Harmony disclosed on June 24, 2022 that unauthorized transactions had removed tokens valued by the protocol at approximately $100 million from its Horizon bridge. The bridge connected Harmony with Ethereum and other networks, making the incident both a direct loss and another warning about the concentrated security assumptions embedded in cross-chain infrastructure.
Harmony’s incident publication said the project had been notified of the attack on June 23. It reported that multiple transactions extracted tokens held by the bridge and identified an Ethereum address associated with the recipient. By June 24, Harmony said it had contacted cybersecurity and exchange partners and the FBI, attempted to communicate with the responsible party through an on-chain message and supplied findings to investigators in the United States.
The central fact available on June 24 was therefore limited but consequential: the bridge had suffered an unauthorized outflow estimated near $100 million, and recovery and attribution efforts had begun. Harmony had not yet published a completed post-mortem or established publicly how the required transfer authority had been obtained.
What the initial record established
Harmony’s maintained incident page described 11 transactions and assigned the extracted assets an estimated value of approximately $100 million at the time of the attack. Blockchain-analysis firm Elliptic separately examined activity across Ethereum and Binance Smart Chain, counted 14 transactions and estimated the stolen assets at $99.7 million.
Those figures are not interchangeable measurements. Harmony supplied a rounded incident estimate, while Elliptic applied its own asset identification, chain coverage and contemporaneous dollar-conversion methodology. The difference in transaction counts may reflect scope or grouping, but the records available for this reconstruction do not support a definitive reconciliation. Approximately $100 million is consequently the most defensible event-day description, not a claim of an exact realized dollar loss.
Elliptic identified assets including ETH, BNB, USDT, USDC and DAI and reported that tokens were exchanged through decentralized exchanges, leaving most of the assessed value in ether at the recipient address. These were observable transaction-tracing findings, but they did not identify the attacker or prove the initial intrusion method.
Why the bridge failure mattered
A cross-chain bridge generally locks or controls assets on one network while representing their value on another. That design can concentrate large pools of tokens behind a separate authorization system. Security of the underlying blockchains does not by itself guarantee that the bridge’s validators, signing credentials, contracts or operational systems cannot be compromised.
The Horizon loss arrived during a year already marked by major bridge failures. Elliptic estimated that the addition of Horizon pushed the value stolen from bridges during 2022 above $1 billion. That aggregate was the analytics company’s incident dataset and dollar-valuation measure, not a complete census of every disputed transaction or loss across decentralized finance.
The sequence also exposed a practical dependency on centralized response channels. Harmony stopped the affected bridge, notified exchanges and sought assistance from cybersecurity firms and law enforcement. Those actions could limit further transfers or support tracing, but they did not guarantee recovery, reimbursement or identification of the responsible party.
No bitcoin, ether or ONE price move is attributed to the disclosure here. Crypto assets traded continuously across venues, and the reviewed records do not establish that this incident caused a specific market change during a defined UTC or exchange session.
What remained unknown on June 24
Harmony had not established publicly on June 24 whether the loss resulted from compromised credentials, faulty code or another operational intrusion. It had also not released a final asset inventory, independently audited loss total or remediation plan for affected users. Assertions about the attack mechanism therefore remained preliminary or speculative on that date.
Later context
On June 25, Harmony attributed the authorization path to compromised private keys and described changes to the bridge’s signing threshold. On January 23, 2023, the FBI attributed the theft to North Korea-associated Lazarus Group actors, also known as APT38. Neither finding was available for the initial June 24 account and neither is projected backward into its event-day conclusions.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

