Harmony plans pre-attack rollback after exploiter forged 3 trillion ONE tokens
Harmony considered alternatives, including a token burn & blacklisting wallets, but concluded a rollback was "fairest and most secure."
Harmony Blockchain considers rollback after massive ONE exploit
The Layer-1 blockchain Harmony is considering rolling back its network after an attacker exploited weaknesses to create unauthorised ONE tokens. The incident involved the unauthorized creation of roughly 4 billion ONE tokens, which represented about 26% of the network’s previously reported supply of 15 billion tokens. The attack began with the creation of two empty-block transactions, generating 1 billion and 3 billion ONE respectively.
Harmony halted Shard 0 at block 92,753,555 to prepare the rollback operation, while also working with validators and exchanges to coordinate a response. The network identified the proposed rollback point as block 92,730,034, recorded on August 11 at 23:25:37 UTC. Harmony has been working to prevent the vulnerability from being exploited again by patching the cross-shard validation mechanism and introducing changes to precommittee quorum verification.
The attack has complicated Harmony's rollback process due to the movement of billions of newly created ONE tokens to addresses associated with the attacker. Some of these tokens had already been transferred away from the original wallets before containment measures could be fully implemented. While rolling back the blockchain to the pre-exploit block could remove fraudulent transactions and restore the token supply, it could also invalidate legitimate transactions conducted after the rollback point.
This event highlights the challenges faced by decentralised networks when protocol-level flaws compromise their ledgers. Harmony's proposal for a rollback creates a difficult trade-off, as returning to the pre-exploit block could remove fraudulent on-chain activity and restore the token supply, but it may also invalidate legitimate transactions. The controversy raises questions about how decentralised networks should respond when fundamental network validation and token creation are compromised.
Written by urgent.news from Arabian Post's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.
- Harmony advances rollback after massive ONE exploit thearabianpost.com
- Harmony plans rollback, wiping 109,000 transactions after ONE exploit cointelegraph.com