Harmony’s ONE token fell about 26% in Asian morning hours Wednesday after an apparent exploit created roughly 4 billion new tokens, according to CoinDesk. That amount would equal more than a quarter of the token’s existing supply, which CoinDesk reports was roughly 15 billion ONE before the incident. According to the report, Harmony confirmed the attack in a post on X and said it was working with exchanges to freeze the funds. The project also said it was preparing a software fix and working on “patch and rollback options,” with another update to come when more information is available. Harmony is a blockchain network, and ONE is used to pay for transactions and help secure the chain. The reported creation of 4 billion additional tokens would represent a sudden supply increase of about 26% against the pre-incident base cited by CoinDesk, which explains the market sensitivity around the event. The response path Harmony described is consequential. A rollback would mean returning the network to a point before the exploit and proceeding from there, effectively removing some later transactions from the chain’s accepted history. CoinDesk notes that this can stop an attacker from keeping newly created tokens that remain on the network, but becomes harder if funds have reached exchanges or moved onto other systems. The incident is still technically unresolved in public. CoinDesk reports that Harmony has not yet explained the vulnerability, how the 4 billion token figure was calculated, or how far back any proposed rollback would go. Those details matter because they determine both the scale of the exploit and the potential blast radius for users who transacted after it. CoinDesk also places the event in a broader week of smaller-chain rollback concerns. The report says Ravencoin, a separate blockchain built from Bitcoin’s code, faced its own possible rollback after invalid blocks were accepted by parts of its network. In that case, miners moved to rebuild the chain from before the flaw, putting several days of transactions at risk of reversal. Harmony has faced unauthorized creation of ONE before, according to CoinDesk. In December 2023, a staking-system bug reportedly created about 146.3 million ONE after tokens that should have stopped receiving payouts continued doing so. Harmony responded then with an emergency software update and blacklisted addresses holding the improperly created tokens. The network also suffered a major bridge attack in 2022, when about $100 million was stolen from its Horizon bridge after attackers compromised private keys controlling it. CoinDesk reports that the FBI later attributed that theft to North Korea’s Lazarus Group. Wednesday’s apparent exploit is different in kind: the reported damage involves creation of ONE on Harmony itself, rather than assets stolen from a bridge. Who benefits: If Harmony can freeze funds and deploy a fix quickly, holders and network participants may benefit from limiting the impact of the apparent token creation. Exchanges also benefit from clear coordination if affected tokens reached their platforms. Who's exposed: Users who transacted after the exploit could be exposed if Harmony pursues a rollback that reverses later activity. Exchanges may also be exposed if newly created ONE moved onto their systems before freezes took effect.