Harmony to Roll Back Blockchain After Attack Issuing Trillions of ONE

In Crypto Regulations
August 18, 2026

Harmony to Roll Back Blockchain After Attack Issuing Trillions of ONE

The Harmony blockchain team has prepared to roll back the network to its state just before an exploit allowed attackers to unauthorizedly issue approximately 4 trillion ONE tokens.

According to the developers, they chose a unified recovery point for both shards to remove the assets generated by the attackers and minimize the risk of damaging legitimate funds.

Harmony to Restore Network to Pre-Attack State

For the recovery, Harmony selected the following checkpoints:

  • Shard 0 — block #92,730,034;
  • Shard 1 — block #94,978,278.

Both blocks correspond to August 11, 2026, at 23:25:37 UTC. At these heights, validators will receive new databases, and the network will resume operations from blocks #92,730,035 and #94,978,279, respectively.

Earlier, Harmony reported that the incident began on August 12. The first attack was recorded in Shard 0 at block #92,730,036. According to one reconstruction, the total volume of fake issuance was about 3.01 trillion ONE through six cross-shard transactions and four attacker wallets. An earlier analysis indicated that the issuance in two empty blocks amounted to approximately 4 trillion ONE — about 27% of the total tokens in circulation.

Why Burning Stolen ONE Isn’t Feasible

The Harmony team considered several alternatives to a rollback but rejected them due to the risk of affecting user funds.

For example, targeted burning was deemed too risky: the tokens issued by the attackers had already passed through exchanges, DEXs, liquidity pools, bridges, and numerous wallets. After mixing ONE with legitimate funds, it is impossible to safely destroy the entire tracked volume without risking the destruction of others’ assets.

A blacklist of addresses was also unsuitable. It does not eliminate the already created issuance and could potentially block wallets not involved in the attack.

Another option was selective transaction recovery. However, after changing the blockchain state, the same transaction might yield a different result. This is especially critical for swaps, staking, contracts, and liquidity reserves.

Therefore, Harmony decided to apply a single rule to all network participants: all blocks after the selected checkpoints will be discarded, including legitimate transactions.

What Happened to the Blockchain

The root cause of the attack was a vulnerability in the cross-shard transaction confirmation mechanism. The bug allowed already used receipts to be processed again.

Separately, developers discovered an issue in quorum verification for staking epoch committees. Under certain conditions, a zero BLS signature could pass quorum verification. The team is still determining whether this bug was directly used in the attack.

Almost All Fake Issuance Tracked

A preliminary model allowed tracking more than 99.9% of the fake ONE to a specific wallet or service boundary. However, developers emphasized that successful monitoring does not enable the safe destruction of illegitimate tokens for users.

The team has already provided lists of addresses related to the incident to exchanges and LayerZero and is cooperating with trading platforms, bridges, and law enforcement agencies.

Rollback to Affect Tens of Thousands of Transactions

One of the challenges for the team was accurately determining which operations after the attack’s start could be preserved.

Harmony analyzed 141,628 consecutive blocks of Shard 0, containing 109,126 regular and 315 staking transactions. Almost all were automated, with DEX operations alone accounting for 99,863 transactions.

Of these, only 22 operations were simple ONE transfers without obvious dependencies. However, even these were not considered automatically safe for recovery by the developers. More than 80,000 transactions depended on the state of smart contracts or the blockchain, and tens of thousands were related to errors, the incident, exchanges, bridges, or fund consolidation.

After the rollback, balances, pool reserves, approvals, and staking states will change. Therefore, a transaction that failed in the original chain might theoretically succeed in the restored one. Hence, the team deemed selective recovery too risky.

Network Remains in Recovery Mode

Harmony halted Shard 0 at block #92,753,555 to prepare for the rollback. The team has already prepared a code change request and a binary file for recovery, but the final launch depends on the agreement of validators, exchanges, and the fulfillment of technical conditions.

Previously, during an ongoing attack on vulnerable Coldcard hardware wallets, user losses reached at least 1,700 BTC.

Avatar photo
/ Published posts: 934

Steven M. Crimmins is a cryptocurrency strategist and freelance writer who has followed the blockchain industry since Bitcoin’s early days. Known for his sharp analysis of altcoins and trading strategies, Steven provides Satoshi News Africa readers with market-focused content grounded in research. He is especially interested in how African traders are adopting crypto as an alternative to traditional markets. Steven is also a podcast host, where he discusses emerging technologies and investment trends.