Skip to main content
Sign in
Harmony ONE (Protocol Entity)3 decisions on this page

Audit log

Every state-changing event for Harmony ONE (Protocol Entity): moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-08-24 23:18:23Z
    Score: ?? (no score change)
    anchorpending
    chain
    hash
    Dr7b5ugoy9tU…VPo8PLvqsha256 → base58
    verifying row…
    canonical bytes (26453 B) ▸
    {"actor":"system:backfill","investigation_id":"92b40233-bfe5-4980-b742-f3d9e6b014e2","kind":"publish","page_slug":"harmony-one-protocol-entity","published_at":"2026-08-24T23:18:23.630Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Harmony ONE (Protocol Entity)","sections":[{"content":"Harmony is a layer-1 blockchain designed for scalability through random state sharding. It uses a Fast Byzantine Fault Tolerance (FBFT) consensus protocol and an Effective Proof-of-Stake (EPoS) mechanism intended to reduce stake centralisation. The protocol was founded by Stephen Tse in 2017. Tse holds a PhD in cryptographic protocols from the University of Pennsylvania and previously held engineering roles at Google and Apple. Harmony raised approximately $18 million in a seed round and an additional $5 million via a Binance Launchpad IEO in May 2019, which was priced at $0.00318 per ONE token. The mainnet launched in June 2019, with staking enabled in May 2020. The ONE token reached an all-time high of approximately $0.379 in October 2021.","heading":"Protocol Overview","severity":"low","sources":[{"credibility":2,"name":"Coin Bureau: Harmony Review","type":"research","url":"https://coinbureau.com/review/harmony-one"},{"credibility":2,"name":"Coinspeaker: Harmony IEO on Binance Launchpad","type":"news_article","url":"https://www.coinspeaker.com/ieo-binance-launchpad-harmony-token-sale/"},{"credibility":2,"name":"HackerNoon: Founder Interview — Stephen Tse of Harmony.one","type":"other","url":"https://hackernoon.com/founder-interviews-stephen-tse-of-harmony-one-6bdf016d1e40"}]},{"content":"On June 24, 2022, Harmony's cross-chain Horizon Bridge was exploited and approximately $99.6 million in cryptoassets was stolen, including WETH, USDC, USDT, DAI, SUSHI, and AAVE. The theft occurred across 14 transactions on Ethereum and Binance Smart Chain and was caused by the compromise of private keys used to control a multisig wallet securing the bridge. Blockchain analytics firm Elliptic attributed the attack to APT38, also known as the Lazarus Group, within days of the incident. In January 2023, the United States Federal Bureau of Investigation formally confirmed that Lazarus Group — a state-sponsored threat actor operating on behalf of the Democratic People's Republic of Korea (DPRK) — was responsible for the theft. The stolen assets were swapped for Ether and laundered through the now-sanctioned Tornado Cash mixer. In January 2023, approximately $60 million was moved through the Ethereum privacy protocol Railgun. Harmony offered a $1 million bounty for the return of funds and stated it would advocate for no criminal charges if funds were returned. The funds were not recovered as of the publication date of this page. The U.S. Department of the Treasury's Office of Foreign Assets Control had previously sanctioned the Lazarus Group in 2019.","heading":"2022 Horizon Bridge Hack — FBI-Attributed to Lazarus Group","severity":"critical","sources":[{"credibility":1,"name":"Elliptic: The Harmony Horizon Bridge Hack","type":"research","url":"https://www.elliptic.co/resources/harmony-horizon-bridge-hack"},{"credibility":1,"name":"FBI Press Release: Lazarus Group Responsible for Harmony Horizon Bridge Theft","type":"regulatory","url":"https://www.fbi.gov/news/press-releases/fbi-confirms-lazarus-group-cyber-actors-responsible-for-harmonys-horizon-bridge-currency-theft"},{"credibility":2,"name":"Decrypt: FBI Confirms North Korea Behind $100 Million Harmony Hack","type":"news_article","url":"https://decrypt.co/119861/fbi-north-korea-lazarus-horizon-harmony-bridge-hack"},{"credibility":1,"name":"Elliptic: