Harmony Suffers Critical Exploit As 4B ONE Are Minted Without Authorization, ZachXBT Boycotts Recovery Efforts
In Brief
Harmony confirms 4B ONE minted via empty blocks; 97% routed to exchanges as token crashes 40% and investigator ZachXBT boycotts recovery.

Harmony, a Layer 1 blockchain, has confirmed a critical exploit in which approximately 4 billion ONE tokens were minted without authorization via empty blocks, representing roughly 26% of the token’s pre-existing supply.
On-chain analyst Juiceberg reported that the attacker quickly routed around 2.8 billion ONE to centralized exchanges as the token price collapsed. According to Juiceberg, the attacker retains only about 115 million ONE on-chain—roughly 2.9% of the illicit supply—while “the overwhelming majority, approximately 97%, is already on exchanges and has either been sold or is sitting in deposit wallets ready to sell.”
The market reaction was immediate. ONE plunged approximately 40% to trade near $0.0008, placing the nominal value of the stolen tokens at roughly $3.2 million. Compounding the opacity, Harmony’s totalSupply endpoint did not immediately reflect the inflation, potentially obscuring the dilution from users and monitoring systems.
In response, Harmony instructed validators to install an emergency patch preventing further minting, paused its token bridge, and published four wallet addresses linked to the incident, asking exchanges to freeze associated funds. The network stated it is developing a comprehensive patch and evaluating rollback options.
Investigator Boycott and Rollback Dilemma Complicate Recovery
The incident has drawn renewed scrutiny to Harmony’s history of security lapses and its treatment of the investigator community. On-chain investigator ZachXBT publicly refused to assist with the current incident, stating: “I will not be tracking this incident and think no one should assist them for free.”
He cited Harmony’s handling of the 2022 Horizon Bridge exploit—attributed by the FBI to North Korea’s Lazarus Group—in which the network allegedly “took advantage of people who assisted” and “rewarded $0 for significant freezes which lead to LE seizures and simply said ‘good job.'”
This boycott emphasises a deepening trust deficit as Harmony considers a blockchain rollback, which would revert the network to a pre-exploit state but erase subsequent transactions—a measure widely viewed as antithetical to blockchain immutability. The task is further complicated by the fact that most funds have already reached exchanges.
The exploit also marks Harmony’s third major security failure in recent years, following a December 2023 staking bug that created 146.3 million ONE and the 2022 bridge attack that drained approximately $100 million. Harmony has not yet disclosed the technical root cause of the current breach.
Disclaimer
In line with the Trust Project guidelines, please note that the information provided on this page is not intended to be and should not be interpreted as legal, tax, investment, financial, or any other form of advice. It is important to only invest what you can afford to lose and to seek independent financial advice if you have any doubts. For further information, we suggest referring to the terms and conditions as well as the help and support pages provided by the issuer or advertiser. MetaversePost is committed to accurate, unbiased reporting, but market conditions are subject to change without notice.
About The Author
Alisa, a dedicated journalist at the MPost, specializes in crypto, AI, investments, and the expansive realm of Web3. With a keen eye for emerging trends and technologies, she delivers comprehensive coverage to inform and engage readers in the ever-evolving landscape of digital finance.
More articles
Alisa, a dedicated journalist at the MPost, specializes in crypto, AI, investments, and the expansive realm of Web3. With a keen eye for emerging trends and technologies, she delivers comprehensive coverage to inform and engage readers in the ever-evolving landscape of digital finance.



