← Harmony Protocol — ONE Token Unauthorized Mint Exploit (August 2026)1 decision on this page
Audit log
Every state-changing event for Harmony Protocol — ONE Token Unauthorized Mint Exploit (August 2026): moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-08-12 23:05:46ZScore: ? → ? (no score change)anchorpending
- chain
- ●—
- hash
B7fAR3cDBB4Q…n5cbUYYrsha256 → base58
verifying row…canonical bytes (22748 B) ▸
{"actor":"system:backfill","investigation_id":"6269bb42-c37e-4361-a723-04ab3cc5f416","kind":"publish","page_slug":"harmony-protocol-one-token-unauthorized-mint-exploit-august-2026","published_at":"2026-08-12T23:05:46.177Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Harmony Protocol — ONE Token Unauthorized Mint Exploit (August 2026)","sections":[{"content":"On August 12, 2026, on-chain analyst Juiceberg publicly flagged an anomalous mint event on the Harmony blockchain. Harmony Protocol subsequently confirmed that an exploit had resulted in the unauthorized creation of approximately 4 billion ONE tokens. This figure, if accurate, represents an increase of approximately 26% over the roughly 15 billion ONE previously in circulation. Harmony did not independently confirm the 4 billion token figure or disclose the root cause of the exploit as of the date of this report. The minting is alleged to have been accomplished through exploitation of empty blocks, a method that exposed a flaw in the network's block accounting or validation logic rather than a theft of pre-existing user funds. The attacker rapidly transferred approximately 2.8 billion ONE tokens to centralized exchange deposit addresses, representing roughly 97% of the illicit supply. Approximately 115 million ONE (roughly 2.9% of the minted amount) remained on-chain. Harmony's totalSupply endpoint allegedly failed to reflect the newly minted tokens at the time of the exploit, potentially obscuring the dilution from users, monitoring systems, and exchanges.","heading":"Exploit Overview","severity":"critical","sources":[{"credibility":2,"name":"Harmony confirms exploit involving unauthorized minting of 4 billion ONE tokens — The Block","type":"news_article","url":"https://www.theblock.co/news/defi/2026-08-12-harmony-confirms-exploit-one-token-411527"},{"credibility":2,"name":"Harmony weighs a full blockchain rollback after unauthorized minting floods exchanges with billions in ONE — CryptoSlate","type":"news_article","url":"https://cryptoslate.com/harmony-weighs-a-full-blockchain-rollback-after-unauthorized-minting-floods-exchanges-with-billions-in-one/"},{"credibility":1,"name":"Harmony's ONE falls 40% after attacker allegedly mints 4 billion tokens — CoinDesk","type":"news_article","url":"https://www.coindesk.com/markets/2026/08/12/harmony-s-one-falls-26-after-attacker-allegedly-mints-4-billion-tokens"},{"credibility":2,"name":"Harmony's ONE sinks 37% after attacker mints 4 billion tokens — Decrypt","type":"news_article","url":"https://decrypt.co/375390/harmonys-one-sinks-37-after-attacker-mints-4-billion-tokens"}]},{"content":"Analysis published by CryptoSlate identified two distinct weaknesses in Harmony's cross-shard receipt verification system. First, an empty signer record exploit: an attacker could submit an empty signer record paired with a mathematically neutral aggregate signature that passed quorum checks because the verifier counted the full committee size rather than the actual validators represented in the signer record. Second, a replay vulnerability: proof fields were not bound to signed block headers, enabling previously processed receipts to appear as new and trigger duplicate credits. Together, these two flaws allowed an attacker to induce the protocol to issue new ONE tokens without legitimate validator authorization. The official validator patch, v2026.1.1, references 'Cx receipt fixes' in its release notes, corresponding