Supply surged by 3 trillion dollars, and the established public chain Harmony is in jeopardy again

Source: Foresight News
Written by Mach
Original title:Hackers print 3 trillion ONE: the established public chain Harmony was fatally hit again
In 2022, Harmony's total TVL peaked at over $1.4 billion.DeFilLama's latest data shows that its TVL is less than $170,000.
Hacker attacks are becoming the “number one killer” of cryptographic protocols.
On August 12, X user Juiceberg tweeted that on-chain data showed that the Harmony protocol had been exploited.
The attackers illegally minted around 4 billion ONE tokens (worth more than $3 million) through empty blocks, accounting for 26% of its total supply.
Of these, about 2.8 billion tokens were quickly transferred to exchanges during the price crash.
At the same time, Harmony's total supply endpoint failed to reflect this token increase, resulting in differences between the actual supply on the chain and public data.
The attackers have about 115 million pieces left on the chain (accounting for about 2.9% of the minting volume), and the vast majority of the rest have already entered exchange accounts.
Either it has been sold, or it is stored in a deposit wallet.
After the news was announced, ONE's price plummeted from $0.00118 to a minimum of $0.00056.
It has now recovered to $0.00078, down nearly 38% in 24 hours.
Harmony officially retweeted the response on the X platform and is cooperating with the team and a number of related exchanges to block and freeze the funds involved;
Also advance software patch development and evaluate network rollback options.
Subsequently, the government further announced four sets of relevant wallet addresses, clearly requiring each exchange to block and freeze funds traceable to these addresses:
one1uap8dx2z0qsjxqthm5flgcxkeepsz3gsrghnfn
one17u300a40ll5wphd8kj5hktryhdjq3ml9f4phy4
one1a5hur07z5vtvzhr35zkw8tfqedemkz8t88xgd7
one1h56hkxmua0uzfv07fu04cudvtrl35u96pq47vy
At around 2 p.m., it was officially announced that the bridge.harmony.one cross-chain bridge service would be suspended due to a security incident.
All validators are also required to immediately upgrade to the latest patch version v2026.1.1.
Officially, the patch will prevent further illegal minting, and will be updated separately to handle minted tokens in the future. The relevant release notes are already available on GitHub.
This is the third time in recent years that Harmony has experienced major security or technical issues directly related to token supply.
In June 2022, its Horizon cross-chain bridge was attacked, and it lost about 100 million US dollars in assets.
The US Federal Bureau of Investigation later attributed the incident to North Korea-related hacker groups.
In December 2023, a bug occurred in the staking system, causing approximately 146.3 million ONEs to be mistakenly minted, involving 74 addresses.
A single address received more than 51 million coins, and some of the tokens were then transferred to the exchange, where the official patch was urgently released and follow-up measures were taken.
Judging from the size of the market, although this incident caused drastic dilution of supply and sharp price fluctuations, the scale of absolute losses was limited.
Prior to the incident, Harmony's market capitalization had dropped to around $17 million; after the incident, it fell further back to the $12 million level, and the market value evaporated by about $5 million.
In 2022, Harmony's total TVL peaked at over $1.4 billion, and DeFilLama's latest data shows that its TVL is less than $170,000.
According to CertiK Alert monitoring, as of around 4 p.m.
The number of ONE tokens unusually minted by the Harmony network has exceeded 3 trillion (worth about $2.34 billion).There are six exception blocks involved.
Early attackers initially used the total supply interface to hide incremental data, and different blocks were packaged one after another, so the 4 billion increase at the time was far from real data.
X account BlockWatchDog said in an analysis of this incident that the attackers took advantage of Harmony's serious logical errors in cross-shard receipt verification and signature checks.
Approximately 3 trillion coins were counterfeited in one go.
Harmony is a sharded chain, and transfers between different shards require a “receipt” to prove it.
The hackers falsified this receipt, and the receipt says:From an epoch a long time ago (100th epoch, now over 3000)
The signatures are all empty (zero signatures)
Transfer from a dead address (0x00... DEAD)
Under normal circumstances, the system should simply reject it. However, there are two flaws in the system: First, the signature check is wrong.
When the system checks “whether enough people have signed”, it only looked at “how many people in the committee total”, not “how many people actually signed”.
Result: As long as the number of members on the committee is 4 or more, all empty signatures can pass. It's equivalent to a broken door lock; you can push it in.
Second, there is a flaw in the anti-heavy protection. The system checks “has this receipt already been used?” The fields it relied on during the old epoch were able to be filled in by the attackers themselves.
So attackers can use the same fake receipt over and over, or bypass checks.
When the two bugs are combined, attackers can create trillions of coins at once.
As of press release, the government has not confirmed whether the network rollback will eventually be carried out.
Rollback means restoring the chain state to a certain node before the attack occurred. Theoretically, some of the effects of illegal casting can be removed.
However, once a large number of tokens have entered centralized exchanges and completed transactions, the actual effect will be significantly limited.
Whether the exchange has effectively frozen the relevant funds and the progress of the patch being popularized in verification nodes,
As well as the subsequent processing plan for minted tokens, they will become the core variables of short-term market attention.
As an early Layer 1 public chain that focused on high performance and low fees, Harmony had a place in DeFi and cross-chain narratives.
Continued security incidents, compounded by long-term market capitalization contraction, have drastically reduced their attention in the current crypto market.
This incident once again revealed the fragility of the small-market capitalization public chain in terms of consensus and supply mechanisms, and also reminded market participants when evaluating similar projects
Their historical security records and actual on-chain activity need to be examined more carefully.
[Disclaimer] The market is risky, so you need to be careful when investing.
This article does not constitute investment advice, and users should consider whether any opinions, opinions, or conclusions in this article are in accordance with their particular circumstances. You are responsible for investing according to this.
Twitter:https://twitter.com/BitpushNewsCN
Compare the TG exchange group:https://t.me/BitPushCommunity
Compare TG subscriptions:https://t.me/bitpush



