A large-scale incident involving unauthorized issuance on the Harmony network forced the team to take radical measures. I have analyzed the situation and can confirm: the developers have decided to roll back the blockchain to a state preceding the exploit, during which attackers managed to generate approximately 4 trillion ONE tokens. This is an unprecedented step that will affect not only fraudulent assets but also a significant layer of legitimate transactions.

Technical details of the recovery

Unified checkpoints have been selected for both shards. Shard 0 will be restored to block #92,730,034, and Shard 1 to block #94,978,278. Both of these blocks date to August 11, 2026, at 23:25:37 UTC. It is at these heights that validators will receive new databases, after which the network will continue operating from subsequent blocks. This approach allows for the uniform removal of all counterfeit assets while minimizing the risk of damage to user funds.

Why burning did not work

At first glance, it would have been more logical to simply burn the stolen tokens. However, my analysis shows why this is impossible. The counterfeit ONE has already passed through exchanges, decentralized platforms, liquidity pools, and bridges. After mixing with legitimate funds, targeted destruction would have become a time bomb—it would have affected other people's assets. Blacklists are also ineffective: they do not eliminate the issuance and block innocent users. Selective transaction rollback is an even riskier path, since changing the blockchain state alters the outcomes of swaps, staking, and contracts.

Scale of damage and vulnerabilities

The root cause of the attack was a bug in the cross-shard transaction confirmation mechanism, which allowed already-used receipts to be reprocessed. Additionally, an issue was identified with quorum verification for BLS signatures—a zero signature could pass validation. A preliminary model showed that more than 99.9% of counterfeit ONE could be traced, but this does not provide a safe way to destroy them. Address lists have already been shared with exchanges and LayerZero, and cooperation with law enforcement is ongoing.

The rollback will affect tens of thousands of operations. Of the 109,126 transactions in Shard 0, only 22 were simple transfers without dependencies, but even these were deemed unsafe to preserve. The rest depend on the state of smart contracts, making selective recovery impossible.

My conclusion: Harmony chose the least bad option. Although the rollback is a painful blow to trust in the network, it is preferable to the chaos that partial preservation would have created. However, investors should prepare for volatility: such incidents undermine confidence in the security of cross-shard architectures, and reputation recovery will take months.