Over $1 Billion Stolen from Bridges in 2022 — Harmony Horizon Analysis","type":"research","url":"https://www.elliptic.co/blog/analysis/over-1-billion-stolen-from-bridges-so-far-in-2022-as-harmony-s-horizon-bridge-becomes-latest-victim-in-100-million-hack/hss_channeltw-1344645140"},{"credibility":2,"name":"Harmony Community Forum: Summary of the Horizon Bridge Incident","type":"official","url":"https://talk.harmony.one/t/summary-of-the-horizon-bridge-incident/20990"},{"credibility":1,"name":"CoinDesk: Harmony Networks Horizon Bridge Exploited for $100M","type":"news_article","url":"https://www.coindesk.com/tech/2022/06/24/harmony-networks-horizon-bridge-exploited-for-100m"},{"credibility":1,"name":"CFR Cyber Operations: Targeting of Harmony Cryptocurrency Bridge","type":"research","url":"https://www.cfr.org/cyber-operations/targeting-of-harmony-cryptocurrency-bridge"}]},{"content":"Following the 2022 Horizon Bridge hack, Harmony introduced a community-driven recovery programme. The programme involved using treasury funds to reimburse depegged assets over a four-year horizon through a token burn mechanism. The Recovery ONE Foundation entered a burn phase in 2023 in coordination with ecosystem partners including Modulo and Tranquil Finance. Multiple funding rounds were distributed through the Recovery ONE mechanism, with Round 10 in July 2023 allocating $100,000 among burn partners. Community discussion and governance participation were conducted through the Harmony Community Forum. Full reimbursement of stolen funds was not achieved, and the recovery programme's total effectiveness has not been independently verified.","heading":"Post-2022 Recovery Efforts","severity":"medium","sources":[{"credibility":2,"name":"Harmony Bridge Recovery Plan Update — September 2022","type":"official","url":"https://medium.com/harmony-one/harmony-bridge-recovery-plan-update-september-29-2022-632dbac20505"},{"credibility":2,"name":"Recovery ONE Foundation: Round 10 Summary","type":"official","url":"https://recoveryonefoundation.medium.com/harmony-recovery-round-10-b6a0bbaa9cd8"},{"credibility":3,"name":"Harmony Community Forum: Recovery ONE Burn Phase","type":"community_report","url":"https://talk.harmony.one/t/recovery-one-burn-phase/21727"}]},{"content":"On August 12, 2026, an attacker exploited multiple compounding vulnerabilities in Harmony's consensus layer to fraudulently mint ONE tokens without corresponding debits. Harmony's official incident update published on August 13, 2026 confirmed the attack began at approximately 23:25:40 UTC on August 11, with the first confirmed activity on Shard 0 at block 92,730,036. Two waves of minting were identified: an initial wave of approximately 4 billion ONE across two empty-block transactions (1 billion ONE at block 92,731,152 and 3 billion ONE at block 92,732,898), and a fuller accounting of approximately 3.01 trillion ONE across six forged cross-shard transactions into four exploiter wallets.\n\nTechnical analysis published by Verichains identified three complementary vulnerabilities. First, a quorum verification bypass: the function IsQuorumAchievedByMask() compared the full committee's public key count against a threshold rather than counting actual signatures in the bitmap, meaning an all-zero bitmap with an identity aggregate BLS signature could satisfy quorum for pre-staking committees. Second, unsigned Merkle proof identity fields: cross-shard receipt proofs contained ShardID and BlockNum as separate, unsigned copies of header fields, allowing attackers to mutate these values while keeping the BLS signature and header byte-identical, enabling the same receipt to be replayed with different identities. Third, weak replay protection logic: the Bloom hard fork's improved spent-marker system checked the epoch inside the proof's own header rather than the current chain epoch, leaving pre-fork receipts vulnerable to the legacy replay path keyed to mutable unsigned fields.