Harmony is preparing one of the more drastic recovery moves seen on a layer-1 blockchain this year. After an attacker allegedly forged billions of ONE tokens out of thin air, the network’s core team proposed a Harmony blockchain rollback that would wind the chain back to two checkpoints from August 11, wiping out more than 109,000 regular transactions in the process. The plan, detailed in Harmony’s latest incident update, is the network’s attempt to erase counterfeit supply without triggering a bigger mess for everyday users caught in the crossfire.
Summary
Key takeaways
- Harmony wants to roll its blockchain back to shard 0 block 92,730,034 and shard 1 block 94,978,278, both timestamped 11:25:37 p.m. UTC on August 11.
- The rollback would discard more than 109,000 regular transactions and 315 staking transactions recorded after those checkpoints.
- Roughly 95.8% of the affected transactions came from automated activity, mostly decentralized exchange bots.
- One attacker wallet moved 2.385 trillion forged ONE through 477 successful transfers in just 106 seconds.
- ONE’s price fell about 40% after the incident, as the attacker allegedly minted close to 4 billion tokens, equal to more than a quarter of existing supply.
Harmony’s Rollback Plan Targets Two August 11 Checkpoints
Harmony’s recovery plan hinges on preserving two specific blocks and discarding everything that came after them. Validators would keep shard 0 block 92,730,034 and shard 1 block 94,978,278, both recorded at 11:25:37 p.m. UTC on August 11, and then restart the network from replacement databases built around those points. New blocks would resume at height 92,730,035 on shard 0 and 94,978,279 on shard 1.
The timing matters. Harmony said the first confirmed forged mint hit shard 0 at block 92,730,036, and block 92,730,035 itself contained no transactions, receipts or gas usage, meaning its state matched the previous block exactly. That gap gave the team a one-block safety buffer, and Harmony noted that changing the checkpoint at a later stage risked leaving validators working from inconsistent recovery targets since scripts and procedures had already been built and tested around block 92,730,034. Shard 1 wasn’t where the exploit occurred, but Harmony added its own checkpoint at the same timestamp purely as a precaution.
To stop the old chain history from resurfacing, Harmony configured client version v2026.1.2 to reject the abnormal block hashes tied to the incident, blocking validators from reaccepting the compromised chain after the restart.
Why Replacement Databases, Not a Simple Rewind
Rather than use its existing in-place rewind function, Harmony chose to replace the affected shard databases entirely. The team explained that the standard revert function mainly shifts chain heads without fully clearing later receipts, indexes, snapshots and cross-shard data, and leaving that residue behind could preserve an attack route or cause validators to land on different states. A freshly built database, Harmony said, gives every validator a single reviewed starting point for resuming consensus, closing off that risk entirely.
Why Harmony Rejected Blacklists, Burns and Selective Replays
Harmony considered several less disruptive fixes before settling on a full rollback, and ruled each one out for a specific reason. Burning or repairing the forged ONE directly was dismissed because the tokens had already scattered across exchanges, decentralized exchange pools, contracts and countless wallets, meaning any attempt to strip them out at each destination could catch legitimate holders in the process.
A blacklist approach was also rejected. It would have left the forged supply technically intact while still risking legitimate wallets that happened to hold tainted funds. Selectively replaying only the “clean” transactions was ruled out too, since the replacement chain’s state would differ from the discarded one, meaning identical transactions could produce different results the second time around. Token migration came up as another option but was judged likely to cause even more disruption than the rollback itself.
Lessons from Flow’s Own Rollback Debate
Harmony isn’t the first network to wrestle with this trade-off. In December 2025, Flow revised its own rollback plans after a $3.9 million execution-layer exploit, abandoning an initial full rollback in favor of targeted token burns once bridge operators and other participants raised concerns about the fallout for legitimate activity. Flow instead opted for a phased network restart alongside restrictions on flagged accounts, a path Harmony ultimately decided wouldn’t fully solve its own problem.
Just How Many Transactions Are at Stake
The scale of what’s being discarded is significant on paper, but Harmony is careful to note it doesn’t equal the number of people affected. To measure the impact, the team built a shard 0 archive spanning blocks 92,730,035 through 92,871,662, covering 141,628 consecutive blocks. That dataset held 109,126 regular transactions and 315 staking transactions, with 109,441 exact transaction-to-receipt matches confirmed for parent-hash continuity and completeness.
Of those regular transactions, 104,545 — or 95.80% — were automated, and decentralized exchange bots alone accounted for 99,863 transactions, split between 75,430 successful swaps and 11,804 failed attempts. This is one of the clearer “why this matters” moments in the whole episode: because bot activity dominates the dataset, the real number of human users losing legitimate transaction history is likely far smaller than the headline figure suggests.
