Harmony said on August 13, 2026, that its emergency fix for unauthorized ONE minting was active and that it was developing a rollback approach with validators and cryptocurrency exchanges.
The update moved the layer-one network from immediate containment toward a more difficult governance decision: whether participants should rewrite part of the blockchain’s accepted history to remove tokens already created through the exploit. Harmony had not announced a rollback height, implementation schedule or final validator agreement on August 13.
An emergency patch reached the network
Harmony released validator software version 2026.1.1 on August 12 after confirming unauthorized minting and asking exchanges to freeze funds connected with identified wallets. The signed GitHub release identified cross-shard receipt fixes as its only listed change.
Harmony’s August 13 statement said the mint-bug fix had been activated. That was a project assertion about deployment status, not an independent audit proving that every validator had upgraded or that every attack path had been eliminated.
The accompanying code record nevertheless documents two concrete changes. One corrected a quorum check that had counted the size of a validator committee rather than the enabled signers represented in a bitmap. Under affected conditions, an empty bitmap combined with an identity aggregate signature could incorrectly satisfy the check.
The second change addressed replay protection for cross-shard receipts. Some receipt-identifying fields were not bound to the signed block header, allowing a previously processed proof to be altered so that it appeared unspent. The destination could consequently be credited again without a corresponding new debit on the source shard. The patch derived the spent marker from authenticated header information instead.
Those code changes explain a mechanism by which excess ONE could be created, but Harmony had not published a complete incident report, independent security review or authoritative accounting of the resulting supply on August 13.
The scale remained an estimate
An on-chain researcher using the name Juiceberg estimated that approximately 4 billion ONE had been minted without authorization. CoinDesk compared that estimate with roughly 15 billion ONE previously in existence. Dividing 4 billion by 15 billion produces an implied increase of about 26.7%, before considering how supply endpoints classified or displayed the new tokens.
Harmony confirmed fraudulent minting but had not independently confirmed the 4 billion figure. It also had not established publicly how many tokens exchanges had frozen, how many had been sold, or how many remained under the attacker’s control. The estimate therefore described the apparent magnitude of the incident, not a finalized protocol accounting.
CoinDesk reported that ONE fell about 40% during Asian morning trading on August 12 as the exploit became public. That measurement concerned the ONE token, used an intraday Asian-session window reported by CoinDesk, and was not a UTC-day close, volume-weighted benchmark or independently reconstructed exchange composite. No verified August 13 closing return was available from the reviewed records.
Why a rollback was consequential
Stopping additional minting and removing tokens already created are separate operations. The activated patch was intended to address the first problem. A rollback would require validators to reject part of the existing ledger and resume from an earlier state.
That could reverse the attacker’s on-chain transactions, but it could also unsettle legitimate transfers, decentralized-exchange trades and cross-shard activity completed after the chosen rollback point. Tokens already deposited or sold through centralized exchanges would add another reconciliation problem, explaining Harmony’s stated need for exchange coordination.
As of August 13, the rollback remained a proposed response rather than an executed protocol change. The unresolved questions were not merely technical: validators had to converge on one history, exchanges had to decide how to treat affected deposits, and users lacked a final accounting of which transactions could be reversed.
The verified event was therefore narrower than some market summaries suggested. Harmony had activated an emergency receipt-validation fix and was pursuing alignment on a rollback. It had not yet established the final excess supply, completed recovery or demonstrated that the incident’s economic effects had been undone.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