\n\nApproximately 2.8 billion ONE tokens moved to intermediate attacker-controlled addresses within minutes of minting, and approximately 97% of minted tokens moved toward exchange deposit addresses according to reporting by TechTimes. Harmony deployed emergency patch v2026.1.1 on August 12 at 06:30 UTC and halted Shard 0 at block 92,753,555 to prepare for rollback. The attacker's identity had not been publicly disclosed as of available reporting.","heading":"August 2026 Cross-Shard Mint Exploit — Consensus-Layer Failure","severity":"critical","sources":[{"credibility":1,"name":"Harmony Protocol Incident Update: August 13, 2026 (Official X Post)","type":"official","url":"https://x.com/harmonyprotocol/article/2088078119269978281"},{"credibility":2,"name":"Verichains: Harmony Cross-Shard Receipt Replay — The Mint of 3 Trillion ONE","type":"research","url":"https://blog.verichains.io/p/harmony-cross-shard-receipt-replay"},{"credibility":1,"name":"The Block: Harmony Plans Pre-Attack Rollback After Exploiter Forged 3 Trillion ONE Tokens","type":"news_article","url":"https://www.theblock.co/news/ecosystems/2026-08-17-harmony-plans-pre-attack-rollback-after-exploiter-forged-3-trillion-one-tokens-411976"},{"credibility":2,"name":"Shattered.io: Harmony ONE Crashes 37% as Hacker Mints 4B Tokens","type":"news_article","url":"https://shattered.io/harmony-one-exploit-4-billion-tokens-2026/"},{"credibility":2,"name":"TechTimes: Harmony ONE Hacked — 4 Billion Tokens Minted, 97% Sent to Exchanges","type":"news_article","url":"https://www.techtimes.com/articles/324068/20260812/harmony-one-hacked-4-billion-tokens-minted-supply-masking-sent-97-exchanges.htm"},{"credibility":2,"name":"KuCoin Flash: Harmony Protocol Confirms Abnormal Minting, Network Rollback Planned","type":"news_article","url":"https://www.kucoin.com/news/flash/harmony-protocol-confirms-one-abnormal-minting-network-rollback-planned"},{"credibility":1,"name":"CoinDesk: Harmony ONE Falls 40% After Attacker Allegedly Mints 4 Billion Tokens","type":"news_article","url":"https://www.coindesk.com/markets/2026/08/12/harmony-s-one-falls-26-after-attacker-allegedly-mints-4-billion-tokens"}]},{"content":"Following the August 12, 2026 exploit, the ONE token fell sharply across major exchanges. The token reached an all-time low of $0.0005735 according to multiple sources, representing a decline of between 29% and 51% within hours of the incident. At the time of the crash the token was already approximately 99.8% below its all-time high of $0.379, set in October 2021. The approximately 4 billion ONE minted in the initial wave represented roughly 26% of the circulating supply, constituting severe inflationary dilution. By the morning of August 13 in European trading hours the token had partially recovered to approximately $0.0007681, reflecting a rebound of approximately 34% from the low. Market confidence remained severely depressed, and analysts noted that the exploit compounded already deep losses from the 2022 Horizon Bridge hack and its subsequent recovery period.","heading":"August 2026 Price Impact and Token Dilution","severity":"critical","sources":[{"credibility":2,"name":"DailyCoin: Harmony ONE Hits All-Time Low After 4B Token Mint Exploit","type":"news_article","url":"https://dailycoin.com/harmony-one-hits-to-all-time-low-after-4b-token-mint-exploit"},{"credibility":2,"name":"BeInCrypto: Harmony Token Falls to Record Low After Exploit Mints 4 Billion ONE","type":"news_article","url":"https://beincrypto.com/harmony-one-record-low-exploit-mint/"},{"credibility":2,"name":"Shattered.io: Harmony ONE Crashes 37% as Hacker Mints 4B Tokens","type":"news_article","url":"https://shattered.io/harmony-one-exploit-4-billion-tokens-2026/"},{"credibility":2,"name":"Coinpedia: Harmony Protocol Hack — 4 Billion ONE Tokens Minted, Price Crashes 