This website uses cookies
We use cookies to personalise content and ads, to provide social media features and to analyse our traffic. We also share information about your use of our site with our social media, advertising and analytics partners who may combine it with other information that you’ve provided to them or that they’ve collected from your use of their services.
Consent Selection
Details
  • Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
  • Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
    • We do not use cookies of this type.

  • Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
    • We do not use cookies of this type.

  • Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.
    • We do not use cookies of this type.

  • Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    • __emg_sidPending
      Maximum Storage Duration: 1 dayType: HTTP Cookie
      __emg_vidPending
      Maximum Storage Duration: 1 yearType: HTTP Cookie
      nl-read-countPending
      Maximum Storage Duration: PersistentType: HTML Local Storage
Cookie declaration last updated on 8/12/26 by Cookiebot
[#IABV2_TITLE#]
[#IABV2_BODY_INTRO#]
[#IABV2_BODY_LEGITIMATE_INTEREST_INTRO#]
[#IABV2_BODY_PREFERENCE_INTRO#]
[#IABV2_BODY_PURPOSES_INTRO#]
[#IABV2_BODY_PURPOSES#]
[#IABV2_BODY_FEATURES_INTRO#]
[#IABV2_BODY_FEATURES#]
[#IABV2_BODY_PARTNERS_INTRO#]
[#IABV2_BODY_PARTNERS#]
About
Cookies are small text files that can be used by websites to make a user's experience more efficient.

The law states that we can store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies we need your permission.

This site uses different types of cookies. Some cookies are placed by third party services that appear on our pages.

You can at any time change or withdraw your consent from the Cookie Declaration on our website.

Learn more about who we are, how you can contact us and how we process personal data in our Privacy Policy.

Please state your consent ID and date when you contact us regarding your consent.
NewsLayer.com

Harmony's ONE Sinks 37% After Attacker Mints 4 Billion Tokens

작성자 Decrypt Agent게시 9시간 전 2 분 소요
Harmony's ONE Sinks 37% After Attacker Mints 4 Billion Tokens

The team is weighing a rollback, which would undo the attack along with every legitimate transaction made since.

In brief

  • Harmony confirmed an exploit after an analyst reported that an attacker minted about 4 billion ONE, roughly 26% of the supply.
  • Around 97% of those tokens have already reached exchanges, on-chain analyst Juiceberg said.
  • ONE was trading at about $0.00077, down 37% on the day, after Harmony shipped a patch to stop further minting.

Layer-1 blockchain Harmony has confirmed it was exploited after an attacker minted roughly 4 billion ONE tokens without authorisation, sending the token down 37% to about $0.00077, per CoinGecko data.

On-chain analyst Juiceberg flagged the mint early Wednesday, putting it at close to 4 billion tokens, or about 26% of the supply, and saying the tokens had been created through empty blocks. Around 2.8 billion were funnelled onto exchanges as the price fell.

In a follow-up tweet, the analyst said the attacker had roughly 115 million ONE left to sell on-chain, about 2.9% of the total minted. "The overwhelming majority (~97%) is already on exchanges," Juiceberg wrote, and had either been sold or was sitting in deposit wallets.

Harmony responded in a tweet that it was "working with our team and appropriate exchanges to stop and freeze the funds," adding that it was preparing a patch and weighing rollback options. In a second post it named four wallets, each listed in both Harmony and hex formats, and asked exchanges to block anything traced to them.

Just over two hours after that first statement it paused its bridge, then released a patch a minute later, telling validators to upgrade to a build it said prevents any further minting. Dealing with the tokens already created would take another update, it said. Five hours had passed since Juiceberg's first post.

The project has not disclosed the vulnerability, confirmed how many tokens were created, or said how much reached exchanges. One oddity Juiceberg noted is that Harmony's totalSupply endpoint did not reflect the new tokens, and price trackers still list circulating supply at about 14.87 billion.

Rolling back the chain

A rollback would return the network to a state before the exploit and continue from there, erasing what followed from the accepted history. That cuts both ways, since transactions made by ordinary users after the attack would go with it.

Harmony has been here before, with hackers draining about $100 million from its Horizon cross-chain bridge in June 2022, in an attack the FBI later attributed to North Korea's Lazarus Group.

The project's first proposal to the 2022 hack was to reimburse victims in ONE, which would have meant minting billions of new tokens on top of the circulating supply and hard-forking the chain to allow it. The plan drew enough criticism that the team replaced it with one funded from its treasury. Four years on, an attacker has minted a comparable amount without asking.

ONE now carries a market capitalisation of about $11.5 million, ranking it outside the top 1,000 tokens. It last traded near its October 2021 record of $0.38 more than four years ago, and is down more than 99% from that level.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.

Attribution

Originally reported by Decrypt

Get stories like this, daily.

Daily crypto + regulation intelligence, straight to your inbox. Free.

관련 기사