Harmony Protocol has suffered a massive exploit that saw an attacker mint 4 billion of Harmony’s ONE tokens, which is 26% of the token’s supply.
The incident was flagged on Wednesday morning by a security researcher on X, who said about 97% of the minted tokens had already been moved to exchanges.
The attacker has roughly 115M ONE left to sell onchain — about 2.9% of the ~4B they minted. The
— Juiceberg (@the_juice_berg) August 12, 2026
overwhelming majority (~97%) is already on exchanges and has either been sold or is sitting in deposit wallets ready to sell
Harmony confirmed the attack, saying it is working with appropriate exchanges to stop and freeze the funds.
The team has already suspended the Harmony Bridge and told validators to upgrade to a patch that prevents any further minting.
Harmony said it will follow up with another update to address the unauthorizedly minted token. Part of the measures the team is considering includes a rollback option.
All validators, please upgrade. This patch prevents any further minting.
— Harmony 💙 (@harmonyprotocol) August 12, 2026
We'll follow up with another update to address the already minted tokens.https://t.co/FpjmbuBNTG https://t.co/JcmP22Nkat
The price of ONE token fell over 38% following the news.
“No one should assist them for free,” says ZachXBT
On-chain sleuth ZachXBT has said he will not be tracking the incident after Harmony called on all exchanges to block and freeze funds traced to four of the attacker’s wallet addresses.
“Harmony took advantage of people who assisted during the $100M Harmony Bridge exploit by DPRK in 2022 and rewarded $0 for significant freezes which lead to LE seizures and simply said ‘good job’,” ZachXBT said.
I will not be tracking this incident and think no one should assist them for free.
— ZachXBT (@zachxbt) August 12, 2026
Harmony took advantage of people who assisted during the $100M Harmony Bridge exploit by DPRK in 2022 and rewarded $0 for significant freezes which lead to LE seizures and simply said “good job”
Harmony Horizon Bridge was hacked in June 2022, with nearly $100 million in crypto stolen. The Federal Bureau of Investigation (FBI) confirmed North Korea’s Lazarus Group was responsible for the exploit.