EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Harmony plans to implement blockchain rollback after 3 trillion ONE tokens

2026-08-18 12:18:09
Bookmark

Why is Harmony rolling back its blockchain?

Harmony plans to roll back its blockchain to the state it was before last week's exploit after it has been confirmed that attackers used a vulnerability that could reuse previously valid transactions to forge more than 3 trillion ONE tokens. The first-level blockchain means that the verifier will roll back the two chains that make up its sharding network-sharding 0 and sharding 1-to the state they were before the confirmed unauthorized casting occurred. Subsequent blocks and transaction records will be discarded to remove counterfeit tokens from the blockchain state. The project considers multiple alternatives, including destroying unauthorized ONE, blacklisting wallets that receive tokens, and migrating to new versions of tokens. Harmony ultimately believes that these options are riskier because counterfeit assets are already flowing through exchanges, decentralized financial agreements and cross-chain bridges. Harmony said: "Among the scenarios we studied, a fixed rollback window is the fairest and most secure. It applies the same rules to everyone, removes forged status, and has the lowest risk of being attacked again or failing consensus. "Rollbacks are a highly disruptive response because legal transactions completed after a block is selected also disappear. As a result, users and applications may need to reconcile balances or re-execute transactions after the network is restored from its early state.

How were more than 3 trillion ONE tokens created?

Harmony first confirmed the exploit on August 12 after discovering unauthorized ONE casting. An independent researcher initially discovered that 4 billion tokens had been created from empty blocks, but the project later discovered that the activity was much larger. A subsequent reconstruction found that 3.01 trillion counterfeit ONE tokens were created through six transactions and sent to four attacker wallets. One of the wallets successfully transferred nearly 2.4 trillion ONE in less than two minutes, worth nearly $3 billion at pre-attack prices. The vulnerability involves Harmony's cross-shard receipt verification system. Valid receipts can reportedly be processed multiple times, allowing attackers to reuse the same transaction record to generate additional ONE tokens without having to make corresponding deductions in other parts of the network. This effectively allows new supplies to be created without the support of economic activity. Harmony patched the vulnerability on August 12 after detecting the attack, preventing the same method from being used again.

Investor Points

Rollback removes forged supplies at the blockchain level, but it also reverses legitimate activity recorded after the block is selected. Therefore, for ONE holders, the current problem is not only the exploit itself, but also whether Harmony can successfully restore balances, applications and cross-chain activities after rewriting some of its online transaction history.

Why can't Harmony just destroy the fake ONE?

Harmony said it has traced almost all unauthorized tokens to wallets or services, but tracing does not mean they can be safely destroyed. After exploiting the vulnerability, a large number of counterfeit tokens have been circulated through decentralized exchanges, liquidity pools and cross-chain bridges. Once counterfeit tokens are exchanged with legitimate assets or mixed with liquidity provided by other users, destroying the balance associated with the attack could transfer losses to people who were not involved. Blacklisting also has similar problems. Received ONE's wallet from an attacker and may then send the token to another trader, protocol, or centralized service. Freezing every address in the transaction chain could affect legitimate users and create confusion as to which balances are still available. Token migration can isolate contaminated supplies, but requires exchanges, wallets, protocols and users to migrate to new assets. Harmony ultimately chose to restore the entire network to its known state before the exploit, accepting the cost of reversing subsequent transactions to remove the counterfeit supply in one step.

What does rollback mean for Harmony?

The decision focuses on whether Harmony can coordinate validators, exchanges, cross-chain bridge operators and decentralized applications around rolling back operations without creating additional balance differences. The most important issue for users is determining which transactions occur after the rollback point and whether deposits, withdrawals, conversions, or cross-chain bridge transfers need to be re-executed. Services that credit ONE based on transactions that have been removed from the chain may also need to reconcile internal records. This incident also exposed the risks posed by cross-sharding infrastructure. Harmony's architecture spreads activity across multiple shards to increase capacity, but communication between shards relies on an authentication mechanism that must ensure that the same transaction is not processed twice. The vulnerability has now been fixed, but restoring blockchain does not automatically restore confidence. Harmony needs to prove that the underlying receipt verification failure problem has been completely resolved and that similar repeated attacks can no longer create additional supply. The rollback may have eliminated the counterfeit ONE from the official chain status, but the long-term test will be whether users, verifiers and liquidity providers will accept the reversal and continue to use the network after one of the largest unauthorized coin minting events in history.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP