What Happens to ONE Holders After Harmony's 4B Token Exploit?

What Happens to ONE Holders After Harmony’s 4B Token Exploit?

Last Updated:
What Happens to ONE Holders After Harmony's 4B Token Exploit?
Google News

Get our latest news first. Add us as your Preferred Source on Google and tap "Star" to prioritize our updates.

  • Harmony got hit by an unauthorized mint of 4 billion ONE, totaling 26% of supply.
  • An analyst estimates that about 2.8 billion ONE had already made their way to exchanges.
  • The blockchain is looking into a rollback after sending out an emergency patch.

Harmony is dealing with an apparent unauthorized mint of approximately 4 billion ONE. That’s roughly 26% of the token’s total circulating supply, which stands at around 15 billion.

According to analyst Juiceberg, about 2.8 billion ONE had already made their way to exchanges, underscoring how quickly the tokens spread through the ecosystem.

Juiceberg was also the first to flag the issue on-chain. Following the post on X, Harmony said it was working with exchanges to secure the affected funds and is now considering two possible responses: deploying a software patch or rolling back the blockchain.

The market reaction was severe, as ONE fell roughly 38% at one point. Meanwhile, Harmony posted four ONE wallet addresses and asked exchanges to identify and freeze any money connected to them.

What Happens to Legitimate ONE Transactions?

If Harmony goes ahead with a chain rollback, any transactions that happened after the chosen point would basically be erased from the main chain. This could potentially include completely legitimate transactions.

For example, if a user bought ONE, moved it to a wallet, sent it to an exchange, and traded it or used it in a DeFi app. If they occurred within the rollback window, they may effectively be undone. 

As such, a rollback isn’t just about wiping out the attacker’s coins, since it could rewind everything that happened after that point in the chain.

Why Containing the Damage Isn’t Simple 

If the compromised ONE was swapped for something else on a DEX, that swap may have changed the liquidity pool’s state. In case those transactions get wiped out in a rollback, the app’s internal state could change too.

This raises a number of questions concerning swaps, liquidity provider positions, staking, lending, collateralization, liquidations, bridging activities, and subsequent transfers.

In other words, the further the minted ONE traveled, the more complicated a rollback becomes. That’s why getting exchanges on board might not be enough to contain the fallout.

Can Exchanges Realistically Contain the Damage?

Considering the situation, exchanges could effectively contain the damage to a degree, but not completely. 

Centralized exchanges have one big advantage, since they manage their own user balances and can pause deposits and withdrawals. In case the attacker sends freshly minted ONE to an exchange that’s willing to cooperate, that exchange can potentially freeze those tokens and stop them from being moved out or traded.

However, there’s a limit to this. For instance, if the attacker has already swapped the ONE for something else, withdrew it, shifted it across wallets, or used decentralized apps, it gets a lot harder to track and contain.

The latest update from Harmony stated that the blockchain tracked over 10,000 transfers across 409 wallets that received the fraudulent tokens. It also noted that within four hours of releasing an emergency patch, 53% of validators had already upgraded.

Related: Crypto Hacks Hit $110 Million in July While Bug Discoveries Rise

Disclaimer: The information presented in this article is for informational and educational purposes only. The article does not constitute financial advice or advice of any kind. Coin Edition is not responsible for any losses incurred as a result of the utilization of content, products, or services mentioned. Readers are advised to exercise caution before taking any action related to the company.