Harmony's ONE token fell 40 percent in Asian morning trading Wednesday after an apparent exploit generated approximately 4 billion new tokens.

The newly minted tokens represent more than a quarter of Harmony's existing supply. Prior to the incident, total ONE supply stood at roughly 15 billion tokens.

Harmony confirmed the attack and immediately instructed network operators to install an emergency software update to prevent further unauthorized minting.

Harmony also paused its token bridge and formally requested that all cryptocurrency exchanges block and freeze funds traced to four specific wallet addresses, including one1uap8dx2z0qsjxqthm5flgcxkeepsz3gsrghnfn and 0xe7427699427821230177dd13f460d6ce43014510.

The team is working on a patch and exploring rollback options. A rollback would revert the blockchain to its state before the exploit, erasing all transactions that occurred after the attack. Rollbacks grow more complex once funds move off-chain to exchanges or other platforms, and much of the broader blockchain community views them as contrary to the principle of immutability.

Harmony functions as a Layer 1 blockchain built for decentralized finance protocols and marketplaces. Its native ONE token pays for network transactions and helps secure the chain. The project's market capitalization peaked at $4 billion in Jan. 2022.

On-chain data shows roughly 2.8 billion of the unauthorized tokens have already moved toward exchanges. The attacker retains approximately 115 million ONE on-chain—about 2.9 percent of the total minted amount.

This is not the first unauthorized token creation on Harmony. In December 2023, a bug in its staking system erroneously created 146.3 million ONE tokens across 74 addresses, with one address receiving 51.2 million ONE and 16.4 million subsequently transferred to an exchange.

The exploit follows a similar incident on Ravencoin one day earlier, where network components accepted invalid blocks and the project weighed a potential rollback. Both cases expose the hard trade-off between undoing an attack and reversing legitimate transactions.