Harmony also checked whether any transactions could simply be restored after the rollback. Only 22 turned out to be simple native transfers with no obvious dependency, and even those weren’t automatically considered safe to replay. Another 860 native transfers raised questions around balances, funding sources, nonces or later spending, while 80,630 transactions depended on contract or blockchain state. A further 27,614 were failed transactions or incident-linked movements through exchanges, bridges and consolidation routes. All 315 staking transactions depend on chain and epoch state as well, meaning nothing in that category can be cleanly separated from the reset.
Harmony flagged that balances, nonces, token approvals, swap deadlines, liquidity pool reserves and staking conditions will all shift once the replacement chain goes live — a transaction that failed the first time could succeed under the new state, and vice versa. Full EVM traces weren’t available through the RPC data used for the review either, so internal contract transfers and storage changes still need application-specific analysis.
Chasing the Forged ONE Across Exchanges and Bridges
Investigators have separately mapped how the counterfeit tokens spread once they existed. One wallet linked to the forged mint attempted 534 transfers of 5 billion ONE each within a 106-second window, and 477 of those transfers succeeded, moving a combined 2.385 trillion ONE. That speed is central to why a targeted cleanup was never realistic — the funds reached standalone wallets, exchange accounts, DEX routers and pools, liquidity provider positions, bridge contracts, wrapped ONE, staking wallets and high-volume service wallets almost immediately.
To untangle the mess, investigators built a time-ordered graph starting from the wallets tied to the forged mints, separating signed transactions from successful transfers, failed attempts and later movements through other addresses, checked against blocks and balances through shard 0 block 92,805,850. When forged ONE mixed with legitimate assets in the same wallet, the model followed transfers chronologically and capped the attributed amount at each wallet’s available balance, preventing the same tokens from being double-counted as they hopped between addresses.
Even with that mapping in place, Harmony acknowledged that the amount of forged ONE that can actually be safely destroyed is smaller than the amount traced. Tokens sitting untouched in a standalone wallet may be isolated, but once ONE entered an exchange account, liquidity pool, bridge or staking position, removing it in full without touching unrelated users’ funds becomes far harder — and in many cases, impossible without collateral damage. A similar dilemma played out in June, when Humanity Protocol disclosed that compromised administrative keys let attackers seize bridge infrastructure and mint extra H tokens on BNB Smart Chain, prompting a halt of affected bridge operations while investigators tracked the stolen assets.
Investigation Continues With Law Enforcement and Security Firms
Harmony said it’s made initial progress tracing the hacker and is working with exchanges, bridges and law enforcement to preserve records and keep the investigation moving. An independent third-party security company reviewed the incident separately and corroborated both the forged mint and the main findings of the fund-flow analysis, according to the network.
This isn’t Harmony’s first major security scare. Its Horizon Bridge lost roughly $100 million in June 2022 after attackers compromised the private keys controlling it, an attack the FBI later attributed to North Korea’s Lazarus Group. Harmony worked with exchanges, law enforcement and blockchain analytics firms afterward, eventually raising its hacker bounty to $10 million. Stolen funds from that hack kept moving for months — in January 2023, on-chain investigators tracked stolen ETH through hundreds of addresses, and Binance and Huobi froze linked accounts, recovering 124 BTC. Harmony also had a smaller incident in late 2023, when a staking-system bug improperly minted about 146.3 million ONE across 74 addresses; the network handled that one with an emergency patch and blacklisted wallets, a far more contained fix than what’s needed this time.
For now, Harmony is working directly with exchanges and bridges to figure out how discarded post-checkpoint activity should be handled and how affected parties might be compensated or supported. The team has been clear that every block created after the two checkpoints will be removed under the proposed Harmony network recovery plan, regardless of whether the transaction in question had anything to do with the forged mint itself.
FAQ
Why is Harmony rolling back its blockchain?
Harmony plans to roll back to two checkpoints dated August 11 to remove forged ONE tokens created through a mint that compromised the blockchain.
How many transactions will be discarded in the rollback?
More than 109,000 regular transactions and 315 staking transactions will be discarded to reset the blockchain state before the forged tokens were created.
Why didn’t Harmony choose alternatives like blacklisting or token burns?
Harmony rejected blacklisting and token burns because forged tokens had already moved through exchanges and wallets, risking legitimate user funds and inconsistent blockchain states.
How is Harmony handling the investigation and recovery?
Harmony is collaborating with exchanges, bridges, law enforcement, and a third-party security firm to trace the hacker, assist recovery, and preserve records.
Article produced with the assistance of artificial intelligence and reviewed by the editorial team.

