you should sell everything — but it does mean you should honestly assess how much of your portfolio is in projects where a single bug could create a 40% overnight loss.
For ONE holders specifically, the situation is still developing. Harmony has not yet explained exactly how the attacker was able to mint tokens, has not confirmed the total amount of unauthorized issuance beyond the initial estimates, and has not said definitively whether a rollback will happen. That uncertainty itself is a risk factor — the longer it takes to resolve, the more confidence erodes.
This is also not Harmony’s first rodeo with unauthorized token creation. In late 2023, a staking bug caused about 146 million ONE to be improperly minted. And in 2022, the project suffered one of crypto’s largest bridge hacks when approximately 100 million was stolen from its Horizon bridge — an attack later attributed to North Korea’s Lazarus Group by the FBI. A pattern of security incidents is a red flag that should factor into any investment decision.
The cryptocurrency market remains highly volatile. This article is for informational purposes only and does not constitute financial advice.
4 billion tokens minted and nobody noticed until the price was already in freefall. this is exactly why bridge security matters more than tps numbers
26% of supply created in one shot and they only flagged 4 wallets? guaranteed some of those tokens already moved through mixers. good luck freezing that
Pavel D. 4 wallets flagged after 26% of the supply got minted overnight. harmony clearly had no incident response plan for this scenario
the part that gets me is they published the addresses AFTER the dumping started. like closing the barn door while the horse is on an exchange
^ honestly the response time was decent compared to some hacks. wormhole took hours to even acknowledge. not defending harmony just saying
4 billion tokens minted through empty blocks and nobody flagged it until morning? consensus on that chain has been broken for a while imo
@mishka the empty blocks thing is wild. thats not even a smart contract bug, thats the actual minting logic being wide open
mishka_sol minting 4B through empty blocks means the consensus rules were never enforced properly. this was a time bomb since 2022
time bomb is the right word. empty block minting isn’t a bug you hotfix, the emission rules themselves were broken. that needs a full rewrite
First the Horizon bridge for 100M, now this. How many passes does a chain get before people stop calling it a coincidence
two is my limit. a bridge hack can be an outside contract, broken emission rules are the chain itself. ONE holders just learned which one matters
Agreed on the distinction. A bridge is an add-on, emission rules are the chain itself. An ATL for ONE feels deserved after this
if 2.8 billion hit exchanges before anyone noticed, listed venues are complicit in the dump. deposit address monitoring is a solved problem, they just dont bother flagging small caps
latency_toll_ venues flagged nothing while a quarter of the supply moved onto their hot wallets overnight. their surveillance is clearly selective
venues will list anything with volume until a regulator letter arrives. 2.8B ONE landing on hot wallets overnight and zero circuit breaker, complicit is fair
wakeup check for every small cap holder. nobody asks how empty blocks behave until 4 billion coins materialize and the chart is vertical down
held ONE since 2023 staked through their own delegate UI. woke up to a chart going vertical down while the dashboard still showed rewards accruing lol. at least after the horizon bridge you got a year to exit, this one happened overnight
4 billion tokens equal to a quarter of supply minted overnight. so much for fixed emission rules, apparently empty blocks were a minting backdoor the whole time
^ 26% dilution while holders sleep and the explorer still shows it as routine block rewards. supply charts are fiction until someone audits empty blocks
The explorer showed those mints as routine validator rewards because the code treated them that way. Whatever fix ships needs a hard cap on emission per block, otherwise the supply charts stay fiction.
Petar Iliev a hard cap on emission per block plus a breaker if supply drifts off schedule. without the second part the cap just gets gamed at the edges
breaker plus cap is table stakes but the harder question is who watches it at 3am. harmony had no oncall for emission anomalies, monitoring was the actual failure
one wallet minting through empty blocks and the chain kept validating like everything was normal. if consensus cant flag a 4 billion coin anomaly the tokenomics were decorative
the part nobody mentions is listing standards. a coin whose emission can be inflated 26 percent overnight still trades on major venues like nothing happened
Empty blocks as a minting backdoor is the detail that should haunt every fixed-supply pitch deck. The cap only counts if something enforces it.