Newsroom
17 August, 2026 / News / AI / Tags: harmony, shard, forged, replacement, databases

The network will replace post-August 11 transaction history on shards 0 and 1, discarding more than 109,000 transactions to remove unauthorized tokens created in a minting attack
Harmony plans to roll back its blockchain on two shards to checkpoints recorded on August 11, discarding more than 109,000 regular transactions and hundreds of staking operations. The move follows an exploit that allowed the unauthorized minting of ONE tokens, which then spread across wallets, exchanges, decentralized exchange pools and bridges.
Under the recovery plan announced on August 17, validators will retain shard 0 at block 92,730,034 and shard 1 at block 94,978,278. Both blocks carry the timestamp 11:25:37 p.m. UTC on August 11. New blocks will begin at the subsequent heights using replacement databases. Updated validator software has been configured to reject the abnormal block hashes associated with the incident.
The first confirmed forged mint entered shard 0 at block 92,730,036. Harmony selected the prior block as a clean cutoff because the intervening block contained no regular transactions, staking activity or gas usage and left the chain state unchanged. Shard 1 was included as a precaution at the matching timestamp even though the mint did not occur there.
One wallet linked to the forged mint attempted 534 transfers of 5 billion ONE each within roughly two minutes. Of those, 477 succeeded, moving 2.385 trillion ONE. Earlier tracing by the network had identified more than 10,000 downstream transactions carrying forged tokens into hundreds of wallets. Investigators later mapped the flow through standalone addresses, exchange accounts, DEX routers and pools, liquidity positions, bridge contracts, wrapped ONE and staking wallets.
An independent third-party security firm reviewed the incident separately and corroborated the forged mint as well as the primary fund-flow findings. Harmony stated that nearly all of the unauthorized supply has been traced to wallets or service boundaries and that it is coordinating with exchanges, bridges and law enforcement.
Harmony examined and rejected five alternative responses before settling on the replacement-database approach. Targeted burning or repair of the forged tokens was ruled out because the assets had already moved through exchanges, pools, contracts and thousands of wallets, raising the risk of affecting legitimate funds. Blacklisting wallets would have left the excess supply intact while potentially restricting unrelated accounts. Selective transaction replay was judged unsafe because balances, nonces, contract states and other conditions on the replacement chain would differ from those on the discarded history, producing inconsistent results. Token migration was considered more disruptive. A simple in-place chain revert was also rejected because the network’s existing revert function primarily advances the chain head without fully clearing later receipts, indexes, snapshots and cross-shard state, which could leave residual attack paths or cause validator divergence.
The replacement databases provide a single reviewed state from which consensus can resume. Client version v2026.1.2 is set to enforce the new checkpoints.
To assess the impact, Harmony constructed a full archive of shard 0 covering 141,628 consecutive blocks from the chosen cutoff through block 92,871,662. The range contained 109,126 regular transactions and 315 staking transactions. Automated activity dominated the volume: 104,545 of the regular transactions, or 95.8 percent, were classified as automated, with DEX bots alone accounting for 99,863 of them.
Only 22 transactions were simple native transfers with no obvious further dependency in the available data, yet even those were not considered automatically safe to restore. Another 860 raised questions about balances, funding sources, nonces or subsequent spending. More than 80,000 depended on contract or chain state that will change after the rollback, while the remainder were failed transactions, incident-linked activity or movements involving exchanges, bridges and consolidation paths. All 315 staking transactions rely on chain and epoch state that will no longer exist on the replacement databases.
The network is working with exchanges and bridges to evaluate the consequences of discarding post-checkpoint activity and to determine how affected parties can be addressed. At the time of the announcement, ONE carried a market capitalization of approximately $10.8 million.
Harmony previously experienced a major security event in June 2022 when its Horizon Bridge was compromised, resulting in losses of roughly $100 million. The network raised a bounty, coordinated with exchanges and law enforcement, and later faced community pushback over proposed reimbursement mechanisms that involved minting additional tokens. A separate bug in December 2023 minted about 150 million ONE to a limited set of wallets, prompting further internal disputes.
Other networks have confronted similar choices after exploits. Some executed hard forks or targeted interventions, while others debated the implications of altering confirmed history. Harmony’s plan prioritizes removal of the unauthorized supply through a controlled database replacement rather than selective adjustments that it judged operationally unsafe.
Validators are expected to adopt the updated software and replacement databases to resume production from the designated checkpoints. The network continues its investigation into the source of the forged mint while coordinating with external partners to contain remaining exposure.









