Harmony Releases Emergency Patch to Halt Unauthorized Minting of ONE Token
Hızlı Bakış
Harmony blockchain network releases patch v2026.1.1 to prevent further unauthorized minting of its native ONE token, addressing protocol-level vulnerabilities; existing illicitly minted tokens' fate undecided.
Yapay zekâ özeti
Neden Önemli?
Harmony blockchain faced a security breach leading to unauthorized minting of its native ONE token.
Harmony, the layer-1 blockchain network, has released an emergency validator patch that it says prevents further unauthorized minting of ONE, its native token. The project said it will address tokens already created in a later update, leaving their number and ultimate treatment unresolved. Harmony told validators to install v2026.1.1 on Aug. 12. The notice confirms that minting occurred but does not disclose the amount. Onchain researcher Juiceberg estimated that roughly 4 billion ONE, equal to about 26% of the supply figure used in the post, had been minted without authorization. Juiceberg also estimated that 2.8 billion ONE had reached exchanges. Harmony has not independently confirmed those figures. How the patch blocks more minting Harmony's published code changes address two weaknesses in cross-shard receipts, which carry transaction results between parts of the network. One flaw allowed an empty signer record and a mathematically neutral aggregate signature to pass a quorum check. The verifier counted the full committee instead of the validators represented in the signer record, allowing a receipt to be accepted without the required approvals. The second flaw affected how the network recorded that a receipt had already been spent. Some proof fields were not bound to the signed block header, so changing those fields could make a previously processed receipt appear new. The destination could then be credited again without a corresponding debit from the source. The signed v2026.1.1 release changes the quorum calculation and ties the spent marker to authenticated header data, closing both paths described in the patch. Harmony also paused bridge.harmony.one during the response, although its notice did not identify the bridge as the exploited component. The project published four implicated wallet addresses and asked exchanges to block and freeze traceable funds, without naming the venues or disclosing how much had been frozen. Harmony's initial response said rollback options were under consideration. The project has not announced that a rollback will occur or specified the point from which transactions could be reversed. The incident differs technically from the June 2022 Horizon bridge exploit, which involved compromised multisig control and about $100 million in stolen assets. The current patch instead addresses receipt verification and replay at the protocol level. Harmony says further minting is now blocked. The remaining risk centers on the size and location of the ONE already created, how much exchanges can freeze, and whether the network will attempt a rollback to remove the excess supply.
Bundan Sonra Ne Olabilir?
Yapay zekâ öngörüsü — kesinlik taşımaz
Potential rollback of transactions to reverse illicit minting
Olası · Haftalar içinde
Açık Sorular
- Total amount of unauthorized ONE minted
- Outcome of potentially frozen funds






