← Back

security

Harmony Performs Blockchain Rollback After Creation of 3.01 Trillion Fake ONE Tokens

Harmony has announced a rollback of its blockchain to address a security exploit that created approximately 3.01 trillion counterfeit ONE tokens, affecting network state and transaction history.

AS1 News

harmonysecurityblockchainexploitsecurity-breach
Scale AI

On August 17, Harmony disclosed that it needed to perform a rollback of two parts of its network following a large-scale exploit. The vulnerability allowed attackers to generate around 3.01 trillion fake ONE tokens through six transactions across four wallets. The flaw was traced to the cross-shard receipts mechanism, which was exploited to reuse transaction confirmations for minting new tokens without deducting from existing balances.

As a corrective measure, Harmony decided to revert the network to its state as of August 11. This rollback involves rewriting parts of the blockchain history, a complex process that requires coordination with exchanges, bridges, and applications to ensure consistency and prevent further issues. The network authorities have opted not to burn the forged tokens or migrate the token, as the counterfeit funds have already mixed with legitimate tokens.

The ongoing recovery process aims to synchronize validators and confirm that no further vulnerabilities exist. The incident highlights the importance of robust cross-shard transaction validation and the challenges of addressing security breaches in blockchain systems.

neutral

The network rollback impacts transaction history and validator coordination, with potential implications for user trust and network stability.