Harmony’s Recovery Strategy
Blockchain platform Harmony has unveiled a strategy to revert its network to two checkpoints established on August 11. This recovery approach will result in the elimination of over 109,000 regular transactions to erase a fraudulent mint of ONE tokens resulting from a security breach.
Details of the Checkpoints
In a detailed update shared on social media platform X, Harmony stated that the validators will retain records from shard 0’s block 92,730,034 and shard 1’s block 94,978,278, both logged at 11:25:37 PM UTC on that date. Following this, a new blockchain will commence from these designated points, with block heights of 92,730,035 for shard 0 and 94,978,279 for shard 1.
Implementation of Client Version
To combat the effects of the fraudulent activity, Harmony has implemented client version v2026.1.2, which has been programmed to reject abnormal block hashes related to this incident. This will prevent validators from considering any impacted chain history after the network is restarted. The first instance of the forged mint was noted at shard 0’s block 92,730,036, while block 92,730,035, which will be preserved, did not have any regular or staking transactions and remained unchanged from its predecessor.
Precautionary Measures
Harmony opted to maintain block 92,730,034 as a precautionary measure, creating a buffer and ensuring that recovery procedures, scripts, and databases were all in place. Shard 1 remained unaffected by the fraudulent mint, and its checkpoint was included for safety reasons corresponding to the same time.
Alternative Recovery Options
In contrast to standard practices, Harmony chose to bypass its existing rewind functionality. This typical revert operation primarily alters chain heads without fully clearing subsequent receipts and information, which could leave pathways for continued attacks or inconsistencies among validators. Instead, the substitution of the entire shard databases was deemed more secure and efficient, allowing for a unified reviewed state for consensus.
The exploration of various recovery options was extensive, including the idea of either destroying or repairing the forged ONE tokens. However, the tokens had circulated through numerous exchanges and wallets, complicating any attempts to isolate them without adversely impacting legitimate users’ assets. Other methods, such as blacklisting or selectively replaying transactions, were also dismissed due to the risks associated with the integrity of the chain state and the potential for unwarranted restrictions on genuine asset holders.
Impact on Regular Transactions
Token migration was another avenue considered but deemed potentially disruptive. Harmony’s decision to proceed with a rollback comes in light of similar challenges faced by another blockchain, Flow, which adjusted its own rollback strategy after an exploit in December 2025.
Within the context of regular transaction impacts, Harmony meticulously constructed a shard 0 archive, carefully analyzing blocks from 92,730,035 to 92,871,662. This detailed review revealed a substantial volume of automated activity, with 95.80% of the regular transactions being automated. The team underscored that the discarded transaction tally does not equate to the number of users affected.
Assessment of Reinstating Transactions
Upon assessing whether certain regular transactions could be reinstated post-rollback, the team’s findings indicated that while a few simple transfers might be viable, numerous others entailed complications that precluded their safe playback. The implications of the rollback also extend to all staking transactions that would be altered by the new chain state.
Investigation into Fraudulent Minting
Harmony’s analysis revealed patterns in the fraudulent minting incident, tracing movements of the forged ONE tokens, including a particular wallet that attempted 534 transactions in rapid succession. Investigators segmented the transactions into successful moves, failed attempts, and later transfers across various addresses, aggregating the impacted funds methodically.
Despite efforts to trace the stolen assets back to their origins, the team cautioned against assuming that all transaction routes could lead to identifying the individuals responsible for the malicious actions as the landscape involved several service clusters and user accounts.
Collaboration and Verification
The investigation’s progress continues as Harmony collaborates with law enforcement and exchanges to address the implications of the rollback on affected users. Additionally, a third-party security firm has independently verified the findings and endorsed the analytical conclusions.