The team behind the Harmony blockchain project has made a radical decision: the network will be rolled back to a state preceding the exploit, during which attackers unauthorizedly generated approximately 4 trillion ONE tokens. This is one of the most large-scale incidents of supply forgery in the history of the industry, and its consequences require immediate intervention.

Technical details of the rollback and checkpoints

The recovery will affect both shards of the network. The developers chose a single point in time for the rollback to eliminate desynchronization and minimize the risk of damaging legitimate assets. Checkpoints have been set at the following heights:

  • Shard 0 — block #92 730 034;
  • Shard 1 — block #94 978 278.

Both blocks correspond to August 11, 2026, 23:25:37 UTC. After validators install the new databases, the network will continue operating from blocks #92 730 035 and #94 978 279, respectively. This means that all transactions made after the specified moment will be discarded, including potentially legitimate operations.

Why burning or blacklists did not work

At first glance, the targeted destruction of counterfeit tokens seemed like a more obvious solution. However, this path turned out to be a dead end. The ONE issued by the fraudsters had already passed through exchanges, decentralized platforms, liquidity pools, bridges, and thousands of wallets. After mixing with legitimate funds, it became impossible to accurately identify and burn only the illegitimate volume without risking other people's assets.

Address blacklists were also rejected: they do not eliminate the already created supply and could block wallets unrelated to the attack. Selective transaction recovery, considered as a third option, carries a fundamental problem: after changing the blockchain's state, the same operation could lead to a different outcome. This is critical for swaps, staking, and smart contracts, where the result depends on the network's prior state.

The root of the vulnerability and the scale of damage

The root cause of the attack was a vulnerability in the mechanism for confirming cross-shard transactions. The bug allowed already-used receipts to be processed again, which enabled attackers to generate tokens. Additionally, a problem was found in the quorum verification for staking epoch committees: under certain conditions, a zero BLS signature could pass verification. Whether this bug was directly used in the attack has not yet been established.

According to a preliminary model, more than 99.9% of the counterfeit ONE were traced to specific wallets or service boundaries. However, as the developers emphasize, successful monitoring does not provide the ability to safely destroy these tokens. Lists of addresses linked to the incident have already been shared with exchanges and LayerZero, and cooperation with law enforcement agencies is also underway.

Impact on users and prospects

The rollback will affect tens of thousands of transactions. Analysis of 141,628 consecutive Shard 0 blocks revealed 109,126 regular and 315 staking operations, of which 99,863 were on DEXs. Only 22 operations were simple transfers without dependencies, but even these were not considered safe to restore. After the rollback, balances, pool reserves, and staking states will change, making selective recovery extremely risky.

The network remains in recovery mode: Shard 0 is halted at block #92 753 555. The final launch depends on validator consensus and the fulfillment of technical conditions.

My analysis: This is a precedent-setting case that highlights the fragility of cross-shard communications in multichain architectures. The rollback is a painful but the only safe solution in this situation, yet it raises a fundamental question about trust in blockchain immutability. Investors should closely monitor market reaction and the readiness of validators to coordinate.