to the cross-shard receipt pathway described in independent analyses. Harmony's GitHub commit e9a05f6b68f0e95a6bb7f50669b01df18768cbd3 reflects the single pull request (#5101) that addressed the receipt functionality. The supply masking element, in which Harmony's totalSupply endpoint did not immediately reflect the token inflation, compounded the harm by allowing the minted tokens to reach exchanges before automated monitoring systems or exchange compliance teams could react.","heading":"Technical Vulnerability","severity":"critical","sources":[{"credibility":2,"name":"Harmony weighs a full blockchain rollback — CryptoSlate (technical analysis)","type":"news_article","url":"https://cryptoslate.com/harmony-weighs-a-full-blockchain-rollback-after-unauthorized-minting-floods-exchanges-with-billions-in-one/"},{"credibility":1,"name":"Release Mainnet Release 2026.1.1 — harmony-one/harmony GitHub","type":"official","url":"https://github.com/harmony-one/harmony/releases/tag/v2026.1.1"},{"credibility":2,"name":"Harmony's ONE sinks 37% after attacker mints 4 billion tokens — Decrypt (supply masking detail)","type":"news_article","url":"https://decrypt.co/375390/harmonys-one-sinks-37-after-attacker-mints-4-billion-tokens"}]},{"content":"The ONE token fell to a record low of approximately $0.0005735 in early Asian trading on August 12, 2026. Price decline estimates across sources range from 30% to 40% over the 24 hours following exploit disclosure. At the token's approximate price at the time of minting, the nominal dollar value of the 4 billion illicitly minted ONE tokens is estimated at approximately $3.2 million, a figure that reflects the token's already significantly depressed valuation relative to its all-time high of $0.379 reached in early 2022. The total market capitalization impact, reflecting the dilution of existing holders' percentage ownership, is proportionally larger. The rapid transfer of approximately 2.8 billion ONE to exchange deposit addresses suggests a deliberate strategy to liquidate the minted tokens before freeze requests could take effect.","heading":"Market Impact and Financial Damage","severity":"critical","sources":[{"credibility":2,"name":"Harmony Suffers Critical Exploit As 4B ONE Are Minted Without Authorization — Metaverse Post","type":"news_article","url":"https://mpost.io/harmony-suffers-critical-exploit-as-4b-one-are-minted-without-authorization-zachxbt-boycotts-recovery-efforts/"},{"credibility":1,"name":"Harmony's ONE falls 40% after attacker allegedly mints 4 billion tokens — CoinDesk","type":"news_article","url":"https://www.coindesk.com/markets/2026/08/12/harmony-s-one-falls-26-after-attacker-allegedly-mints-4-billion-tokens"},{"credibility":2,"name":"Harmony Token Falls to Record Low After Exploit Mints 4 Billion ONE — BeInCrypto","type":"news_article","url":"https://beincrypto.com/harmony-one-record-low-exploit-mint/"}]},{"content":"Harmony's team took several steps in the hours following the exploit's detection on August 12, 2026. Approximately two hours after the exploit was confirmed via social media, Harmony paused the bridge.harmony.one token bridge. Shortly thereafter, the team released emergency validator patch v2026.1.1 with instructions for all node operators to upgrade immediately. The patch is described as preventing further unauthorized minting through the identified receipt flaws. Harmony published four wallet addresses linked to the attacker and requested that all exchanges freeze funds traceable to those addresses: one1uap8dx2z0qsjxqthm5flgcxkeepsz3gsrghnfn, 0xe7427699427821230177dd13f460d6ce43014510, one17u300a40ll5wphd8kj5hktryhdjq3ml9f4phy4, and 0xf722f7f6afffe8e0dda7b4a97b2c64bb6408efe5. Harmony did not publicly name the exchanges it contacted, nor disclose the amounts frozen. The team also stated it was evaluating a potential full blockchain