Harmony’s native token ONE plummeted to an all-time low after an attacker minted 4 billion tokens — roughly 26% of the total supply — and moved most of them to exchanges to sell. The unauthorized minting was first flagged by on-chain analysts on August 12, 2026, and quickly led to a price crash from around $0.00117 to a new ATL of $0.0005735, according to CoinGecko data.
Harmony confirmed the exploit and said it was traced to four wallet addresses. The project has paused its LayerZero bridge, requested validators to upgrade with a patch that prevents further minting, and is working with centralized exchanges to freeze funds. Nearly 97% of the minted 4 billion ONE had already been deposited on exchanges, with the attacker holding just 115 million ONE available to sell on-chain.
The incident drew a sharp response from prominent on-chain investigator ZachXBT, who publicly stated that no one should help Harmony for free. He pointed to the project’s failure to pay a bounty or compensate white-hat hackers and analysts who assisted after the 2022 Horizon Bridge exploit, which resulted in a $100 million theft by North Korean hackers. At that time, volunteers helped trace and freeze assets but received only a “good job” acknowledgment. “I will not track the case,” ZachXBT wrote, underscoring a growing demand for fair compensation for security researchers.
The ONE token recovered slightly to trade about 33% above its ATL but was still down nearly 40% over 24 hours and more than 32% for the week. The episode highlights the risks in blockchain bridges and the importance of robust bug bounty programs to maintain ecosystem security.