Harmony to roll back chain after attacker forges 3.01T ONE tokens
Security & Exploits ·
Harmony plans to reset its blockchain to a pre-attack state after an exploiter minted 3.01 trillion ONE tokens, discarding every block and transaction that followed the forged mint.
Harmony's response, first detailed by The Block, centers on a full rollback rather than a patch layered on top of the compromised chain state. All blocks and transactions produced after the attacker's mint transaction will be discarded, effectively rewinding the network to the moment before the forged 3.01T ONE entered circulation. The approach treats the exploit as a break in the chain's legitimate history rather than an isolated bug to be fixed going forward.
The scale of the forged supply, 3.01 trillion ONE tokens, is what appears to have driven the decision to roll back rather than remediate in place. Minting on that order threatens to distort balances, liquidity, and any transactions that touched the tainted supply after the attack, making a targeted fix difficult without also erasing the contamination's downstream effects across the chain.
Rollbacks of this kind sit within a broader category of exploits that abuse vulnerabilities in code, design, or user behavior to subvert systems, as outlined in explainers on the mechanics of crypto exploits more generally, including how attackers turn latent weaknesses into actual attacks with financial consequences, a distinction laid out in Leviathan's exploit explainer. Multiple accounts of the Harmony incident describe the same core fact pattern: an exploiter forged roughly 3 trillion ONE tokens, prompting the chain to plan a reset to before the attack occurred, with four distinct sources corroborating the rollback plan and the token figure.
What remains unclear from available reporting is how the rollback will be implemented at the validator and node level, whether affected users or exchanges will need to take specific action to align with the reset chain state, and what happens to any legitimate transactions or activity that occurred in the window between the attack and the rollback announcement. Also unresolved is whether the vulnerability that allowed the forged mint has been identified and closed, or whether further exploitation remains possible before the rollback takes effect.