The team behind the Harmony blockchain project has made a radical but necessary decision: a full network rollback to the state preceding the exploit, during which attackers unauthorizedly generated approximately 4 trillion ONE tokens. This is one of the largest incidents of counterfeit issuance in the history of the industry, and its consequences require surgical precision.

The developers chose a single recovery point for both shards to uniformly remove the fabricated assets and minimize the risk of damaging legitimate user funds. This refers to block #92 730 034 in Shard 0 and block #94 978 278 in Shard 1, both corresponding to August 11, 2026, 23:25:37 UTC. Validators will receive new databases from these heights, after which the chain will continue operating from subsequent blocks.

Why burning and blacklists don't work

At first glance, it would seem more logical to simply destroy the stolen tokens or freeze the hackers' addresses. However, my analysis shows that this is technically impossible without catastrophic side effects. The counterfeit ONE tokens have already passed through exchanges, decentralized platforms, liquidity pools, and bridges, mixing with clean assets. Targeted burning after such mixing would inevitably affect other people's funds, and a blacklist does not solve the problem of already-created issuance and could block innocent parties.

Moreover, selective transaction rollback is a trap. After changing the blockchain state, the same operation could yield a completely different result, especially for swaps, staking, and reserves. Therefore, the only safe path became a single rule: all blocks after the checkpoints are discarded, even if they contain legitimate transfers.

Technical details of the attack and scale of damage

The root of the problem is a vulnerability in the cross-shard transaction confirmation mechanism that allowed already-used receipts to be reprocessed. Additionally, a bug was found in the quorum verification for staking committees, where a zero BLS signature could pass validation. The team is currently determining whether it was directly used in the attack.

A preliminary model shows that more than 99.9% of the fake ONE tokens were traced to specific wallets or service boundaries. However, as I already noted, successful monitoring does not provide the ability to safely destroy these tokens. The address lists have been shared with exchanges and LayerZero, and cooperation with law enforcement is underway.

The cost of the rollback: tens of thousands of transactions affected

The scale of losses is significant. An analysis of 141,628 consecutive Shard 0 blocks revealed 109,126 regular and 315 staking transactions. Of these, only 22 were simple ONE transfers without dependencies, but even those cannot be safely restored. More than 80,000 operations depended on the state of smart contracts, while the rest were linked to exchanges, bridges, or errors. After the rollback, balances, reserves, and approvals will change, making selective restoration too risky.

The network has been halted at block #92 753 555, and the final launch depends on the consent of validators and exchanges. This is a painful but necessary step to preserve the integrity of the protocol.

My expert opinion: the rollback is an acknowledgment that the security of cross-shard communications was fundamentally compromised. Investors should view this as a signal of systemic risks, not a one-off failure. Restoring trust will require not only technical fixes but also a reassessment of the risk management model.