Harmony said it was working with exchanges to freeze funds linked to the exploit and identified four wallet addresses associated with the incident. The network also said it was evaluating rollback options.
Harmony later paused its bridge and released an emergency software update for validators that it said would prevent additional unauthorized minting. The project said a separate update would be required to address the tokens already created.
Harmony has not yet disclosed the vulnerability behind the exploit or provided its own confirmed figure for the amount of $ONE created or transferred to exchanges. Its reported circulating supply before the incident stood at roughly 15 billion tokens, making the approximately 4 billion unauthorized tokens equal to about 26% of that amount.
A rollback would restore the blockchain to a state before the exploit, potentially removing the unauthorized tokens that remain on the network. It would also reverse legitimate transactions processed after the selected rollback point.
Harmony previously suffered a major security breach in June 2022, when attackers stole approximately $100 million from its Horizon bridge. The FBI later attributed that attack to North Korea’s Lazarus Group.