
A potential rollback by Harmony would mean returning the network to a state before the exploit and continuing from that point, effectively removing transactions that occurred afterward from the blockchain’s accepted history. Imagine this as being allowed to undo a chess move that led to checkmate and restart from an earlier, safer position on the board.
That can prevent an attacker from keeping newly created tokens still on the network, but becomes harder once funds have reached exchanges or moved onto other systems. Many in the industry, however, view a rollback as antithetical to blockchain’s core principle of immutability.
The apparent exploit comes a day after Ravencoin, another smaller blockchain built from Bitcoin’s code, faced its own possible rollback after parts of its network accepted invalid blocks.
In that case, miners moved to rebuild the chain from before the flaw, putting several days of transactions at risk of reversal. Ravencoin is separate from Harmony, but the two incidents show the trade-off involved in a rollback – that undoing an attack can also undo legitimate transactions made after it.
Not the first hit
Harmony has dealt with unauthorized creation of ONE before.
In December 2023, a bug in its staking system caused about 146.3 million ONE to be created when tokens that should have stopped receiving payouts continued to receive them. Harmony said at the time that 74 addresses were involved, with one receiving 51.2 million ONE, and that about 16.4 million was subsequently moved to an exchange.


