
Harmony plans a chain rollback after a $3 billion token-forging exploit
An exploiter forged 3.01 trillion ONE tokens on Harmony's sharded network by finding a way to replay the same valid receipt across shards, and the Harmony team now plans to roll the chain back to the moment before it happened rather than try to contain the damage after the fact.
The flaw sat in how Harmony verifies receipts moving between its two shards, Shard 0 and Shard 1: a valid receipt could be processed more than once, letting tokens get minted on one side without a matching debit on the other. Across six transactions into four wallets, the exploiter used that gap to forge 3.01 trillion ONE. One wallet alone moved 2.4 trillion of it, worth close to $3 billion at pre-attack prices, though ONE's price collapsed once the scale of the forgery became clear, so the realizable value of any of it dropped fast. An independent researcher first flagged the issue on August 12 after spotting roughly 4 billion tokens minted through empty blocks, a fraction of the eventual total; Harmony patched the underlying flaw the same day, and only a fuller reconstruction afterward revealed the exploit's true scope.
Harmony says it considered burning the forged tokens, blacklisting the exploiter's wallets, and migrating the token entirely before settling on a full rollback of both affected shards to the block immediately preceding the forged mint, discarding every block and transaction that came after it, forged or not.
“Of the options we studied, one fixed rollback window is the fairest and most secure. It applies one rule to everyone, removes the forged state, and carries the lowest risk of another attack or consensus failure.”
— Harmony team
A rollback is a blunt instrument by design: it doesn't distinguish forged transactions from ordinary ones, so anyone who sent, received, traded, or bridged ONE on either shard during the affected window gets reset along with the attacker, which is precisely the trade-off Harmony is arguing was still the least-bad option available. Minting bugs hiding in verification logic keep surfacing across chains with complex internal accounting: Zcash closed an Orchard-pool bug of its own kind only weeks ago, one that had sat unnoticed for roughly four years before anyone caught it. Cross-shard messaging in particular has a track record as a soft target, since every extra hop between chains, or between shards of the same chain, is one more place a receipt can be replayed, double-counted, or trusted when it shouldn't be, and a bug in that path can mint value directly rather than just draining what's already locked somewhere.
Rollbacks carry a heavier history than most fixes in this industry: Ethereum's own 2016 hard fork after the DAO hack remains the reference case, and it split the community badly enough that Ethereum Classic still exists as the chain that refused to roll back. Harmony's version is narrower in one important sense — it touches only the two shards where the forged mint happened, not the entire network — but the underlying tension is the same one every rollback runs into: validators and node operators still have to actually adopt the new canonical chain for the plan to work, and anyone who built a position, trade, or integration on the discarded blocks is out that activity regardless of whether they had anything to do with the exploit.
This article is for informational purposes only and does not constitute investment advice.

Comments (0)
No comments yet — be the first!
Related news
Most readTop 7
Silicon Valley Workers Are Wearing Noise-Cancelling Masks to Dictate AI Prompts
235AI





