Harmony’s August 12, 2026 exploit initially produced about 4 billion unauthorized ONE, while later on chain reconciliation pointed to roughly 3.01 trillion forged ONE. Harmony is replacing shard databases at August 11 checkpoints—blocks 92,730,034 and 94,978,278—to remove the forged state, but the rollback also disc...
Research answer

Create a landscape editorial hero image for this Studio Global article: What happened in Harmony’s August 12 forged-token exploit, how did the attacker mint and distribute approximately 4 billion unauthorized ONE. Article summary: Harmony’s August 12, 2026 incident was a cross-shard receipt-forgery exploit: attackers induced Shard 0 to accept forged cross-shard transactions and mint roughly 4 billion unauthorized ONE initially, although subsequent. Topic tags: general, general web, user generated. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fa
Harmony’s August 12, 2026 incident was not simply a wallet theft. It was a supply-integrity failure: a flaw in Harmony’s cross-shard receipt verification allowed valid-looking receipts to be processed more than once, enabling unauthorized ONE issuance on Shard 0. Harmony patched the vulnerability, paused relevant services, and then opted for one of the most disruptive recovery measures available to a live blockchain—a rollback to a known pre-attack state.
The first incident estimate was approximately 4 billion unauthorized ONE, created around 05:25 UTC on August 12. Harmony said the activity involved forged cross-shard transactions, and it deployed emergency release v2026.1.1 on the same day.
Subsequent blockchain analysis produced a much larger figure. One reconstruction identified approximately 3.01 trillion forged ONE across six forged cross-shard transactions and four attacker wallets, although the investigation was still reconciling the initial and later measurements. That is why reporting alternates between “4 billion” and “trillions”: the former was the early confirmed issuance figure, while the latter reflects a broader reconstruction of forged issuance and movement.
Reports also describe rapid distribution from an attacker-controlled wallet. The reported transfer totals differ across accounts: one report cites 2.385 trillion ONE moved through 477 successful transfers, while another describes 534 transfers in 106 seconds. The discrepancy is a reason to avoid presenting any single transfer count as fully settled without a definitive incident ledger.
Harmony considered narrower responses, including targeted burns, wallet blacklists, selective transaction replay, token migration, and direct database intervention. It instead selected fixed recovery points for both active shards.
The core problem was contamination. Once forged ONE had moved through wallets, exchanges, pools, contracts, and other transactions, a targeted fix would need to identify every affected balance and state transition correctly. Harmony said a targeted repair could also affect unrelated funds. A blacklist might block addresses without actually removing every forged token, while selective replay could produce mismatches in balances, contract state, or transaction nonces.
A fixed checkpoint avoids making thousands of individual judgments about which transactions should survive. Validators can load replacement databases from the same agreed state and resume from the next block heights. That gives the recovery a deterministic starting point, even though it sacrifices legitimate activity after the checkpoint.
Harmony plans to retain:
Validators are expected to resume block production from blocks 92,730,035 and 94,978,279 using replacement databases. Client version v2026.1.2 rejects the identified problematic block hashes.
The cost is that all blocks after those checkpoints are discarded, including transactions that were not part of the attack. Reports put the affected volume at more than 109,000 regular transactions, including 109,126 ordinary transactions and 315 staking transactions in the detailed breakdown.
For users, that means the rollback is not equivalent to freezing a few attacker wallets. Legitimate transfers, swaps, staking actions, and other post-checkpoint activity may need to be recreated or otherwise addressed after the network restarts. The supplied evidence does not establish that most of the affected transactions were automated DEX-bot activity, so that characterization should not be treated as confirmed.
The available reports indicate that forged ONE spread rapidly through a series of transfers rather than remaining in a single minting address. One account says a wallet moved 2.385 trillion ONE through hundreds of transfers in seconds, while Harmony provided exchanges and LayerZero with a list of incident wallets.
Other reporting says exchanges were asked to block or freeze funds traceable to the published wallet addresses. Those measures can limit off-chain liquidation and cross-chain movement, but they do not by themselves restore the canonical on-chain state. That distinction helps explain why Harmony treated rollback as a broader containment measure rather than relying only on coordination with intermediaries.
The incident clearly created a serious supply-integrity and liquidity problem. However, the supplied evidence does not provide a sufficiently reliable, independently corroborated price series or market-cap calculation for stating exactly how far ONE fell or how much capitalization it lost. A report claims a sharp price decline, but that single account is not enough to support a precise market-impact figure.
The safer conclusion is that unauthorized issuance undermined confidence in the token’s supply and forced exchanges, bridges, validators, and users to treat settlement as uncertain while the investigation continued. The scale of the market reaction should be verified separately against time-stamped exchange and market-data records.
Harmony’s choice makes an important trade-off explicit: transaction finality is being subordinated to restoration of a known-good state. That may be more comprehensive than trying to burn or blacklist every forged balance, but it also confirms that “immutable” ledger history can become a governance decision when the alternative is leaving counterfeit assets embedded in protocol state.
The rollback can be compared with other blockchain reversals, but the supplied evidence does not document the technical details of Ravencoin’s response well enough to make a detailed comparison. It also confirms that Harmony previously dealt with the Horizon Bridge incident, including a proposal involving ONE-based reimbursement, but it does not establish that the new rollback formally changes Harmony’s long-term policy for future exploits.
The immediate lesson is narrower and more practical: when a cross-shard validation flaw allows forged assets to propagate, the recovery decision is not only about deleting tokens. It is about whether the network can reliably reconstruct every affected balance, contract state, and transaction dependency. Harmony judged that it could not do so safely enough and chose to reset both shards instead.
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
Harmony’s August 12, 2026 exploit initially produced about 4 billion unauthorized ONE, while later on chain reconciliation pointed to roughly 3.01 trillion forged ONE.
Harmony’s August 12, 2026 exploit initially produced about 4 billion unauthorized ONE, while later on chain reconciliation pointed to roughly 3.01 trillion forged ONE. Harmony is replacing shard databases at August 11 checkpoints—blocks 92,730,034 and 94,978,278—to remove the forged state, but the rollback also discards legitimate activity recorded afterward.
The decision favors a deterministic, auditable ledger reset over blacklists, targeted burns, or selective transaction replay, which Harmony said could affect unrelated funds or create inconsistent chain state.