Harmony ONE Security Breach: 4 Billion Tokens Minted in Massive Supply Exploit
An attacker minted 4 billion unauthorized ONE tokens on Harmony's blockchain by exploiting a gap involving empty blocks, according to The Cryptonomist.

The breach was uncovered not by Harmony itself but by an independent X user called Juiceberg — and by the time Harmony confirmed the loss, roughly 97% of the stolen supply had already landed on exchanges. ONE's price crashed 34% in 24 hours, trading near $0.0008, leaving NFT traders who bridge, pay gas in ONE, or stake it into marketplaces holding a token whose supply integrity is now an open question.
How the mint actually worked
The attacker did not break into a wallet or phish a private key. The Cryptonomist reports they triggered an exploit that let them produce 4 billion ONE outside of any authorized emission schedule. Juiceberg's onchain tracking showed the totalSupply endpoint did not immediately reflect the unauthorized mint in real time — a detection delay that handed the attacker a window before the wider market caught on.
That delay is the part that matters for you. A healthy blockchain surfaces supply inflation instantly. When a node-level view and a public view of the same ledger disagree, any position denominated in that asset — floor bids, NFT payouts, treasury balances, bridge reserves — is operating on stale data. Even after the dust settles, the question is whether ONE's onchain plumbing can be trusted at all.
By Juiceberg's count, the attacker still has about 115 million ONE to sell — roughly 2.9% of the 4 billion minted. The remaining $3.2 million equivalent is upside still on the table for whoever can liquidate it.
Why NFT desks are not insulated
Harmony sits behind more than a few NFT collections, cross-chain bridges, and marketplace integrations that settle in ONE. A supply shock at the base layer doesn't just dilute holders — it poisons every payment rail and royalty payout priced in the asset. If you sell on a Harmony-hosted NFT marketplace, your floor price, buyer pool, and settlement timing are all moving through a token whose peg to its own supply just broke.
Harmony says it is working with exchanges to freeze the remaining funds and is developing a patch alongside evaluating a rollback. No timeline has been published, and the technical root cause is still undisclosed. Do not price any ONE-denominated NFT trade on the assumption that the network is back to normal until Harmony names the vulnerability and ships a verifiable fix.
Your protocol before the next dump
1. Isolate any ONE sitting on a connected wallet. Move it off hot wallets and off marketplace deposit addresses.
2. Revoke token approvals on every Harmony dApp you have ever touched, including NFT marketplaces and bridges.
3. Pause ONE-denominated listings. Pull floor-priced auctions and offers on Harmony-based collections until price discovery stabilizes.
4. Audit your bridge exposure. If you bridged assets through Harmony, check the wrapper contracts for pause functions and verify whether the team has actually called them.
5. Track the official Harmony channel for the root-cause post-mortem. Interim "patching underway" statements are not proof of containment.
Your non-negotiable checklist before you touch ONE again:
- ONE balances moved to a hardware wallet or off the chain entirely.
- Every Harmony contract approval revoked.
- NFT listings on Harmony marketplaces paused or repriced.
- Bridge positions verified for emergency pause status.
- Wallet activity log scanned for any interaction during the attacker window.
- Post-mortem read before re-engaging with any ONE-touching dApp.
Until Harmony names the vulnerability and ships a verifiable patch, treat the chain as hostile. The exploit path is still active. The attacker still has tokens. The only closed lever is yours.