Someone minted 4 billion tokens out of thin air on Harmony. Here is what we know

On 12 August an attacker exploited what analysts identified as a consensus-verification flaw on the Harmony blockchain to mint roughly 4 billion ONE tokens, inflating supply about 26 percent and crashing the price by roughly a third. Around 97 percent of the tokens reached exchanges before the mint went public. The realised haul was only a few million dollars, but tokens created from nothing is the real alarm.

Someone minted 4 billion tokens out of thin air on Harmony. Here is what we know
TL;DR

On 12 August an attacker minted roughly 4 billion ONE tokens on the Harmony blockchain by exploiting what analysts identified as a consensus-verification flaw, inflating supply by about 26 percent and crashing the price by roughly a third. Around 97 percent of the new tokens reached exchanges before the mint became public. In dollars the realised haul was modest, a few million, but the fact that tokens could be created from nothing is the real alarm. Harmony has shipped an emergency fix to stop further minting and is chasing the funds.

Early on 12 August 2026, someone printed about 4 billion new ONE tokens on Harmony that should never have existed. It was not a bridge drain or a phishing sweep of user wallets. The attacker made the blockchain itself mint fresh supply, then moved almost all of it onto exchanges before most people knew anything had happened. The dollar figure turned out to be small, but the nature of the failure, a chain minting tokens from nothing, is exactly the kind of thing that is supposed to be impossible.

What happened?

An on-chain analyst who posts as Juiceberg flagged the mint during the morning, before Harmony had confirmed anything. The new tokens had appeared through "empty blocks", blocks containing no real transactions that nonetheless credited freshly created ONE to the attacker's wallets, and Harmony's own total-supply figure did not yet reflect them.

The key facts, from on-chain analysis and trade reporting:

  • What: roughly 4 billion ONE minted without authorisation on 12 August 2026. That total is an on-chain estimate; Harmony has not confirmed its own figure.
  • Supply hit: about a 26 percent jump against a pre-existing supply of roughly 15 billion ONE.
  • Price: ONE fell by roughly a third, and by some measures closer to 40 percent, to about $0.0008.
  • Where it went: around 97 percent of the minted tokens, roughly 3.9 billion ONE, had already reached exchange deposit wallets or been sold by the time the mint was public, leaving only around 115 million still to move.
  • Detection: spotted first by an independent analyst, not by Harmony, from the empty blocks and a supply endpoint that did not add up.

How do you mint 4 billion tokens out of nothing?

Harmony has not officially disclosed the exact flaw. According to the on-chain analyst who published a breakdown the same day, the bug lived in how the network checked consensus. When validators sign a block, their approvals are tracked with a "mask", a list of which keys are covered. The verifier, the analysis says, counted the public keys listed in that mask rather than the validators who had actually signed, so a forged message carrying no valid signatures still cleared the quorum threshold. In the analyst's words, the mask "is the list of public keys the mask covers, not the subset that signed, so every listed key counted as a signer whether it had signed or not." That let the attacker push through fake consensus messages that minted ONE into their own wallets.

Until Harmony confirms its own post-mortem, treat the precise mechanism as the best current reading from independent analysis rather than a settled, official account.

Wait, so how much was actually stolen?

Less than "4 billion tokens" suggests. Because ONE trades at a tiny fraction of a cent, and the price collapsed the moment the mint was spotted, the attacker's realised haul was modest: one analysis put it at around $3.2 million at post-crash prices. That is a fraction of the headline sums seen in this year's other crypto incidents, such as the roughly $116 million Coldcard hardware-wallet theft.

But the dollar figure is not really the point. A token supply that can be inflated 26 percent overnight is a break in the one guarantee a blockchain is meant to provide: that no one can conjure the asset from nothing. The price fell both because that flood of new supply diluted existing holders and hit exchanges, and because the integrity break itself dented confidence, even though the attacker's direct take was small.

What has Harmony done?

Harmony moved quickly once the mint was public. It paused its token bridge, shipped an emergency validator update, versioned 2026.1.1, that fixes a quorum-verification flaw, and instructed validators to upgrade. It has not, however, publicly confirmed that this flaw was the cause of the mint, or published a full post-mortem. It asked exchanges to freeze funds tied to four flagged wallet addresses, and said it was weighing a blockchain rollback to reverse the affected transactions. Getting the tokens back is another matter: with roughly 97 percent already on exchanges or sold, recovery depends heavily on how fast those platforms can freeze the linked deposits.

Has this happened to Harmony before?

Yes, twice, which is part of why the reaction was so sharp. Harmony's Horizon bridge was drained of about $100 million in 2022, and a separate staking bug in 2023 minted roughly 146 million unintended ONE. This incident dwarfs the 2023 issuance by token count, around 27 times larger, and differs in kind: the 2023 tokens came from a malfunction, while these were directed straight to specific wallets and routed toward exchanges, a pattern more consistent with a deliberate theft than an accidental over-issuance. For a project still rebuilding trust after 2022, a third major security failure is a heavy blow. (It lands during a rough stretch for the sector generally; see our look at the 2026 crypto shakeout.)

Frequently asked questions

How many ONE tokens were minted, and what did it do to the price?

On-chain estimates put it at roughly 4 billion ONE minted without authorisation on 12 August 2026, inflating supply by about 26 percent. The price fell by roughly a third, and by some measures closer to 40 percent, to about $0.0008. Harmony has not confirmed its own total.

How much money did the attacker actually make?

Less than the token count implies. Because ONE trades at a fraction of a cent and the price crashed immediately, one analysis estimated the realised haul at around $3.2 million. The bigger concern is the supply-integrity breach, not the dollar amount.

How was it done?

Harmony has not published an official cause, though it shipped a patch (version 2026.1.1) fixing a quorum-verification flaw. Independent on-chain analysis points to that kind of consensus bug: the network counted the public keys listed in a signature "mask" rather than the validators that actually signed, letting forged messages with no valid signatures mint tokens through empty blocks.

Can the tokens be recovered?

Unclear. Harmony has asked exchanges to freeze funds linked to four flagged wallets and is considering a rollback, but around 97 percent of the tokens were already on exchanges or sold before the mint was public, so recovery depends on how quickly those platforms act.