30%","type":"news_article","url":"https://coinpedia.org/news/harmony-protocol-hack-4-billion-one-tokens-minted-price-crashes-30/"}]},{"content":"On approximately August 17–18, 2026, Harmony announced and began executing a full blockchain rollback to pre-attack checkpoints. Shard 0 was reverted to block 92,730,034 and Shard 1 to block 94,978,278, both timestamped at 23:25:37 UTC on August 11, 2026 — moments before the first confirmed forged mint. The rollback eliminated more than 109,000 regular transactions and 315 staking transactions that had been confirmed after those checkpoints. Approximately 95.8% of discarded transactions were classified as automated, with DEX automation accounting for approximately 99,863 of the erased transactions. As of August 21, 2026, both shards were reported stable and advancing through normal epoch progression.\n\nThe rollback decision generated significant industry criticism. Critics argued that the ability of a small development team and validator set to coordinate and execute a unilateral rewrite of ledger history demonstrated that Harmony was not functionally decentralised. Crowdfund Insider reported that the action raised direct concerns about blockchain immutability and decentralisation. Harmony considered but rejected alternatives including direct token removal (forged ONE had already dispersed across exchanges and pools), a blacklisting approach (risk of freezing legitimate holdings), and transaction replay (state inconsistencies). The team deployed replacement databases for affected shards rather than using the standard revert function, which Harmony stated 'mainly moves chain heads and does not fully clear later receipts, indexes, snapshots and cross-shard information.' A significant proportion of the attacker's gains — tokens already converted and held in custody by centralised exchanges — could not be reversed by any blockchain rewrite.","heading":"Chain Rollback — Centralisation and Immutability Concerns","severity":"high","sources":[{"credibility":2,"name":"crypto.news: Harmony Plans Chain Rollback as Forged ONE Spreads Across Network","type":"news_article","url":"https://crypto.news/harmony-plans-chain-rollback-as-forged-one-spreads-across-network/"},{"credibility":2,"name":"Crowdfund Insider: Harmony Protocol Plans Network Rollback After Token Forgery Exploit","type":"news_article","url":"https://www.crowdfundinsider.com/2026/08/298395-harmony-protocol-plans-network-rollback-after-token-forgery-exploit-raising-blockchain-immutability-and-lack-of-decentralization-concerns/"},{"credibility":2,"name":"Coinpaprika: Harmony Will Roll Back Its Blockchain to Erase 3 Trillion Forged Tokens","type":"news_article","url":"https://coinpaprika.com/news/harmony-roll-back-blockchain-erase-3-trillion/"},{"credibility":2,"name":"IDOSLaunchPad: Harmony Plans Rollback, Wiping 109,000 Transactions After ONE Exploit","type":"news_article","url":"https://www.idoslaunchpad.com/harmony-plans-rollback-wiping-109000-transactions-after-one-exploit/"},{"credibility":2,"name":"GlobalCryptoPress: Harmony Exploit Forged 3.01 Trillion Tokens, Reverting Blockchain","type":"news_article","url":"https://www.globalcryptopress.com/2026/08/harmony-exploit-forged-301-trillion.html"},{"credibility":2,"name":"BingX Flash: Harmony Protocol Says 4B ONE Illegally Minted, Plans Chain Rollback","type":"news_article","url":"https://bingx.com/en/flash-news/post/harmony-confirms-billion-one-minted-in-aug-attack-pauses-shard-and-plans-rollback-to-block"}]},{"content":"The ONE token has a stated maximum supply of 12.6 billion tokens. Annual issuance was set at 441 million ONE, declining over time, with transaction fees burned. The Binance Launchpad IEO in May 2019 allocated 12.5% of the total supply at a price of $0.00318 per token and raised $5 million. A prior seed round raised approximately $18 million from investors including Lemniscap, Consensus Capital, UniValues Associates, and BCA Fund. The August 2026 exploit's forged issuance — ranging from 4 