rollback, which would revert the network to a pre-exploit state but would simultaneously erase all legitimate user transactions conducted since the attack. No rollback decision had been announced as of the date of this report.","heading":"Official Response and Mitigation Efforts","severity":"high","sources":[{"credibility":2,"name":"Harmony confirms exploit involving unauthorized minting of 4 billion ONE tokens — The Block","type":"news_article","url":"https://www.theblock.co/news/defi/2026-08-12-harmony-confirms-exploit-one-token-411527"},{"credibility":2,"name":"Harmony Weighs Rollback After Claims of 4B ONE Exploit — CoinTelegraph","type":"news_article","url":"https://cointelegraph.com/news/armony-rollback-alleged-one-token-mint"},{"credibility":1,"name":"Release Mainnet Release 2026.1.1 — harmony-one/harmony GitHub","type":"official","url":"https://github.com/harmony-one/harmony/releases/tag/v2026.1.1"},{"credibility":1,"name":"Harmony's ONE falls 40% after attacker allegedly mints 4 billion tokens — CoinDesk","type":"news_article","url":"https://www.coindesk.com/markets/2026/08/12/harmony-s-one-falls-26-after-attacker-allegedly-mints-4-billion-tokens"}]},{"content":"On-chain investigator ZachXBT publicly declined to assist with recovery efforts following the August 2026 exploit. In a public statement, ZachXBT said: 'I will not be tracking this incident and think no one should assist them for free.' He cited Harmony's alleged mistreatment of individuals who assisted during the 2022 Horizon Bridge hack, claiming the protocol provided no compensation for 'significant asset freezes that resulted in law enforcement seizures' and offered only acknowledgment of their work. The initial exploit was flagged by on-chain analyst Juiceberg, though CoinTelegraph noted it could not independently verify the claims made by that account. Community sentiment was broadly negative given the protocol's history of prior security incidents.","heading":"Community and Investigator Response","severity":"medium","sources":[{"credibility":2,"name":"Harmony Suffers Critical Exploit As 4B ONE Are Minted Without Authorization, ZachXBT Boycotts Recovery Efforts — Metaverse Post","type":"news_article","url":"https://mpost.io/harmony-suffers-critical-exploit-as-4b-one-are-minted-without-authorization-zachxbt-boycotts-recovery-efforts/"},{"credibility":2,"name":"Harmony Weighs Rollback After Claims of 4B ONE Exploit — CoinTelegraph","type":"news_article","url":"https://cointelegraph.com/news/armony-rollback-alleged-one-token-mint"}]},{"content":"The August 2026 exploit is Harmony Protocol's third major publicly disclosed security incident. In June 2022, the Harmony Horizon Bridge was exploited for approximately $100 million when attackers compromised two of the five private keys required to authorize bridge withdrawals. The FBI formally attributed that attack to North Korea's Lazarus Group (APT38) in January 2023, confirming earlier analysis by blockchain analytics firm Elliptic. Funds from the 2022 hack were laundered through Tornado Cash in a pattern consistent with prior Lazarus Group operations. In December 2023, a staking-logic vulnerability improperly created 146.28 million ONE tokens, a figure approximately 27 times smaller than the 2026 incident. No attribution to Lazarus Group or any state-sponsored actor has been made in connection with the August 2026 exploit. The pattern of recurring protocol-level vulnerabilities, combined with the ZachXBT refusal to assist citing prior mistreatment of researchers, presents a negative reputational context for the protocol's security posture and incident response culture.","heading":"Historical Security Context","severity":"high","sources":[{"credibility":2,"name":"The Harmony Horizon Bridge Hack — Elliptic","type":"research","url":"https://www.elliptic.co/resources/harmony-horizon-bridge-hack"},{"credibility":1,"name":"FBI