Key Takeaways
- A hacker exploited Harmony Protocol to fraudulently issue 4 billion unauthorized ONE tokens.
- The sell-off wiped 26% of ONE’s market cap while investigator ZachXBT declined to assist.
- Harmony asked exchanges to freeze 4 hacker wallets while evaluating a full network rollback.
Token Collapses After 4-Billion Token Minting Exploit
Harmony Protocol’s native token, ONE, plunged more than 30% Wednesday to reach an all-time low following an exploit that enabled an attacker to mint more than 4 billion tokens—representing roughly 26% of the network’s total supply.
According to onchain analytics shared by crypto investigator Juiceberg, the perpetrator moved approximately 97% of the fraudulently minted tokens directly to cryptocurrency exchanges, leaving roughly 115 million tokens sitting in the original minting addresses.
While the exact amount of tokens liquidated was unclear, the sudden collapse in ONE’s market capitalization—shrinking from nearly $16 million down to $11.7 million—indicates that a significant portion of the illicit tokens were successfully cashed out.
In the wake of the breach, the Harmony team issued a series of public statements confirming the exploit and outlining emergency mitigation steps. First, the team requested that major crypto exchanges immediately freeze funds linked to four specific primary attacker wallet addresses.
In subsequent updates, the protocol said it had paused operations on its main bridge interface and disclosed that it had released an urgent core code patch, instructing all network validators to upgrade immediately to halt any further unauthorized minting capabilities.
“All validators, please upgrade. This patch prevents any further minting. We’ll follow up with another update to address the already minted tokens,” the Harmony core development team stated in an announcement.
The team confirmed it is evaluating additional measures, including a potential network rollback, to neutralize the economic impact of the fraudulently issued supply.
This latest incident marks another blow to a project that was once a multibillion-dollar Layer-1 ecosystem. In early 2022, ONE achieved an all-time high of $0.379 before the network suffered a $100 million breach of its Horizon Bridge. In that attack, North Korea’s state-sponsored Lazarus Group allegedly exploited compromised private keys hosting hot wallets tasked with listening for and processing cross-chain bridging transactions.
By the time of the first attack, ONE had already fallen to roughly 2 cents. Following a multiyear structural downtrend, this latest validator-level minting vulnerability has pushed ONE down nearly 97% from its peak, leaving the community questioning how critical security vulnerabilities continue to evade protocol audits and core infrastructure controls.
Compounding Harmony’s troubles is a distinct lack of support from high-profile Web3 security researcher ZachXBT. The researcher cited the protocol’s history of failing to reward white-hat contributors and investigators during the 2022 attack as the reason he is unwilling to assist.
Replying directly to Harmony’s public appeal to exchanges, ZachXBT stated: “I will not be tracking this incident and think no one should assist them for free. Harmony took advantage of people who assisted during the $100M Harmony Bridge exploit by DPRK in 2022 and rewarded $0 for significant freezes which led to LE [Law Enforcement] seizures, and simply said ‘good job’.”