billion in the initial wave to a full-scope estimate of 3.01 trillion across six transactions — represented a potential supply dilution orders of magnitude beyond the total stated cap. The chain rollback was the mechanism chosen to void the forged supply, though forged tokens already liquidated at exchanges could not be recovered by this means.","heading":"Tokenomics and Supply History","severity":"high","sources":[{"credibility":2,"name":"CoinLore: Harmony ONE ICO and Tokenomics","type":"research","url":"https://www.coinlore.com/coin/harmony/ico-tokenomics"},{"credibility":2,"name":"CryptoRank: Harmony ONE IEO Funding Rounds and Tokenomics","type":"research","url":"https://cryptorank.io/ico/harmony"}]}],"sources_used":[{"credibility":1,"name":"FBI: Lazarus Group Responsible for Harmony Horizon Bridge Theft","type":"regulatory","url":"https://www.fbi.gov/news/press-releases/fbi-confirms-lazarus-group-cyber-actors-responsible-for-harmonys-horizon-bridge-currency-theft"},{"credibility":1,"name":"Elliptic: The Harmony Horizon Bridge Hack","type":"research","url":"https://www.elliptic.co/resources/harmony-horizon-bridge-hack"},{"credibility":1,"name":"Elliptic: Over $1 Billion Stolen from Bridges in 2022","type":"research","url":"https://www.elliptic.co/blog/analysis/over-1-billion-stolen-from-bridges-so-far-in-2022-as-harmony-s-horizon-bridge-becomes-latest-victim-in-100-million-hack/hss_channeltw-1344645140"},{"credibility":1,"name":"Harmony Protocol Incident Update August 13 2026","type":"official","url":"https://x.com/harmonyprotocol/article/2088078119269978281"},{"credibility":2,"name":"Verichains: Harmony Cross-Shard Receipt Replay Technical Analysis","type":"research","url":"https://blog.verichains.io/p/harmony-cross-shard-receipt-replay"},{"credibility":1,"name":"The Block: Harmony Plans Pre-Attack Rollback After 3 Trillion ONE Forged","type":"news_article","url":"https://www.theblock.co/news/ecosystems/2026-08-17-harmony-plans-pre-attack-rollback-after-exploiter-forged-3-trillion-one-tokens-411976"},{"credibility":1,"name":"CoinDesk: Harmony ONE Falls 40% After Attacker Allegedly Mints 4B Tokens","type":"news_article","url":"https://www.coindesk.com/markets/2026/08/12/harmony-s-one-falls-26-after-attacker-allegedly-mints-4-billion-tokens"},{"credibility":1,"name":"CoinDesk: Harmony Networks Horizon Bridge Exploited for $100M","type":"news_article","url":"https://www.coindesk.com/tech/2022/06/24/harmony-networks-horizon-bridge-exploited-for-100m"},{"credibility":2,"name":"Decrypt: FBI Confirms North Korea Behind $100M Harmony Hack","type":"news_article","url":"https://decrypt.co/119861/fbi-north-korea-lazarus-horizon-harmony-bridge-hack"},{"credibility":2,"name":"crypto.news: Harmony Plans Chain Rollback as Forged ONE Spreads","type":"news_article","url":"https://crypto.news/harmony-plans-chain-rollback-as-forged-one-spreads-across-network/"},{"credibility":2,"name":"Crowdfund Insider: Harmony Protocol Plans Network Rollback — Immutability and Decentralisation Concerns","type":"news_article","url":"https://www.crowdfundinsider.com/2026/08/298395-harmony-protocol-plans-network-rollback-after-token-forgery-exploit-raising-blockchain-immutability-and-lack-of-decentralization-concerns/"},{"credibility":2,"name":"Coinpaprika: Harmony Will Roll Back Its Blockchain to Erase 3 Trillion Forged Tokens","type":"news_article","url":"https://coinpaprika.com/news/harmony-roll-back-blockchain-erase-3-trillion/"},{"credibility":2,"name":"DailyCoin: Harmony ONE Hits All-Time Low After 4B Token Mint Exploit","type":"news_article","url":"https://dailycoin.com/harmony-one-hits-to-all-time-low-after-4b-token-mint-exploit"},{"credibility":2,"name":"Shattered.io: Harmony ONE Crashes 37% as Hacker Mints 4B Tokens","type":"news_article","url":"https://shattered.io/harmony-one-exploit-4-billion-tokens-2026/"},{"credibility":2,"name":"Coinpedia: Harmony Protocol Hack — 4 Billion ONE Tokens Minted, Price Crashes 