The team behind the Harmony blockchain project has announced preparations for a radical network recovery following an incident in which attackers managed to unauthorizedly generate about 4 trillion ONE tokens. Instead of piecemeal measures, I decided to break down why developers chose a rollback to the state before the exploit and what risks this poses for the ecosystem.

Technical details of the recovery

Unified checkpoints have been selected for both shards: Shard 0 — block #92,730,034, Shard 1 — block #94,978,278. Both correspond to August 11, 2026, 23:25:37 UTC. Validators will receive new databases, after which the chain will continue operating from subsequent blocks. This solution removes all assets generated by fraudsters, minimizing the risk of damage to legitimate funds.

Why alternatives were rejected

Three main scenarios were considered, but each proved unacceptable. Targeted token burning is too risky: counterfeit ONE has already mixed with legitimate tokens through exchanges, DEXs, liquidity pools, and bridges. A blacklist of addresses does not eliminate the issuance itself and could block innocent wallets. Selective transaction recovery is dangerous due to dependence on the state of smart contracts: the same operation could yield a different result after the blockchain is altered.

The root of the problem and the scale of damage

The root cause is a vulnerability in the cross-shard transaction confirmation mechanism that allowed already-used receipts to be reprocessed. Additionally, a bug was found in the quorum verification for BLS signatures. According to a preliminary model, more than 99.9% of counterfeit ONE was tracked, but this does not provide a way to safely destroy them. The team has already shared address lists with exchanges and LayerZero, cooperating with law enforcement.

The cost of the rollback for users

An analysis of 141,628 blocks on Shard 0 showed that out of 109,126 regular transactions, only 22 were simple transfers without dependencies, but even those were not deemed safe to restore. More than 80,000 operations depended on the state of contracts, making selective recovery impossible. The network is halted at block #92,753,555, and the final launch depends on the consent of validators and exchanges.

My comment: Harmony's decision is a classic example of the "lesser evil" in crisis management. The rollback will erase legitimate transactions but leaves a chance to preserve trust in the network. However, the incident exposes a systemic problem: cross-shard architecture requires stricter verification mechanisms, otherwise such attacks will become a trend for other multichain projects.