Harmony Deleted 109,000 Real Transactions to Undo One Attacker's Work
An attacker forged three trillion ONE tokens through a cross-shard flaw, moved 2.385 trillion of them in a hundred seconds, and Harmony's own supply endpoint reported nothing was wrong. The only fix left was deleting a day of everybody else's history.

The headline number was four billion. That was wrong, and the real number is hard to hold in your head.
At 23:25:40 UTC on August 12, 2026, an attacker began minting ONE tokens out of nothing on the Harmony mainnet. The first activity hit Shard 0 at block 92,730,036. On-chain analysts reported roughly 4 billion forged tokens, about 26% of the 15 billion in circulation, and that figure is what most coverage ran with. Harmony's own incident reconstruction put the full forged cross-shard issuance at approximately 3.01 trillion ONE across six transactions into four attacker wallets. In one sequence lasting just over 100 seconds, a single wallet executed hundreds of transfers and successfully moved about 2.385 trillion of them.
The flaw was in cross-shard receipt handling. Harmony splits its network into shards that pass value between each other using receipts, and the marker that records whether a receipt has already been spent was not being derived from the authenticated ShardID and block number in the signed source header. Forge the right receipt and the same value could be claimed repeatedly on the other side. A related quorum weakness let signer masks pass validation when they were empty or nil.
The detail that turned a bad night into a farce was the accounting. Harmony's totalSupply endpoint did not reflect the forged tokens at all. Price trackers went on reporting circulating supply at roughly 14.87 billion while trillions moved on-chain. Anyone checking the official numbers to work out whether their holdings had just been diluted would have been told everything was normal.
The attacker did not wait around. Roughly 97% of the forged supply went straight to exchanges, leaving only about 115 million ONE sitting in the original minting addresses. Harmony named four wallets and asked every exchange to freeze anything traceable to them. ONE fell more than 30% to an all-time low, then bounced.
Harmony patched fast, which is to its credit. Mainnet release v2026.1.1 shipped at 06:30 UTC on August 12, fixing the receipt marker to derive from the authenticated header and hardening the quorum check to count only validators enabled in the signer bitmap. Once enough validators upgraded, no further forging was possible. The bridge was paused as a precaution.
That left the question of the tokens already loose in the wild, and here Harmony ran out of good options. The forged ONE had already scattered through decentralized exchanges, liquidity pools, and bridges, mixing with legitimate holdings across a great many addresses. Freezing individual balances risked hitting innocent users or leaving inconsistencies that could enable further attacks. Harmony considered the alternatives and rejected them.
On August 17 it announced a full rollback. Shard 0 reverts to block 92,730,034 and Shard 1 to block 94,978,278, both timestamped 23:25:37 UTC on August 11, three seconds before the first forged mint. Client version v2026.1.2 is configured to reject the abnormal block hashes so validators cannot accidentally accept the poisoned history after restart.
Everything after those checkpoints goes. Harmony's own statement is explicit that all blocks after the checkpoint are removed, including regular transactions entirely unrelated to the attack. That comes to more than 109,000 transactions belonging to people who did nothing but use the network on the wrong day.
There is a wrinkle that says something about how carefully this was done. Block 92,730,035, the one immediately before the first forged mint, contained no transactions, no receipts and no gas usage, and its state was identical to the block before it. Harmony chose to revert one block further back anyway, to 92,730,034, purely as a safety buffer, because the recovery databases and validator procedures had already been prepared and reviewed around that height and changing the target late risked validators working from different recovery points.
Nobody has been identified. Harmony says it is working with exchanges, law enforcement and blockchain analytics firms. It has been in this position before, and that is why one of the most effective investigators in the industry publicly refused to help.
ZachXBT declined to track the incident, referring to freeloading investigators and assistants, and pointed at the $100 million Horizon Bridge exploit in 2022, which the FBI attributed to North Korea's Lazarus Group. His stated reason was that Harmony had failed to reward the people who helped with major freezes after that hack. Harmony had raised a $10 million bounty at the time; funds from Horizon were still moving months later, and it took Binance and Huobi freezing accounts to recover 124 BTC in January 2023.
This is the third serious security event on the same chain. The bridge hack in 2022. A staking bug in December 2023 that improperly minted 146.28 million ONE across 74 delegator addresses, contained by an emergency hard fork. And now a forgery three orders of magnitude larger, resolved by deleting a day of the ledger.
The Aftermath
The mint vulnerability is fixed and the rollback was approved, with validators loading reviewed replacement databases at the checkpoint heights and resuming from blocks 92,730,035 and 94,978,279. Harmony says exploit reconstruction, wallet identification and exchange coordination all remain in progress. No attacker has been identified and nothing has been recovered. Users whose legitimate transactions fall after the checkpoint lose them; Harmony has said it is working with exchanges and bridges to assess the impact and determine how affected parties can be handled, without committing to compensation. ZachXBT's refusal stands as a reminder that goodwill from independent investigators is a resource projects can spend.
COMMENTS