Harmony disclosed on June 25, 2022 that its investigation had found evidence of compromised private keys behind the Horizon bridge breach, materially narrowing the explanation for one of the year’s largest cryptocurrency thefts. The protocol said it had found no evidence that Horizon’s smart-contract code or the Harmony consensus layer had been breached.
The distinction mattered. Horizon moved assets between Harmony and other blockchains, but the bridge depended on a limited group of signing keys to authorize transfers. Harmony’s account indicated that an attacker did not need to defeat the underlying blockchain’s consensus rules: obtaining enough bridge credentials was sufficient to sign unauthorized transactions and remove assets held on the Ethereum side.
What Harmony disclosed
In an incident update labeled 8:25 p.m. PST on June 25, Harmony said its private keys had been stored in encrypted form, protected by both passphrases and a key-management service. According to the company, no single machine held multiple keys in plaintext. The attacker nevertheless gained access to and decrypted multiple keys, including keys used to approve the unauthorized transfers.
Harmony said stolen assets—including USDC, ETH and WBTC—were exchanged for ether and remained in the attacker’s Ethereum account at the time of the update. That was a contemporaneous company finding, not a completed independent forensic report. Harmony also withheld unspecified details because its investigation was continuing.
The company said it had changed the Ethereum side of Horizon to a four-of-five multisignature arrangement after the breach. That meant four authorized keys would be required for subsequent approvals, compared with the lower threshold that had protected the bridge before the theft. Raising the threshold reduced the risk that the compromise of a small number of credentials could authorize another transfer, but it did not establish how the keys had been obtained or prove that every affected system was secure.
Twenty minutes after the technical update, Harmony announced a $1 million bounty for the return of the funds and said it would advocate against criminal charges if the assets were returned. The offer represented a recovery attempt, not evidence that the attacker had accepted it or that funds would be restored.
Measuring the loss
Harmony’s incident page estimated that approximately $100 million was extracted during transactions detected on June 23, 2022. CertiK’s contemporaneous transaction analysis calculated approximately $97 million across 12 attack transactions and three attacker addresses. It also found that an authorized wallet owner’s privileges had been used to confirm and execute transfers.
Those figures describe estimates at the time of the transfers, not a later recovery value or a universal market price. The difference between approximately $97 million and approximately $100 million reflects source methodology, token selection and valuation timing. This reconstruction therefore retains Harmony’s rounded figure while identifying CertiK’s narrower estimate rather than presenting false precision.
No bitcoin, ether or ONE market-price claim is used here. Cryptocurrency trading continued around the clock across venues, and the reviewed records do not establish that the June 25 disclosure caused a specific market move.
Why the disclosure mattered
The June 25 finding focused attention on the institutional design of cross-chain bridges. Assets advertised as moving between decentralized networks could still be controlled by a small credential set, creating a concentrated operational risk outside the consensus security of either blockchain.
It also established limits on what was known. Harmony had identified key compromise as the immediate authorization path, but had not publicly documented the initial intrusion method, the complete affected-asset inventory or a final independently verified loss calculation. The four-of-five change addressed the signing threshold; it did not by itself answer those questions.
Later context
On January 23, 2023, the FBI attributed the theft to North Korea-associated Lazarus Group actors, also known as APT38. That later attribution was not available on June 25, 2022 and should not be projected into the event-day account. On June 25, the defensible record was narrower: Harmony reported compromised bridge keys, an approximately $100 million loss estimate, a hardened signing threshold and an unresolved investigation.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

