Harmony Protocol exploit mints 4B ONE – and sparks a public rift with ZachXBT
The latest major security incident in crypto has hit Harmony Protocol, after an attacker managed to mint roughly 4 billion ONE tokens out of thin air – around 26% of the asset’s total supply. The event immediately raised questions not only about the network’s security model, but also about how much support projects can expect from independent blockchain investigators when previous cooperation went unrewarded.
How the Harmony exploit unfolded
On-chain sleuths first flagged suspicious activity when previously empty blocks on Harmony began producing massive amounts of newly minted ONE. According to investigator Juiceberg, the attacker exploited a vulnerability that allowed them to generate tokens without corresponding economic backing, effectively inflating the supply at will.
From the approximately 4 billion fraudulently minted ONE, about 2.8 billion tokens were quickly funneled to centralized exchanges. These transfers appear to have been designed to liquidate as much of the illicit balance as possible before exchanges or the protocol could respond.
A further 115 million ONE remained on-chain and readily available for sale at the time of reporting. Although this is a relatively small fraction of the exploit – around 3% of the newly minted supply – it still represents a substantial amount of potential sell pressure if moved to markets.
Preliminary analysis suggests most of the minted tokens have either:
– Already been deposited to exchanges and sold
– Remained parked in exchange deposit wallets
– Sat idly in addresses tied to the attacker, pending further laundering
The attack came at a time when broader crypto security figures were already painting a worrying picture. In just the first 12 days of the month, exploits across the industry had driven more than 12.37 million dollars in losses, according to on-chain tracking data. Notably, this figure did not yet include the Harmony incident, meaning the real total is materially higher once the ONE exploit is accounted for.
Market impact: ONE price and derivatives
The sudden appearance of billions of unbacked tokens inevitably slammed market confidence. In the immediate aftermath of the exploit, ONE’s price plunged more than 54% as traders priced in both the dilution shock and fears of sustained forced selling from the attacker.
As the situation evolved and more details emerged, the drawdown moderated somewhat, with the decline narrowing to around 38% at press time. Even with this partial recovery, the move represented one of the sharpest single-event drops for the asset in recent history.
Derivatives data underscored just how aggressively traders positioned for downside. Open Interest across ONE-linked products climbed sharply during the sell-off, indicating a surge in short positions and leveraged bearish bets. This dynamic is typical for tokens caught in major security incidents: speculators race to front-run further selling by exploiters, as well as panic exits from spot holders.
Whether the market can stabilize will now depend heavily on how effectively Harmony and its partners can contain the fraudulent supply and restore trust in the chain’s minting mechanism.
Harmony’s response: patching, coordination, and a possible rollback
Harmony’s core team quickly acknowledged the exploit and began coordinating with exchanges and validators. Their response focused on three main tracks:
1. Emergency patch
The team issued a mandatory software update for validators designed to halt any further unauthorized minting of ONE. In a public call to action, they urged all validators to upgrade immediately, emphasizing that the patch was critical to preventing additional inflation attacks.
By the time of the latest update, 53% of validators had completed the upgrade, marking a majority but still leaving a significant portion of the network needing to comply to fully close the loophole.
2. Exchange collaboration and asset freezes
Recognizing that most of the fraudulent tokens had already hit centralized platforms, Harmony began working directly with exchanges to identify and freeze suspicious deposits. The team shared a list of four primary wallet addresses associated with the attacker and requested that partners block or quarantine related funds.
In addition, Harmony flagged exactly 10,288 suspect deposit transactions spread across 409 wallets. These addresses are believed to be the main landing points for the newly minted coins. By mapping this network of deposits, the team hopes to slow or prevent further cash-outs and, where possible, enable law enforcement seizures or coordinated freezes.
3. Rollback as the “most practical” option
Perhaps the most controversial element of Harmony’s response is the suggestion that a chain rollback may be the most viable path to fully neutralizing the exploit. Rolling back would involve re-organizing the chain to a state before the unauthorized minting occurred, essentially erasing the attacker’s activity from the canonical history.
