
Roughly 4 billion ONE tokens created out of nothing on Harmony. The team weighs a rollback. But with tokens already reaching exchanges, the window for a clean unwind is closing. Real implications for holders and their tax records.
Alpha Score of 63 reflects moderate overall profile with strong momentum, weak value, moderate quality, moderate sentiment.
A blockchain is treated as a ledger you can only add to at the end. That promise gets tested whenever a protocol, hit by an attack, starts weighing a rollback. Because rolling back the chain does not erase only the attacker's activity. It also erases the purchases and transfers of uninvolved holders.
Since mid-August 2026, that debate has been playing out in real time on the layer-1 chain Harmony. An attacker created roughly four billion ONE tokens out of thin air, the on-chain analyst Juiceberg estimated. Harmony shipped an emergency patch and has been weighing whether to reset the chain back to a point before the exploit. The window for that kind of unwind closes fast, and the decisions made in the next days will ripple through the exchange balances, self-custody holdings, and even tax records of everyone holding ONE.
How a rollback actually works
A rollback is a network-wide agreement to reset the chain's state to an earlier block and continue from there. Everything that happened between that block and the decision drops out of the recognised history. It does not happen by fiat. It works only if enough validators install a software version that treats the old state as valid. Anyone who does not follow along stays on the old chain, which can produce a split – two versions of the chain, two versions of the same token.
The Harmony team confirmed the incident on August 12. ONE tokens were created without authorisation. The protocol instructed validators to install the emergency version v2026.1.1, halted its own bridge and asked exchanges to freeze balances from four identified addresses. Roughly 53% of validators had updated within four hours of the patch release, according to reports. That ratio is the real yardstick of an emergency response.
On the precise amount, Harmony itself has not confirmed a number. Juiceberg's estimate of roughly four billion newly minted ONE would represent a supply increase of about 26% on the roughly 15 billion previously in circulation. Some 2.8 billion of the new tokens are said to have reached exchanges, CryptoSlate reported, citing an outside observer. The protocol has not confirmed those figures.
The mint mechanism
The published code changes centred on cross-shard receipts – the messages that carry a transaction result from one part of the chain to another. The first weakness was in the quorum check: the verifier counted the full committee instead of the validators actually represented, so a receipt passed without the necessary approvals. The second was in the marking that a receipt had already been spent. Because individual proof fields were not bound to the signed block header, a processed receipt could look like a new one. The destination shard credited the amount again without the source shard being debited. That gap is where the additional supply came from.
The pattern is not new. In April 2026, a similar flaw in a bridge's proof procedure created more than a billion counterfeit DOT tokens on Ethereum. Thin liquidity there limited the damage.
The escalating cost of a clean fix
A protocol has three options, and each later one is harder to enforce than the one before.
The emergency patch closes the vulnerability so nothing more can be minted. That is the quickest and least disruptive move. Harmony has already done that.
Freezing works only where someone holds control – at centralised exchanges and stablecoin issuers. The protocol publishes addresses and asks for a block. Whether the exchanges respond is their own decision. Harmony did not disclose which venues went along or what amount was frozen. The effectiveness is barely verifiable from outside.
The rollback is the most expensive move. It requires a majority of validators, the consent of the largest venues, and a community willing to accept the break with immutability. The longer the vote drags on, the more uninvolved transactions accumulate on the period that would be erased.
The cleanest-case scenario for an unwind is when the unauthorised tokens have never left the chain. The blocks concerned fall away, the tokens no longer exist, and no one outside has paid anything for them. Once the attacker has sold them on a centralised exchange, the process has stepped outside the chain: the buyer handed over real money and holds a claim in the exchange's books in return.
A rollback of the chain does not undo that trade. It only devalues the basis on which the exchange made the credit. The gap between chain state and internal ledger then has to be carried by someone – the venue out of its own pocket, or the customers through adjusted balances. The estimate that roughly 2.8 billion tokens reached exchanges at Harmony therefore describes how small the window for a clean unwind has become.
The DAO precedent
The best-known case is the attack on The DAO in the summer of 2016. The Ethereum community opted for an unwind. A part of the operators did not go along, and the chain split. The variant without the unwind runs to this day as Ethereum Classic. The underlying risk: in the end there can be two chains and two tokens, and your holding sits on both with very different values.
One day before the Harmony incident, Ravencoin was hit by a similar issue. Its network had accepted invalid blocks. Miners rebuilt the chain from a point before the flaw, putting several days of transactions at risk. Both cases show the same trade-off: whoever reverses an attack always reverses legitimate transfers as well.
What it means for holders
If your tokens sit on a centralised exchange, you legally hold not a coin but a claim against the venue. In an emergency the venue decides what happens to your balance. Deposits and withdrawals are typically stopped. Trading is suspended. Whether your holding stays unchanged depends on the provider's own booking practice.
In self-custody the situation is different. Your private key stays valid, but the chain state decides what it controls. If a reset happens, the account balance of the restored block applies to you, and every transaction after it is gone. A hardware wallet protects your key from outside access; it does not protect you against a change in supply at the protocol level, and not against a rollback. Both happen one layer down, where the validity of the chain is decided.
The tax problem nobody is talking about
In Germany, gains from selling crypto assets held as private assets fall under Section 23 of the Income Tax Act. The one-year holding period is the key threshold. If exceeded, the gain is tax-free. Below it, the €1,000 exemption threshold per calendar year applies.
A rollback calls into question the very figure that calculation hangs on: the acquisition date. If the block your purchase sits in falls out of the chain and the transaction is executed later or not at all, the start of the period shifts, or the deal never came about. There is no explicit rule in Germany for this scenario that a holder could rely on.
Do not count on software reconstructing the history later. Portfolio and tax programs draw data from exchange interfaces and from block explorers. If the chain is reset, one source changes retroactively while the exchange data stays put. From that moment the two states diverge.
The practical fix: save your exchange's transaction history as a file while it is still available. Keep the transaction hashes of your own transfers. Note the time and price of your purchases. These records are the only basis on which a diverging chain history can later be explained to the tax office. For larger amounts, the case belongs with a tax adviser.
The immutability trust test
The ability to patch quickly and the ability to rewrite history are the same ability. A network in which a small team rolls out a patch within hours, and validators follow, can just as quickly decide on an unwind. No single factor is a knockout on its own. Together, though, they tell you how much trust the finality of a booking on this chain deserves.
(As of August 15, 2026.)
Prepared with AlphaScala editorial tooling from the source reporting linked above. Indexable analysis may include a cited Alpha Score value. Publishing checks screen each story before release. Educational coverage, not personalized advice.