Harmony protocol exploited for 2.385 trillion ONE tokens via cross-shard validation flaw, forcing full network rollback and bridge pause.
Security & Exploits ·
Harmony Protocol disclosed a security incident in which cross-shard receipt and quorum validation flaws enabled an attacker to illegally generate 2.385 trillion ONE tokens. Within 106 seconds, a single wallet submitted 534 fraudulent transfers of 5 billion ONE each; 477 succeeded, causing ONE's price to decline more than 30%. The protocol responded by rolling back both Shard 0 and Shard 1 to their August 11 state, deploying emergency patch Mainnet v2026.1.1, and halting cross-chain bridge operations.
The network invalidated 141,628 blocks generated during the attack window, including 109,126 standard transactions and 315 staking transactions. Harmony stated that over 99.9% of the counterfeit token supply has been located on-chain, and requested exchanges to restrict addresses involved in the fraudulent transfers.
The incident exposes persistent risks in cross-shard consensus mechanisms. Details on how the vulnerability will be prevented in future versions, or whether slashing of compromised validators will occur, remain unclear.