In Brief:
- Harmony plans a blockchain rollback across both shards to eliminate more than three trillion ONE tokens created through the exploit.
- Investigators traced 3.01 trillion forged ONE across six transactions, while one exploiter wallet transferred nearly 2.4 trillion tokens within minutes.
- The rollback will erase legitimate transactions within the affected window, while Harmony has already patched the cross-shard verification vulnerability completely.
Harmony has chosen to roll back its blockchain, with validators preparing to erase over 3 trillion forged ONE tokens and restore the pre-exploit state. According to Harmony’s incident update on X, validators will roll back Shard 0 and Shard 1, which form its sharded blockchain network.
Validators will restore both shards to the final confirmed block before the fraudulent minting, consequently discarding all subsequent blocks and transactions. Harmony considered several recovery options, including burning tokens, blacklisting exploiter wallets, and migrating ONE holders, while assessing potential network risks.
However, Harmony determined those measures could create technical complications or affect unsuspecting users, leading it to select a fixed rollback window. Moreover, the approach applies one network-wide rule instead of targeting individual wallets, which Harmony believes reduces attack and consensus failure risks.
Also Read: Shiba Inu Exchange Outflows Beat Inflows Despite 128% SHIB Activity Surge
Harmony Traces 3.01 Trillion Forged ONE Across Six Transactions
Harmony confirmed the exploit on August 12 when investigators identified unauthorized ONE tokens entering the network. Early findings suggested attackers had created approximately 4 billion tokens through empty blocks.
Further investigation revealed the initial figure represented only a fraction of the total supply, as Harmony reported 3.01 trillion forged ONE across six transactions. Investigators traced those transactions to four exploiter wallets, with one transferring nearly 2.4 trillion ONE within two minutes. The tokens were worth almost $3 billion at pre-exploit prices, although available liquidity would have limited potential proceeds.
Harmony has traced nearly all forged tokens to identifiable wallets or services, but movements through decentralized exchanges and bridges complicate recovery. Additionally, forged ONE entered liquidity pools and mixed with other users’ assets, meaning burns or freezes could affect uninvolved market participants.
Investigators linked the exploit to a cross-shard receipt verification weakness that reportedly allowed attackers to process legitimate receipts multiple times. Consequently, exploiters could create new ONE tokens without recording an equivalent debit elsewhere on the network. Harmony patched the vulnerability on August 12 once developers identified the underlying problem.
Rollback Will Also Remove Legitimate Transactions
Harmony’s rollback will remove blockchain activity recorded between the chosen restoration point and the network’s current state. That means legitimate transactions completed within the affected window will also disappear.
Hence, the recovery method carries consequences beyond eliminating the trillions of forged ONE tokens. Users may need to account for transfers that no longer exist following the restoration.
Despite those effects, Harmony concluded that selective token recovery presented greater risks because forged assets had already moved across multiple services. A fixed rollback also avoids determining which individual wallets should face restrictions.
The planned blockchain reversal now represents Harmony’s primary recovery strategy for removing the unauthorized supply. Validators will determine the network’s restored state by implementing the rollback across both shards.
Also Read: Solana Futures Volume Surges as Crowded Long Positions Raise Retrace Risk