30%","type":"news_article","url":"https://coinpedia.org/news/harmony-protocol-hack-4-billion-one-tokens-minted-price-crashes-30/"},{"credibility":2,"name":"TechTimes: Harmony ONE Hacked — 97% of Tokens Sent to Exchanges","type":"news_article","url":"https://www.techtimes.com/articles/324068/20260812/harmony-one-hacked-4-billion-tokens-minted-supply-masking-sent-97-exchanges.htm"},{"credibility":2,"name":"Harmony Community Forum: Summary of the Horizon Bridge Incident","type":"official","url":"https://talk.harmony.one/t/summary-of-the-horizon-bridge-incident/20990"},{"credibility":2,"name":"KuCoin Flash: Harmony Confirms Abnormal Minting, Network Rollback Planned","type":"news_article","url":"https://www.kucoin.com/news/flash/harmony-protocol-confirms-one-abnormal-minting-network-rollback-planned"},{"credibility":2,"name":"BeInCrypto: Harmony Token Falls to Record Low After Exploit Mints 4B ONE","type":"news_article","url":"https://beincrypto.com/harmony-one-record-low-exploit-mint/"},{"credibility":2,"name":"IDOSLaunchPad: Harmony Plans Rollback Wiping 109,000 Transactions","type":"news_article","url":"https://www.idoslaunchpad.com/harmony-plans-rollback-wiping-109000-transactions-after-one-exploit/"},{"credibility":2,"name":"Harmony Bridge Recovery Plan Update — September 2022","type":"official","url":"https://medium.com/harmony-one/harmony-bridge-recovery-plan-update-september-29-2022-632dbac20505"},{"credibility":2,"name":"Recovery ONE Foundation: Harmony Recovery Round 10","type":"official","url":"https://recoveryonefoundation.medium.com/harmony-recovery-round-10-b6a0bbaa9cd8"},{"credibility":1,"name":"CFR Cyber Operations: Targeting of Harmony Cryptocurrency Bridge","type":"research","url":"https://www.cfr.org/cyber-operations/targeting-of-harmony-cryptocurrency-bridge"},{"credibility":2,"name":"CoinLore: Harmony ONE ICO and Tokenomics","type":"research","url":"https://www.coinlore.com/coin/harmony/ico-tokenomics"},{"credibility":2,"name":"GlobalCryptoPress: Harmony Exploit Forged 3.01 Trillion Tokens","type":"news_article","url":"https://www.globalcryptopress.com/2026/08/harmony-exploit-forged-301-trillion.html"}],"summary":"Harmony (ONE) is a layer-1 sharded proof-of-stake blockchain founded in 2017 and launched on mainnet in June 2019. The protocol has suffered two major security incidents: the June 2022 Horizon Bridge hack attributed by the FBI to the DPRK-linked Lazarus Group, in which approximately $100 million was stolen, and an August 2026 cross-shard mint exploit in which an attacker forged between 4 billion and 3.01 trillion ONE tokens by exploiting a consensus-layer quorum verification flaw. The 2026 incident drove the ONE token to an all-time low of $0.0005735 and prompted an unilateral chain rollback erasing over 109,000 confirmed transactions, raising systemic concerns about the network's security architecture and degree of decentralisation.","timeline":[{"date":"2017-01-01","event":"Harmony Protocol founded by Stephen Tse.","source":"HackerNoon Founder Interview","source_url":"https://hackernoon.com/founder-interviews-stephen-tse-of-harmony-one-6bdf016d1e40"},{"date":"2019-05-29","event":"Harmony ONE IEO launched on Binance Launchpad at $0.00318 per token, raising $5 million.","source":"Coinspeaker","source_url":"https://www.coinspeaker.com/ieo-binance-launchpad-harmony-token-sale/"},{"date":"2019-06-01","event":"Harmony mainnet launches.","source":"Coin Bureau Review","source_url":"https://coinbureau.com/review/harmony-one"},{"date":"2020-05-16","event":"Harmony launches staking, becoming the first sharded blockchain to offer staking.","source":"Coin Bureau Review","source_url":"https://coinbureau.com/review/harmony-one"},{"date":"2021-10-01","event":"ONE token reaches all-time high of approximately $0.379.","source":"DailyCoin","source_url":"https://dailycoin.com/harmony-one-hits-to-all-time-low-after-4b-token-mint-exploit"},{"date":"2022-06-24","event":"Harmony's Horizon Bridge