Harmony has described this as the most practical solution under consideration, given the scale of the exploit and the difficulty of clawing back coins that are already circulating. However, such a move carries serious implications for network credibility, as it can be seen as undermining immutability and setting a precedent for intervention in times of crisis.
Why ZachXBT refused to help – and the ethics of unpaid investigations
Amid Harmony’s appeals for cooperation from ecosystem partners, a separate controversy erupted when well-known blockchain investigator ZachXBT publicly declined to assist in tracing the attacker’s funds unless compensated.
He argued that Harmony had previously failed to reward or even properly acknowledge significant unpaid efforts following the 2022 Harmony Bridge exploit, where roughly 100 million dollars was stolen in an attack linked to North Korea’s DPRK. According to his account, community investigators helped identify and freeze portions of those funds, which contributed to subsequent law enforcement actions – yet received “zero” in rewards for their work.
ZachXBT summarized his stance by urging others not to provide free assistance to Harmony this time around, citing:
– Prior exploitation of unpaid labor
– Lack of appropriate compensation or structured bounty programs
– A pattern of simply saying “good job” without tangible rewards for impactful contributions
His refusal triggered a divided reaction. Some observers backed his position, arguing that professional on-chain forensics is highly specialized work that should be remunerated, especially when it leads to the recovery or freezing of millions in assets. They see structured compensation as essential to building a sustainable ecosystem of independent security researchers.
Others pushed back, insisting that helping track stolen funds should be viewed as contributing to the health and safety of the broader crypto space, with public recognition often being the primary “reward.” One user noted having assisted with dozens of incidents and stated that recognition, rather than financial compensation, had been the norm.
This clash highlights a growing tension in crypto security: protocols increasingly rely on independent investigators and white-hat researchers to respond to crises, but many still lack clear frameworks for payment, bounties, or retroactive rewards when those efforts succeed.
The economic fallout of mint-based exploits
Exploits that directly mint new supply, rather than draining existing user funds, pose a particularly complex challenge for token economies. In Harmony’s case, the sudden creation of 4 billion ONE distorted the asset’s underlying tokenomics, introducing an artificial supply shock equivalent to more than a quarter of the total circulation.
Even if a significant portion of these tokens is eventually frozen or rolled back, the event raises deep questions:
– Can investors trust published circulating supply numbers after such an incident?
– How should token valuation models account for the risk of arbitrary inflation via contract or consensus bugs?
– What happens to market confidence when the line between “real” and “invalid” tokens is temporarily blurred?
When an attacker successfully sells a chunk of newly minted coins, they effectively extract value from existing holders: the proceeds realized by the exploiter are mirrored by a dilution of everyone else’s share of the network. That dynamic is why markets tend to react so violently to mint-based attacks, often more so than to isolated protocol hacks affecting a smaller subset of users.
Rollbacks vs. immutability: can Harmony repair trust?
If Harmony proceeds with a rollback, the decision will echo beyond this single incident. Rollbacks have always been a contentious tool: they can protect users and undo catastrophic bugs, but they also chip away at the principle that “code is law” and that blockchain history is immutable.
For Harmony, the calculus is particularly delicate:
– Pros of a rollback
– Removes or neutralizes illegitimate tokens from the ledger
– Can restore tokenomics closer to their pre-exploit state
– Limits the attacker’s ability to profit long-term
– Cons of a rollback
– Sets a precedent that the chain’s history can be rewritten under social or governance pressure
– May undermine future assurances given to developers and users building on the network
– Could trigger legal and regulatory questions regarding which version of the chain is “official”
If Harmony chooses not to roll back, it instead faces the long, technically complex process of tracking, freezing, and potentially burning fraudulent coins – all while markets remain uncertain about the final effective supply.
