Harmony, the layer-1 blockchain network, has released an emergency validator patch that it says prevents further unauthorized minting of ONE, its native token. The project said it will address tokens already created in a later update, leaving their number and ultimate treatment unresolved.
Harmony told validators to install v2026.1.1 on Aug. 12. The notice confirms that minting occurred but does not disclose the amount.
Onchain researcher Juiceberg estimated that roughly 4 billion ONE, equal to about 26% of the supply figure used in the post, had been minted without authorization. Juiceberg also estimated that 2.8 billion ONE had reached exchanges. Harmony has not independently confirmed those figures.
How the patch blocks more minting
Harmony’s published code changes address two weaknesses in cross-shard receipts, which carry transaction results between parts of the network.
One flaw allowed an empty signer record and a mathematically neutral aggregate signature to pass a quorum check. The verifier counted the full committee instead of the validators represented in the signer record, allowing a receipt to be accepted without the required approvals.
The second flaw affected how the network recorded that a receipt had already been spent. Some proof fields were not bound to the signed block header, so changing those fields could make a previously processed receipt appear new. The destination could then be credited again without a corresponding debit from the source.
The signed v2026.1.1 release changes the quorum calculation and ties the spent marker to authenticated header data, closing both paths described in the patch.
Harmony also paused bridge.harmony.one during the response, although its notice did not identify the bridge as the exploited component. The project published four implicated wallet addresses and asked exchanges to block and freeze traceable funds, without naming the venues or disclosing how much had been frozen.
Harmony’s initial response said rollback options were under consideration. The project has not announced that a rollback will occur or specified the point from which transactions could be reversed.
The incident differs technically from the June 2022 Horizon bridge exploit, which involved compromised multisig control and about $100 million in stolen assets. The current patch instead addresses receipt verification and replay at the protocol level.
Harmony says further minting is now blocked. The remaining risk centers on the size and location of the ONE already created, how much exchanges can freeze, and whether the network will attempt a rollback to remove the excess supply.
Featured,Hacks,ONEONE#Harmony #weighs #full #blockchain #rollback #unauthorized #minting #floods #exchanges #billions1786533007