exploited for approximately $99.6 million via private key compromise. Assets stolen include WETH, USDC, USDT, DAI, SUSHI, and AAVE across 14 transactions.","source":"Elliptic Analysis","source_url":"https://www.elliptic.co/blog/analysis/over-1-billion-stolen-from-bridges-so-far-in-2022-as-harmony-s-horizon-bridge-becomes-latest-victim-in-100-million-hack/hss_channeltw-1344645140"},{"date":"2023-01-13","event":"FBI formally confirms Lazarus Group (DPRK-linked) was responsible for the 2022 Horizon Bridge hack. Separately, approximately $60 million in stolen ETH moves through privacy protocol Railgun.","source":"FBI Press Release / Decrypt","source_url":"https://decrypt.co/119861/fbi-north-korea-lazarus-horizon-harmony-bridge-hack"},{"date":"2026-08-11","event":"At 23:25:40 UTC, an attacker begins exploiting cross-shard receipt replay and quorum verification bypass vulnerabilities in Harmony Mainnet.","source":"Harmony Official Incident Update","source_url":"https://x.com/harmonyprotocol/article/2088078119269978281"},{"date":"2026-08-12","event":"Approximately 4 billion ONE tokens minted across two empty-block transactions (1B ONE at block 92,731,152 and 3B ONE at block 92,732,898). Approximately 2.8 billion ONE moved to exchange deposit addresses within minutes. ONE token falls to all-time low of $0.0005735.","source":"Harmony Official Incident Update / DailyCoin","source_url":"https://x.com/harmonyprotocol/article/2088078119269978281"},{"date":"2026-08-12","event":"Harmony deploys emergency patch v2026.1.1 at 06:30 UTC, halts Shard 0 at block 92,753,555, pauses bridge, and contacts exchanges to freeze exploiter-linked wallets.","source":"Harmony Official Incident Update","source_url":"https://x.com/harmonyprotocol/article/2088078119269978281"},{"date":"2026-08-13","event":"Harmony publishes official incident update. Full-scope estimate of forged supply revised to approximately 3.01 trillion ONE across six cross-shard transactions into four exploiter wallets.","source":"Harmony Official Incident Update","source_url":"https://x.com/harmonyprotocol/article/2088078119269978281"},{"date":"2026-08-17","event":"Harmony announces plan to roll back blockchain to pre-attack checkpoints on August 11 (Shard 0: block 92,730,034; Shard 1: block 94,978,278), eliminating 109,000+ regular transactions and 315 staking transactions.","source":"The Block / crypto.news","source_url":"https://crypto.news/harmony-plans-chain-rollback-as-forged-one-spreads-across-network/"},{"date":"2026-08-20","event":"Validators activate second stage of the rollback procedure.","source":"CoinMarketCap AI News / CryptoRank","source_url":"https://cryptorank.io/news/feed/36e8b-harmony-blockchain-rollback-counterfeit-one-attack"},{"date":"2026-08-21","event":"Rollback reported complete. Both shards stable for 24+ hours with near-full signing participation, advancing from epoch 3002 to 3004.","source":"CoinMarketCap Latest News","source_url":"https://coinmarketcap.com/cmc-ai/harmony/latest-updates/"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision 8cb6653e-2939-4f60-9a97-9517ef36782b
  2. #2reviewby reviewerreviewer
    2026-08-25 02:47:24Z
    Score: 1414 (no score change)
    The page's claims are substantially corroborated by independent reporting for both the 2022 Horizon Bridge hack and the August 2026 cross-shard mint exploit and subsequent rollback; core figures (dollar amounts, block numbers, transaction counts, price data) were independently verified against multiple outlets and, where possible, primary sources. No claims were found to be disputed or subject to link rot. Weaknesses are minor: some granular figures rely on a single official source (an X post) that could not be independently accessed, one claim (funds 'not recovered') omits a nuance about partial fund interception, and a small number of tokenomics/technical details are accurate but not directly supported by the specific sources the page cites for them.
    anchorpending
    chain
    hash
    3d3EJSSLNnig…PLHvF5oNsha256 → base58
    verifying row…
    canonical bytes (1125 B) ▸
    {"actor":"reviewer","decided_at":"2026-08-25T02:47:23.748Z","decision":"review","investigation_id":"92b40233-bfe5-4980-b742-f3d9e6b014e2","new_score":14,"page_slug":"harmony-one-protocol-entity","prev_score":14,"reason":"The page's claims are substantially corroborated by independent reporting for both the 2022 Horizon Bridge hack and the August 2026 cross-shard mint exploit and subsequent rollback; core figures (dollar amounts, block numbers, transaction counts, price data) were independently verified against multiple outlets and, where possible, primary sources. No claims were found to be disputed or subject to link rot. Weaknesses are minor: some granular figures rely on a single official source (an X post) that could not be independently accessed, one claim (funds 'not recovered') omits a nuance about partial fund interception, and a small number of tokenomics/technical details are accurate but not directly supported by the specific sources the page cites for them.","score_delta":0,"sequence_num":2,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision 16328e55-c480-4261-8935-8ca1c1e902ab
  3. #3review reviseby judgejudge
    2026-08-25 02:47:24Z
    Score: 148 (-6)
    None of the page's core allegations were found false: the 2022 Horizon Bridge hack, its FBI/Lazarus Group attribution, and the August 2026 cross-shard mint exploit and rollback are all independently corroborated by multiple Tier 1-2 sources with zero disputed claims. However, recomputed over the reviewer's full 30-item claim_findings array, 3 of 30 claims (10.0%) land as unverifiable, and several other items show real friction: the single most heavily relied-upon source for granular 2026 incident details (an official X/Twitter post) returned HTTP 402 with no archived snapshot, leaving the precise attack-start block number unconfirmed (claim_findings[15]) and the emergency-patch halt block only partially supported (claim_findings[19]). The claim that both shards were 'stable' and had advanced from epoch 3002 to 3004 as of August 21 rests solely on a dynamically-updating AI aggregator page rather than a fixed, citable source (claim_findings[24]). Separately, the page's blanket statement that stolen Horizon Bridge funds were 'not recovered' omits contemporaneous reporting of a partial ~124 BTC interception (claim_findings[12]). These are citation-durability and completeness issues rather than factual disputes, so a modest downward adjustment with no status change is warranted rather than a more severe penalty.
    anchorpending
    chain
    hash
    EW8TbK8L2dvX…k17puo5jsha256 → base58
    verifying row…
    canonical bytes (1695 B) ▸
    {"actor":"judge","decided_at":"2026-08-25T02:47:23.748Z","decision":"review_revise","investigation_id":"92b40233-bfe5-4980-b742-f3d9e6b014e2","new_score":8,"page_slug":"harmony-one-protocol-entity","prev_score":14,"reason":"None of the page's core allegations were found false: the 2022 Horizon Bridge hack, its FBI/Lazarus Group attribution, and the August 2026 cross-shard mint exploit and rollback are all independently corroborated by multiple Tier 1-2 sources with zero disputed claims. However, recomputed over the reviewer's full 30-item claim_findings array, 3 of 30 claims (10.0%) land as unverifiable, and several other items show real friction: the single most heavily relied-upon source for granular 2026 incident details (an official X/Twitter post) returned HTTP 402 with no archived snapshot, leaving the precise attack-start block number unconfirmed (claim_findings[15]) and the emergency-patch halt block only partially supported (claim_findings[19]). The claim that both shards were 'stable' and had advanced from epoch 3002 to 3004 as of August 21 rests solely on a dynamically-updating AI aggregator page rather than a fixed, citable source (claim_findings[24]). Separately, the page's blanket statement that stolen Horizon Bridge funds were 'not recovered' omits contemporaneous reporting of a partial ~124 BTC interception (claim_findings[12]). These are citation-durability and completeness issues rather than factual disputes, so a modest downward adjustment with no status change is warranted rather than a more severe penalty.","score_delta":-6,"sequence_num":3,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision 39c6aca5-a85f-41f2-b614-29b6c7859f62
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.