Either path demands clear, transparent communication with the community and detailed documentation of the reasoning behind any decision. How Harmony manages this will be critical in determining whether the network can regain credibility with both retail users and institutional players.
What this incident reveals about crypto security in 2026
The Harmony exploit underscores several broader themes in the current security landscape:
1. Layer 1s remain high-value targets
Core protocol vulnerabilities – especially those affecting consensus, minting, or validation logic – offer attackers enormous leverage. A single bug can translate into billions of tokens or hundreds of millions of dollars in value.
2. Monitoring and rapid response are still uneven
The fact that the exploit was first flagged by independent investigators rather than automated protocol-level defenses shows how much the industry still leans on ad hoc external vigilance. Many chains lack real-time anomaly detection for events like sudden spikes in minting or suspicious validator behavior.
3. Economic design must consider exploit scenarios
Tokenomics documents tend to outline issuance schedules and burn mechanisms under normal conditions, but rarely model worst-case events where supply suddenly balloons due to a bug. Investors are increasingly aware that “tail risks” like this can materialize and devastate valuations.
4. The social layer is inseparable from security
Harmony’s reliance on validator upgrades, exchange cooperation, and independent investigators highlights that technical fixes are only part of the equation. Trust, relationships, and reputation determine how quickly and effectively a network can respond when things go wrong.
Lessons for projects: prevent, incentivize, and prepare
For other protocols and projects, the Harmony incident offers several concrete takeaways:
– Invest in rigorous pre-launch and ongoing audits
Security audits cannot guarantee perfection, but multiple independent reviews, formal verification where possible, and continuous security testing dramatically reduce the surface area for catastrophic bugs.
– Design clear, public bounty and reward programs
If a project expects external investigators to help trace funds or identify vulnerabilities, it should publish explicit terms of compensation. That includes both proactive bug bounties and retroactive rewards when external efforts prevent or mitigate loss.
– Establish incident playbooks in advance
Having predefined processes for exploit response – including communication templates, on-chain monitoring frameworks, exchange contact channels, and governance procedures – can save critical hours during a live attack.
– Clarify rollback policies
Projects should be upfront about whether rollbacks are on the table under any circumstances, who can trigger them, and how they would be implemented. This helps set realistic expectations about immutability and governance from day one.
What ONE holders and users should watch next
For current and prospective ONE holders, several elements will be key in judging the protocol’s recovery:
– Final impact on circulating supply
How many of the 4 billion tokens end up frozen, rolled back, or otherwise neutralized – and how that is transparently tracked – will matter for any long-term valuation.
– Validator alignment
The speed with which the remaining validators apply the patch, and whether the network can present a unified front around any rollback or remediation decision, will influence perceptions of stability.
– Communication and accountability
Detailed post-mortems explaining the root cause of the bug, who was responsible for the vulnerable code, and what governance or development process changes will follow are essential to rebuilding trust.
– Security roadmap
Concrete commitments to enhance monitoring, audits, and recovery mechanisms will determine whether this event is seen as a one-off crisis or evidence of systemic weakness.
The bigger question: who pays for security in crypto?
Beyond Harmony itself, the clash with ZachXBT raises a systemic issue: as the sums at stake in crypto grow, relying on unpaid good will for critical security work becomes increasingly untenable. Professional-grade tracing, analysis, and negotiation with centralized platforms require time, skill, and often legal risk – all of which have real economic value.
If protocols want rapid, high-quality support when exploits hit, many will need to formalize relationships with investigators, set aside treasury funds for emergency response, and treat security ecosystems as first-class infrastructure, not an afterthought.
Until that shift fully occurs, tension between projects and independent researchers is likely to persist – especially in high-profile cases where past efforts went uncompensated.
For now, Harmony must manage a dual challenge: technically containing a massive unauthorized mint and socially convincing both markets and security experts that it has learned from its past and is willing to invest in a safer, more collaborative future.