Confirms Lazarus Group Cyber Actors Responsible for Harmony's Horizon Bridge Currency Theft — FBI","type":"regulatory","url":"https://www.fbi.gov/news/press-releases/fbi-confirms-lazarus-group-cyber-actors-responsible-for-harmonys-horizon-bridge-currency-theft"},{"credibility":2,"name":"FBI confirms North Korea's Lazarus Group as hackers behind $100 million Harmony Horizon Bridge theft — Elliptic","type":"research","url":"https://www.elliptic.co/blog/analysis/fbi-confirms-north-korea-s-lazarus-group-as-hackers-behind-100-million-harmony-horizon-bridge-theft"},{"credibility":2,"name":"Harmony's ONE Plunges 30% After Attacker Mints 4 Billion Tokens — Bitcoin.com News (2023 bug context)","type":"news_article","url":"https://news.bitcoin.com/security/harmonys-one-plunges-30-after-attacker-mints-4-billion-tokens/"}]},{"content":"Harmony published four wallet addresses alleged to be linked to the attacker, in both Harmony-native (bech32) and hex (EVM-compatible) formats: one1uap8dx2z0qsjxqthm5flgcxkeepsz3gsrghnfn, 0xe7427699427821230177dd13f460d6ce43014510, one17u300a40ll5wphd8kj5hktryhdjq3ml9f4phy4, and 0xf722f7f6afffe8e0dda7b4a97b2c64bb6408efe5. According to on-chain analyst Juiceberg, approximately 2.8 billion ONE had been moved to centralized exchange deposit addresses, with approximately 115 million ONE remaining in on-chain wallets at the time of analysis. The totalSupply endpoint on Harmony's network allegedly masked the new token issuance in the immediate aftermath, which independent analysts described as a supply masking condition that delayed detection and freeze response. Harmony has not released an official on-chain post-mortem or transaction hash documentation as of this report.","heading":"On-Chain Evidence and Attacker Wallet Addresses","severity":"critical","sources":[{"credibility":1,"name":"Harmony's ONE falls 40% after attacker allegedly mints 4 billion tokens — CoinDesk","type":"news_article","url":"https://www.coindesk.com/markets/2026/08/12/harmony-s-one-falls-26-after-attacker-allegedly-mints-4-billion-tokens"},{"credibility":2,"name":"Harmony Suffers Critical Exploit As 4B ONE Are Minted Without Authorization — Metaverse Post","type":"news_article","url":"https://mpost.io/harmony-suffers-critical-exploit-as-4b-one-are-minted-without-authorization-zachxbt-boycotts-recovery-efforts/"},{"credibility":2,"name":"Harmony's ONE sinks 37% after attacker mints 4 billion tokens — Decrypt","type":"news_article","url":"https://decrypt.co/375390/harmonys-one-sinks-37-after-attacker-mints-4-billion-tokens"}]},{"content":"Several critical facts remain unconfirmed as of August 12, 2026. Harmony has not officially confirmed the total quantity of tokens minted or disclosed the technical root cause of the vulnerability. The exchange freeze status — including which exchanges complied, which amounts were frozen, and whether any illicit ONE was liquidated before freeze orders reached exchanges — has not been publicly reported. The rollback decision remains pending; a full rollback would raise significant questions about the finality of legitimate transactions conducted after the exploit. No regulatory filing or law enforcement referral has been publicly announced. The status of any user funds affected by the bridge pause has not been disclosed. Independent security researchers have not yet published a verified post-mortem.","heading":"Unresolved Questions and Ongoing Risks","severity":"high","sources":[{"credibility":2,"name":"Harmony confirms exploit involving unauthorized minting of 4 billion ONE tokens — The Block","type":"news_article","url":"https://www.theblock.co/news/defi/2026-08-12-harmony-confirms-exploit-one-token-411527"},{"credibility":2,"name":"Harmony weighs a full blockchain rollback — CryptoSlate","type":"news_article","url":"https://cryptoslate.com/harmony-weighs-a-full-blockchain-rollback-after-unauthorized-minting-floods-exchanges-with-billions-in-one/"}]}],"sources_used":[{"credibility":2,"name":"Harmony confirms exploit involving unauthorized minting of 4 billion ONE tokens — The Block","type":"news_article","url":"https://www.theblock.co/news/defi/2026-08-12-harmony-confirms-exploit-one-token-411527"},{"credibility":2,"name":"Harmony weighs a full blockchain rollback after unauthorized minting floods exchanges with billions in ONE — CryptoSlate","type":"news_article","url":"https://cryptoslate.com/harmony-weighs-a-full-blockchain-rollback-after-unauthorized-minting-floods-exchanges-with-billions-in-one/"},{"credibility":1,"name":"Harmony's ONE falls 40% after attacker allegedly mints 4 billion tokens — CoinDesk","type":"news_article","url":"https://www.coindesk.com/markets/2026/08/12/harmony-s-one-falls-26-after-attacker-allegedly-mints-4-billion-tokens"},{"credibility":2,"name":"Harmony's ONE sinks 37% after attacker mints 4 billion tokens — Decrypt","type":"news_article","url":"https://decrypt.co/375390/harmonys-one-sinks-37-after-attacker-mints-4-billion-tokens"},{"credibility":2,"name":"Harmony Suffers Critical Exploit As 4B ONE Are Minted Without Authorization, ZachXBT Boycotts Recovery Efforts — Metaverse Post","type":"news_article","url":"https://mpost.io/harmony-suffers-critical-exploit-as-4b-one-are-minted-without-authorization-zachxbt-boycotts-recovery-efforts/"},{"credibility":2,"name":"Harmony Weighs Rollback After Claims of 4B ONE Exploit — CoinTelegraph","type":"news_article","url":"https://cointelegraph.com/news/armony-rollback-alleged-one-token-mint"},{"credibility":2,"name":"Harmony's ONE Plunges 30% After Attacker Mints 4 Billion Tokens — Bitcoin.com News","type":"news_article","url":"https://news.bitcoin.com/security/harmonys-one-plunges-30-after-attacker-mints-4-billion-tokens/"},{"credibility":3,"name":"Harmony ONE Plunges 40% After Reported 4B Token Mint Exploit — CryptoAdventure","type":"news_article","url":"https://cryptoadventure.com/harmony-one-plunges-40-after-reported-4b-token-mint-exploit/"},{"credibility":2,"name":"Harmony Protocol Hack: 4 Billion ONE Tokens Minted, Price Crashes 30% — Coinpedia","type":"news_article","url":"https://coinpedia.org/news/harmony-protocol-hack-4-billion-one-tokens-minted-price-crashes-30/"},{"credibility":1,"name":"Release Mainnet Release 2026.1.1 — harmony-one/harmony GitHub","type":"official","url":"https://github.com/harmony-one/harmony/releases/tag/v2026.1.1"},{"credibility":2,"name":"The Harmony Horizon Bridge Hack — Elliptic","type":"research","url":"https://www.elliptic.co/resources/harmony-horizon-bridge-hack"},{"credibility":1,"name":"FBI Confirms Lazarus Group Cyber Actors Responsible for Harmony's Horizon Bridge Currency Theft — FBI","type":"regulatory","url":"https://www.fbi.gov/news/press-releases/fbi-confirms-lazarus-group-cyber-actors-responsible-for-harmonys-horizon-bridge-currency-theft"},{"credibility":2,"name":"FBI confirms North Korea's Lazarus Group as hackers behind $100 million Harmony Horizon Bridge theft — Elliptic blog","type":"research","url":"https://www.elliptic.co/blog/analysis/fbi-confirms-north-korea-s-lazarus-group-as-hackers-behind-100-million-harmony-horizon-bridge-theft"},{"credibility":2,"name":"Harmony Token Falls to Record Low After Exploit Mints 4 Billion ONE — BeInCrypto","type":"news_article","url":"https://beincrypto.com/harmony-one-record-low-exploit-mint/"},{"credibility":2,"name":"Harmony Protocol Faces Suspected 4B ONE Mint as Team Explores Network Rollback — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/08/12/harmony-faces-suspected-4b-one-mint-as-team-explores-network-rollback/"},{"credibility":2,"name":"Harmony's ONE sinks 40% after apparent 4B-token mint — Cryptopolitan","type":"news_article","url":"https://www.cryptopolitan.com/harmony-one-sinks-40-apparent-4b-token-mint/"}],"summary":"On