Harmony will discard 141,628 blocks containing 109,126 transactions when validators roll its chain back to a state recorded at 23:25:37 UTC on August 11, according to a plan the project published on August 17.
The chain will restart from block 92,730,034 on shard 0, two blocks before the first confirmed forged mint.
Chain Restarts From Block 92,730,034
Validators will keep block 92,730,034 on shard 0 and block 94,978,278 on shard 1, both timestamped 23:25:37 UTC on August 11, and install replacement databases at those blocks. New blocks will be created at heights 92,730,035 and 94,978,279. Client version v2026.1.2 rejects the problematic block hashes.
The first confirmed forged mint entered shard 0 at block 92,730,036, according to the plan. Harmony said block 92,730,035 contained no regular transactions, no staking transactions, no incoming receipts, and no gas use, and held the same state as the block before it, so the project selected 92,730,034 as a one-block safety buffer.
The forged mint occurred on shard 0. Shard 1 is included only as a precaution at the same timestamp.
Only 22 Transactions Had No Obvious Dependency
Harmony said it built a complete shard-0 archive covering blocks 92,730,035 through 92,871,662, containing 141,628 consecutive blocks, 109,126 regular transactions, 315 staking transactions, and 109,441 exact transaction-to-receipt matches.
Of those regular transactions, 104,545, or 95.80%, were automated. Automated decentralized exchange activity accounted for 99,863 transactions, including 75,430 successful swaps and 11,804 failed bot attempts. Harmony noted that transaction count is therefore not the same as user count.
The project said it tested whether transactions could be restored selectively and concluded they could not. Only 22 of the 109,126 regular transactions were simple native transfers with no obvious dependency in their data, and Harmony said that still does not make them safe to restore. A further 860 native transfers carried balance, funding, nonce, or later-spend questions; 80,630 transactions depended on contract or chain state; and 27,614 were failed, incident-linked, or crossed exchange, bridge, or consolidation paths. All 315 staking transactions depend on chain and epoch state.
Balances, nonces, swap deadlines, approvals, pool reserves, and staking state will all change after the rollback, according to the plan, meaning a transaction that failed before could succeed on the replacement chain, and a swap, approval, or staking action could produce a different result.
Project Rejected Five Alternatives
Harmony said it considered a targeted burn or repair and rejected it because minted ONE moved through exchanges, pools, contracts, and many wallets, so a targeted change could affect unrelated funds. A blacklist was rejected because it would not remove the forged mint and could block unrelated wallets.
Selectively replaying transactions was rejected because changing the chain state means the same transaction can produce a different result, and the project said there is no safe or fair way to choose which to restore. Token migration was rejected as causing wider disruption.
A simple in-place database rewind was also ruled out. Harmony said its existing revert function mainly moves chain heads and does not fully remove later receipts, indexes, snapshots, or cross-shard data, and that leftover state could reopen an attack path or cause validators to disagree.
The project said a replacement database for each shard gives validators one reviewed recovery state and keeps recovery steps simple, and that of the options studied, one fixed rollback window applies a single rule to everyone and carries the lowest risk of another attack or consensus failure.
One Wallet Moved 2.385 Trillion ONE in 106 Seconds
One forged-mint wallet attempted 534 transfers of 5 billion ONE each within 106 seconds, according to Harmony. Of those, 477 succeeded, moving 2,385,000,000,000 ONE.
Harmony said it built a time-ordered graph starting from all forged-mint wallets, separating transactions signed by those wallets, successful transfers, failed attempts, and later movement through other wallets, and checked traced transfers against block data, transaction receipts, and balances through shard-0 block 92,805,850.
The trace followed native ONE into standalone wallets, exchange wallets, decentralized exchange routers and pools, liquidity provider positions, bridge contracts, wrapped ONE, staking wallets, and high-volume service wallets. Where forged ONE was mixed with other funds, Harmony said it followed transfers in time order and limited the traced amount to each wallet’s available balance to avoid counting the same funds again at every later transfer.
Traceable Does Not Mean Recoverable
Harmony said an earlier flow model routed more than 99.9% of the forged ONE to a wallet or service boundary, and a later model reconciled almost 100% across those boundaries and transaction fees at the same cutoff. It then set out what those figures do not mean.
Traceable to a wallet or cluster means the route can be followed to a wallet, pool, contract, exchange, bridge, validator, or service, the project said. Traceability to an individual requires stronger proof, because a cluster or service wallet may represent many unrelated users. Safely burnable is smaller again: forged ONE that stayed untouched in a standalone wallet may be isolated, but once it entered a centralized exchange wallet, a decentralized exchange pool, a liquidity provider position, a bridge contract, or a staking position, burning the full traced amount could take unrelated funds or damage the service.
The near-100% figures describe route coverage and do not mean nearly all forged ONE can be tied to specific people or safely burned, Harmony said.
Investigation Continues With Exchanges and Law Enforcement
Harmony said it has made initial progress tracing the attacker and is working with exchanges, bridges, and law enforcement to continue the investigation and preserve records. It said an independent third-party security firm separately reviewed the incident and corroborated the forged mint and the main fund-flow findings, without naming the firm.
The project said available RPC data does not include full EVM traces, so internal contract transfers and storage changes still require application-specific review. It said it is working with exchanges and bridges to assess impact.
Harmony thanked seven validators for testing the shard-0 and shard-1 recovery scripts across different hardware and setups and directed validators to a recovery checklist published in its GitHub repository.
Third On-Chain Security Event Since 2022
The Crypto Times reported the suspected mint on August 12, when Harmony published four wallet addresses and asked exchanges to freeze funds traced to them. Blockchain security firm SlowMist put the realized loss at approximately $3.2 million based on what the attacker extracted through on-chain sales before liquidity dried up, as covered in our weekly summary.
An attacker drained approximately $100 million from Harmony’s Horizon bridge in June 2022 after compromising validator private keys, an incident the FBI later attributed to North Korea’s Lazarus Group. The project offered a bounty and later proposed minting new ONE to reimburse affected users.
