Harmony is evaluating a potential rollback of its blockchain after reports of a suspected exploit allegedly allowed an attacker to create billions of unauthorized ONE tokens, triggering a sharp sell-off and prompting the network to coordinate with cryptocurrency exchanges.
The layer-1 blockchain said Tuesday that it was working with exchanges to identify and freeze potentially affected funds while preparing a software patch to address the suspected vulnerability. Harmony also said it was assessing whether a rollback of the blockchain would be necessary.
The project has not independently confirmed the exploit’s exact mechanism, the number of tokens allegedly created or how much of the newly issued supply reached exchanges.
Billions of ONE Tokens Allegedly Created
Harmony’s response followed claims from an X account known as “Juiceberg,” which alleged that an attacker had exploited the network by manipulating empty blocks to generate unauthorized ONE tokens.
According to the claims, nearly 4 billion ONE may have been created, representing roughly 26% of the token’s total supply.
The account further alleged that approximately 2.8 billion ONE tokens were rapidly transferred toward cryptocurrency exchanges, potentially creating significant selling pressure.
If accurate, such an increase in circulating supply would represent an extraordinary expansion of the token’s available supply and could severely affect its market value.
Juiceberg estimated that approximately 115 million ONE remained onchain under the attacker’s control, representing around 2.9% of the allegedly minted amount. The remaining tokens were reportedly either sold or transferred into exchange deposit wallets.
These figures have not been independently verified, and Harmony has not confirmed the full scale of the alleged incident.
Harmony Moves to Contain Potential Damage
Harmony said its immediate priority is to prevent potentially unauthorized funds from moving further through the cryptocurrency ecosystem.
The network is working with centralized exchanges to identify and freeze suspicious funds while simultaneously developing a patch intended to address the underlying issue.
The project is also examining whether a blockchain rollback could restore the network to a state before the suspected exploit occurred.
A rollback would be a significant intervention because it could effectively reverse transactions recorded after a particular point in the blockchain’s history. Such a decision could involve complex questions surrounding legitimate transactions, exchange deposits and withdrawals, user balances and the finality of transactions.
Harmony has not announced whether a rollback will actually take place.
ONE Price Drops Sharply
The alleged supply inflation was followed by substantial volatility in ONE.
Market data showed ONE falling approximately 34% over a 24-hour period at the time of reporting.
A sudden increase in token supply can create severe pressure on an asset when newly created tokens are rapidly sold into the market. If billions of unauthorized tokens were indeed transferred to exchanges, traders could face uncertainty over how much additional supply might enter circulation.
However, the precise relationship between the reported exploit and the market decline remains subject to verification because Harmony has not yet confirmed the amount of unauthorized issuance.
Investigation Remains Ongoing
The most important unanswered question is how the suspected attacker was allegedly able to create the additional ONE tokens.
Harmony has not publicly confirmed the vulnerability or explained whether the reported token creation resulted from a consensus failure, a smart-contract issue, validator manipulation or another technical weakness.
The blockchain’s decision to prepare a patch suggests that developers are investigating a technical issue that could require changes to the network’s underlying software.
Until Harmony completes its investigation, the figures circulating online should be treated as preliminary claims rather than confirmed measurements of the exploit.
The network’s cooperation with exchanges could nevertheless become critical if unauthorized tokens have already reached trading platforms. Freezing suspected funds may limit the attacker’s ability to liquidate additional tokens while developers determine the appropriate response.
Incident Recalls Harmony’s 2022 Bridge Hack
The latest incident also revives memories of Harmony’s much larger security breach in 2022.
In June that year, attackers exploited the Horizon Bridge, a cross-chain bridge operated by Harmony, resulting in the theft of approximately $100 million worth of cryptocurrency.
The FBI subsequently attributed the Horizon Bridge attack to North Korea’s Lazarus Group.
The latest suspected exploit appears to involve a fundamentally different issue, as the current claims concern unauthorized token issuance rather than the theft of assets from the Horizon Bridge. Nevertheless, another major security incident could raise renewed questions about the resilience and security of Harmony’s infrastructure.
What Happens Next for Harmony and ONE
Harmony’s next steps will likely depend on what its technical investigation reveals.
The project is currently pursuing several measures simultaneously: coordinating with exchanges to freeze potentially affected funds, developing a patch and evaluating whether a rollback is technically and economically feasible.
A decision to roll back the chain would carry significant consequences for users and market participants, particularly if legitimate transactions must also be reversed.
For ONE holders, the key developments to watch are an official explanation of the suspected vulnerability, confirmation of the amount of unauthorized tokens created, the status of funds sent to exchanges and any decision regarding a blockchain rollback.
Until those details are confirmed, the reported billions of newly created ONE tokens remain allegations rather than independently verified figures. The scale of the market reaction, however, shows how quickly confidence can deteriorate when a blockchain’s token supply and underlying security come into question.

