Harmony plans to roll back its blockchain to a point before last week's exploit after confirming more than 3 trillion of its native ONE tokens were forged. The Layer 1 network says validators will reset Shard 0 and Shard 1 to just before the forged mint, discarding every block and transaction after that point.
Harmony will roll back its Layer 1 blockchain after concluding that an attacker forged more than 3 trillion ONE tokens. Validators will reset Shard 0 and Shard 1, the two chains making up its sharded network, to the point just before the confirmed forged mint, discarding every block and transaction after that point.
The team weighed several fixes before settling on the rollback. It considered burning the forged tokens, blacklisting the wallets that received them, and even migrating ONE to a new token, but concluded the rollback carries the least risk. According to Harmony: "one fixed rollback window is the fairest and most secure".
3 trillion forged ONE
Harmony first confirmed the exploit on Aug. 12 after discovering unauthorized minting of ONE. An independent researcher initially identified 4 billion tokens minted through empty blocks, but Harmony later found that was only the first wave. A later reconstruction found 3.01 trillion ONE forged across six transactions into four exploiter wallets.
One of those wallets moved nearly 2.4 trillion ONE, worth almost $3 billion at pre-attack prices, in under two minutes. Harmony says it has traced nearly all the forged tokens to wallets or services, though many passed through DEX pools and bridges, making them difficult to recover or burn without affecting innocent users.
Root cause patched
The exploit reportedly stemmed from a flaw in Harmony's cross-shard receipt verification, which let the attacker process valid receipts multiple times and mint new ONE without any offsetting debit. Harmony patched the vulnerability on Aug. 12, the same day the attack was discovered.
Source: The Block
Trading involves risk.