August 12, 2026, Harmony Protocol confirmed an exploit in which approximately 4 billion ONE tokens were minted without authorization through a flaw in cross-shard receipt verification, representing roughly 26% of the token's prior circulating supply. An estimated 2.8 billion of the minted tokens (approximately 97% of the illicit supply) were transferred to centralized exchanges before Harmony could coordinate a freeze response; the token price fell between 30% and 40% to a record low of approximately $0.0005735. Harmony released emergency validator patch v2026.1.1 and paused its Horizon bridge while evaluating a potential blockchain rollback, but the root cause and confirmed token totals had not been officially disclosed as of the date of this report.","timeline":[{"date":"2022-06-24","event":"Harmony Horizon Bridge exploited for approximately $100 million; attackers compromised two of five multi-sig private keys.","source":"Elliptic / FBI","source_url":"https://www.elliptic.co/resources/harmony-horizon-bridge-hack"},{"date":"2023-01-01","event":"FBI formally attributes the 2022 Horizon Bridge hack to North Korea's Lazarus Group (APT38).","source":"FBI Press Release","source_url":"https://www.fbi.gov/news/press-releases/fbi-confirms-lazarus-group-cyber-actors-responsible-for-harmonys-horizon-bridge-currency-theft"},{"date":"2023-12-01","event":"Staking-logic bug improperly mints 146.28 million ONE tokens — approximately 27 times smaller than the 2026 event.","source":"Bitcoin.com News / Metaverse Post","source_url":"https://news.bitcoin.com/security/harmonys-one-plunges-30-after-attacker-mints-4-billion-tokens/"},{"date":"2026-08-12","event":"On-chain analyst Juiceberg flags anomalous mint of approximately 4 billion ONE tokens via empty blocks.","source":"CoinDesk / Decrypt","source_url":"https://www.coindesk.com/markets/2026/08/12/harmony-s-one-falls-26-after-attacker-allegedly-mints-4-billion-tokens"},{"date":"2026-08-12","event":"Harmony Protocol confirms the exploit and announces it is working on a patch and evaluating rollback options.","source":"The Block","source_url":"https://www.theblock.co/news/defi/2026-08-12-harmony-confirms-exploit-one-token-411527"},{"date":"2026-08-12","event":"Approximately 2.8 billion illicitly minted ONE tokens are transferred to centralized exchange deposit addresses (~97% of minted supply).","source":"Decrypt / Metaverse Post","source_url":"https://decrypt.co/375390/harmonys-one-sinks-37-after-attacker-mints-4-billion-tokens"},{"date":"2026-08-12","event":"Harmony pauses bridge.harmony.one and releases emergency validator patch v2026.1.1 to close cross-shard receipt vulnerabilities.","source":"CryptoSlate / GitHub","source_url":"https://github.com/harmony-one/harmony/releases/tag/v2026.1.1"},{"date":"2026-08-12","event":"Harmony publishes four attacker wallet addresses and requests exchanges freeze associated funds.","source":"CoinDesk / Metaverse Post","source_url":"https://www.coindesk.com/markets/2026/08/12/harmony-s-one-falls-26-after-attacker-allegedly-mints-4-billion-tokens"},{"date":"2026-08-12","event":"ONE token falls to a record low of approximately $0.0005735, a decline of 30-40% from pre-exploit price.","source":"BeInCrypto / Decrypt","source_url":"https://beincrypto.com/harmony-one-record-low-exploit-mint/"},{"date":"2026-08-12","event":"On-chain investigator ZachXBT publicly refuses to assist with recovery, citing Harmony's prior mistreatment of researchers during the 2022 Horizon Bridge hack.","source":"Metaverse Post","source_url":"https://mpost.io/harmony-suffers-critical-exploit-as-4b-one-are-minted-without-authorization-zachxbt-boycotts-recovery-efforts/"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision 62dd93c0-55a5-48bb-9a3d-3b4dd53f774c
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.