Harmony's Forged Mint Took 106 Seconds

The attack on Harmony lasted 106 seconds. Inside that window late Tuesday, someone minted ONE tokens the network never should have issued, working through the messaging layer that connects Harmony's shards. The forged mint executed before 23:25:37 UTC and was first detected at block 92,730,036 on Shard 0; the activity touched Shards 0 and 1. On-chain analyst Juiceberg flagged it publicly at about 9:42 PM ET. Harmony itself had not issued a statement at the time of writing, and the most important number in the story, how much ONE was created, exists only as one analyst's estimate.
A receipt with nothing behind it
Harmony splits its chain into shards, parallel segments that each process their own transactions. Moving tokens between shards works by receipt: the sending shard debits a balance, and the receiving shard credits it once shown proof that the first half happened. The early read of Tuesday's attack is that this proof step failed. Receipts passed verification without a matching debit anywhere, so the receiving shard credited tokens that came from nothing. That account comes from the first on-chain analysis, not from Harmony, and the precise defect in the receipt checks had not been confirmed by the network's engineers as of Tuesday night. What the block data does show plainly is the speed. From first forged credit to last, the window spans 106 seconds.
One analyst's count
The only size estimate circulating Tuesday night was Juiceberg's: roughly 4 billion ONE, which would be about 26% of a circulating supply near 15 billion. The same analysis put around 2.8 billion of it, roughly 70%, on exchanges already. Both figures are a single researcher's real-time reading of the chain. Harmony had not confirmed them, and no second tally existed at the time of writing. The count stands unverified. Incident math this early usually rests on tracing token flows across thousands of transactions while they are still moving, so the figure to hold onto is the verified one: the timestamp boundary at 23:25:37 UTC, before which every forged token was created.
The market did not wait for confirmation
ONE fell more than 30% as the reports spread, printing an all-time low of $0.0005735. The selling tracked the estimate, not any official disclosure, because there was none to trade on. It caps a bruising stretch for crypto infrastructure. Coinsbuy had its hot wallets drained of roughly $8 million across two chains on Sunday, and July brought an account-aliasing flaw that cost Allbridge Core $1.65 million. Those were thefts of funds that existed. Tuesday's incident created tokens. A forged mint attacks the supply itself, and against a circulating base near 15 billion, the unconfirmed 4 billion estimate would be dilution on a scale token holders cannot ignore.
Everything now waits on Harmony
As of late Tuesday the public record consists of block data and one analyst's thread. Unknown from outside: whether exchanges holding forged ONE will freeze deposits, what the validators will be asked to run, and what Harmony's own accounting of the mint says. The timestamp gives responders one clean edge to work from, since every token minted through the flaw was created before a known boundary, inside a known window. Every response option starts from a confirmed total, and that is the number Harmony has yet to publish.
Read also: A Stolen Owner Key Mints 5.23M WEMIX$