Harmony, the Layer 1 blockchain behind the ONE token, was exploited in an unauthorized mint of roughly 4 billion ONE, according to an August 12, 2026 report from crypto news account WuBlockchain. The attacker did not drain an existing pool of funds in the usual sense. They created new tokens that were never supposed to exist, inflating supply and handing themselves a balance with no cost basis.
An unauthorized mint is one of the more damaging failure modes a token can suffer. When funds are stolen from a bridge or a lending pool, the loss is bounded by what was in the pool. A mint bug has no such ceiling. The limit is whatever the attacker chooses to type, and 4 billion ONE is a large number to inject into circulating supply at once.
The mechanics of a mint exploit
Most tokens restrict who can call the mint function. That authority is meant to sit behind a locked door: a bridge contract that mints wrapped tokens only after it verifies a matching deposit, a multisig that requires several approvals, or a validator set that must agree before new units are issued. When one of those checks fails or is bypassed, an attacker can mint to their own address and then move fast to convert the fabricated tokens into something with real backing before the market reprices.
The immediate risk after any mint exploit is the same. The attacker races to sell or bridge the fake tokens into stablecoins, blue-chip assets, or another chain while liquidity still exists at the old price. Once the market absorbs the news, the token gaps down and later exits become far less profitable. That window, often measured in minutes, is where most of the realized damage happens.
Harmony's history sharpens the concern
This is not Harmony's first serious security incident. In June 2022, the project's Horizon bridge was drained of around $100 million in an attack later attributed by US authorities to North Korea's Lazarus Group. That earlier breach compromised a small set of multisig keys, and the fallout weighed on the network and the ONE token for a long time afterward. A second high-profile supply or security failure lands on a project that has already spent years rebuilding trust.
For holders, the practical questions are narrow and urgent. Whether the 4 billion figure represents the full extent of the mint or an early estimate. Whether the affected function has been paused. Whether exchanges have frozen ONE deposits to stop the attacker from cashing out. Centralized venues can act as a chokepoint here, and a fast deposit freeze is often the difference between a contained incident and a full liquidation of the fabricated supply.
Token integrity and custody are separate risks
Crypto card users and everyday spenders rarely hold a small Layer 1 token like ONE directly, so the immediate personal exposure for most readers is limited. The lesson is broader. Custodial and self-custodial products alike ultimately rest on the integrity of the underlying assets. A stablecoin whose issuer keeps tight control over minting is exactly the kind of guardrail this incident lacked. When the money itself can be conjured, no wallet design downstream can fully protect the value inside it.
It also reinforces why counterparty and protocol risk cannot be waved away with a single label. A self-custody wallet protects you from an exchange freezing your funds, but it does nothing if the token you hold is inflated to worthlessness by a broken contract. Custody choices and supply integrity are separate problems, and a serious portfolio has to account for both.
The details still to come
The details reported so far are thin, which is normal in the first hour of an active exploit. Expect the picture to sharpen quickly: an on-chain accounting of exactly how much was minted, a statement from the Harmony team, and the response from exchanges that list ONE. If deposits are halted early and the mint authority is revoked, the realized loss can stay well below the 4 billion headline. If the attacker has already bridged out, the number on the screen becomes the number that matters.
Overview
Harmony, the Layer 1 behind the ONE token, was exploited in an unauthorized mint of roughly 4 billion ONE on August 12, 2026, per WuBlockchain. Unlike a bounded pool drain, a mint exploit has no natural ceiling and inflates supply directly. The project's 2022 Horizon bridge hack, tied to the Lazarus Group, makes a second security failure especially costly for a token still rebuilding trust. Key unknowns remain: the true scale of the mint, whether the function is paused, and how fast exchanges freeze ONE deposits.



