Harmony weighs a full blockchain rollback after unauthorized minting floods exchanges with billions in ONE
Harmony, the layer-1 blockchain community, has launched an emergency validator patch that it says prevents additional unauthorized minting of ONE, its native token. The venture stated it is going to tackle tokens already created in a later replace, leaving their quantity and supreme remedy unresolved.
Harmony told validators to install v2026.1.1 on Aug. 12. The discover confirms that minting occurred however doesn’t disclose the quantity.
Onchain researcher Juiceberg estimated that roughly 4 billion ONE, equal to about 26% of the provision determine used in the publish, had been minted with out authorization. Juiceberg additionally estimated that 2.8 billion ONE had reached exchanges. Harmony has not independently confirmed these figures.
How the patch blocks extra minting
Harmony’s published code changes tackle two weaknesses in cross-shard receipts, which carry transaction outcomes between elements of the community.
One flaw allowed an empty signer file and a mathematically impartial mixture signature to cross a quorum test. The verifier counted the full committee as an alternative of the validators represented in the signer file, permitting a receipt to be accepted with out the required approvals.
The second flaw affected how the community recorded that a receipt had already been spent. Some proof fields weren’t certain to the signed block header, so altering these fields may make a beforehand processed receipt seem new. The vacation spot may then be credited once more with out a corresponding debit from the supply.
The signed v2026.1.1 release adjustments the quorum calculation and ties the spent marker to authenticated header knowledge, closing each paths described in the patch.
Harmony additionally paused bridge.harmony.one in the course of the response, though its discover didn’t determine the bridge because the exploited element. The venture published four implicated wallet addresses and requested exchanges to dam and freeze traceable funds, with out naming the venues or disclosing how a lot had been frozen.
Harmony’s initial response stated rollback choices had been into account. The venture has not introduced that a rollback will happen or specified the purpose from which transactions may very well be reversed.
The incident differs technically from the June 2022 Horizon bridge exploit, which concerned compromised multisig management and about $100 million in stolen belongings. The present patch as an alternative addresses receipt verification and replay on the protocol degree.
Harmony says additional minting is now blocked. The remaining threat facilities on the dimensions and placement of the ONE already created, how a lot exchanges can freeze, and whether or not the community will try a rollback to take away the surplus provide.
The publish Harmony weighs a full blockchain rollback after unauthorized minting floods exchanges with billions in ONE appeared first on CryptoSlate.
