Harmony proposed rolling back its blockchain to two Aug. 11 checkpoints, discarding 109,126 transactions as the network removes forged ONE.
According to Harmony's incident update on X, validators would retain shard 0 block 92,730,034 and shard 1 block 94,978,278, both recorded at 11:25:37 p.m. UTC on Aug. 11, before restarting from replacement databases built around those checkpoints. New blocks would begin at heights 92,730,035 on shard 0 and 94,978,279 on shard 1, with client version v2026.1.2 configured to reject the abnormal block hashes linked to the incident.
The first confirmed forged mint reached shard 0 at block 92,730,036. One wallet attempted 534 transfers of 5 billion ONE each within 106 seconds, with 477 succeeding and moving 2.385 trillion ONE. Investigators traced the funds through standalone wallets, exchange accounts, DEX routers and pools, liquidity provider positions, bridge contracts, wrapped ONE, staking wallets and high-volume service wallets.
The rollback would remove all blocks created after the checkpoints, including legitimate user activity. Harmony built a shard 0 archive covering blocks 92,730,035 through 92,871,662, containing 141,628 consecutive blocks, 109,126 regular transactions and 315 staking transactions. Of the regular transactions, 104,545 (95.80 percent) were classified as automated, including 75,430 successful DEX swaps and 11,804 failed bot attempts. Only 22 were simple native transfers without an obvious dependency, but Harmony said even those could not automatically be considered safe for replay.
Harmony said it selected replacement databases over its existing in-place rewind function because the --revert tool mainly moves chain heads and does not fully clear later receipts, indexes, snapshots and cross-shard information. The team also rejected burning or repairing the forged ONE directly because the tokens had already passed through exchanges, DEX pools, contracts and numerous wallets, making removal at individual destinations risky for unrelated users. A blacklist was ruled out because it would leave the forged supply in existence while potentially restricting wallets holding legitimate assets.
The decision follows a similar exploit on Flow, which in December 2025 dropped an initial full rollback proposal in favor of targeted token burns after a $3.9 million execution-layer exploit. Humanity Protocol also disclosed in June that compromised administrative keys allowed attackers to mint additional H tokens on BNB Smart Chain.
Harmony said it has made initial progress toward tracing the hacker and is working with exchanges, bridges and law enforcement. An independent third-party security company corroborated the forged mint and the main fund-flow findings. The network previously lost about $100 million in its Horizon Bridge attack in June 2022, after which it raised its hacker bounty to $10 million.
The rollback carries structural risk for Harmony's user base. Balances, nonces, token approvals, swap deadlines, liquidity pool reserves and staking conditions will change once the replacement chain starts, meaning transactions that previously failed could succeed and swaps could generate different outcomes. Harmony cautioned that the number of discarded transactions should not be treated as the number of affected users, and said it is working with exchanges and bridges to assess how affected parties can be handled.
This article is for informational purposes only and does not constitute investment advice.