Harmony has proposed rolling back its blockchain to two Aug. 11 checkpoints, a recovery plan that would discard more than 109,000 regular transactions as the network removes ONE created through a forged mint.

According to Harmony’s latest incident update on X, validators would retain shard 0 block 92,730,034 and shard 1 block 94,978,278, both recorded at 11:25:37 p.m. UTC on Aug. 11, before restarting the network from replacement databases built around those checkpoints.

https://t.co/EKDqnqTuDk

— Harmony 💙 (@harmonyprotocol) August 17, 2026

Under the plan, new blocks would begin at heights 92,730,035 on shard 0 and 94,978,279 on shard 1. Harmony said client version v2026.1.2 has been configured to reject the abnormal block hashes linked to the incident, preventing validators from accepting the affected chain history after the restart.

The first confirmed forged mint reached shard 0 at block 92,730,036, according to the network. Block 92,730,035 contained no regular or staking transactions, incoming receipts or gas usage, while its state remained unchanged from block 92,730,034.

Harmony said it selected block 92,730,034 to provide a one-block safety buffer. The database, recovery scripts and validator procedures had also been prepared and reviewed around that block, while changing the checkpoint at a late stage could leave validators working from different recovery targets.

Shard 1 was not where the forged mint occurred. Harmony said its corresponding checkpoint was included as a precaution using the same timestamp.

Harmony rollback would use replacement databases

The recovery plan would replace the affected shard databases instead of using Harmony’s existing in-place rewind function.

According to the team, the network’s –revert function mainly moves chain heads and does not fully clear later receipts, indexes, snapshots and cross-shard information. Leaving some of that data behind could preserve an attack route or cause validators to reach different states.

Harmony said a replacement database gives validators a single reviewed state from which to resume consensus.

The team also considered burning or repairing the forged ONE directly, but said the tokens had already passed through exchanges, decentralized exchange pools, contracts and numerous wallets. Removing assets at individual destinations could therefore affect funds belonging to unrelated users.

A blacklist was rejected because it would leave the forged supply in existence while potentially restricting wallets holding legitimate assets. Selectively replaying transactions was also ruled out because the state of the replacement chain would differ from the discarded chain, meaning identical transactions could produce different results.

Token migration was another option reviewed by Harmony, but the team said it would cause substantially more disruption.

The decision comes after another blockchain faced a similar choice following an exploit. In December 2025, Flow revised rollback plans following a $3.9 million execution-layer exploit, dropping an initial full rollback proposal in favor of targeted token burns after bridge operators and other participants raised concerns about the effect on legitimate activity. crypto.news reported at the time that Flow also planned a phased network restart and restrictions on flagged accounts.

More than 109,000 transactions face removal

Harmony’s rollback would discard all blocks created after the selected checkpoints, including regular transactions made by users during the affected period.

To measure the impact, the team built a shard 0 archive covering blocks 92,730,035 through 92,871,662. The dataset contained 141,628 consecutive blocks, 109,126 regular transactions and 315 staking transactions, with 109,441 exact transaction-to-receipt matches.

Harmony said it checked parent-hash continuity and receipt completeness throughout the archived range.

Automated activity accounted for most of the transaction count. Of the 109,126 regular transactions, 104,545, or 95.80%, were classified as automated. DEX automation represented 99,863 transactions, including 75,430 successful swaps and 11,804 failed bot attempts.

As a result, Harmony cautioned that the number of discarded transactions should not be treated as the number of affected users.

The team also examined whether some regular transactions could be safely restored after the rollback. Only 22 were simple native transfers without an obvious dependency in the available data, but Harmony said even those could not automatically be considered safe for replay.

Another 860 native transfers raised questions involving balances, funding sources, nonces or later spending. A further 80,630 transactions depended on contract or blockchain state, while 27,614 were failed transactions, incident-linked activity or movements involving exchanges, bridges and consolidation routes.

All 315 staking transactions also depend on chain and epoch state, according to the update.

Harmony said balances, nonces, token approvals, swap deadlines, liquidity pool reserves and staking conditions would change once the replacement chain starts. Under that altered state, a transaction that previously failed could succeed, while a swap, approval or staking transaction could generate a different outcome.

Full EVM traces are also unavailable through the RPC data used in the review, leaving internal contract transfers and storage changes subject to application-specific analysis.

Forged ONE moved through exchanges, pools and bridges

The investigation has separately mapped the movement of the newly created ONE across the network.

According to Harmony, one wallet involved in the forged mint attempted 534 transfers of 5 billion ONE each within 106 seconds. A total of 477 transfers succeeded, moving 2.385 trillion ONE.

Investigators created a time-ordered graph beginning with all wallets associated with the forged mints, separating transactions signed by those wallets from successful transfers, failed attempts and subsequent movements through other addresses.

The traced activity was checked against blocks, transaction receipts and balances through shard 0 block 92,805,850. Harmony said the funds reached standalone wallets, exchange accounts, DEX routers and pools, liquidity provider positions, bridge contracts, wrapped ONE, staking wallets and high-volume service wallets.

When forged ONE became mixed with other assets, the tracing model followed transfers chronologically and capped the amount attributed to the forged tokens at each wallet’s available balance. According to the team, the method was intended to prevent the same tokens from being counted repeatedly as they moved between addresses.

An earlier model traced more than 99.9% of the forged ONE to a wallet or service boundary, while a later version reconciled almost all of the amount across those boundaries and transaction fees at the selected cutoff.

Harmony stressed that route coverage does not mean investigators can identify the individuals controlling every destination. Exchange accounts, pools, contracts and other service clusters can contain funds belonging to many users.

The amount that can be safely destroyed is smaller still, according to the team. Forged tokens left untouched in a standalone wallet may be possible to isolate, while ONE that entered an exchange wallet, liquidity pool, bridge, staking position or another shared balance could no longer be removed in full without risking unrelated assets.

A comparable problem has surfaced in other token-minting attacks. In June, Humanity Protocol disclosed that compromised administrative keys allowed attackers to take control of bridge infrastructure and mint additional H tokens on BNB Smart Chain. The protocol halted affected bridge operations and coordinated with exchanges and law enforcement while investigators tracked the stolen assets.

Investigation continues alongside validator recovery

Harmony said it has made initial progress toward tracing the hacker and is working with exchanges, bridges and law enforcement to preserve records and continue the investigation.

An independent third-party security company also reviewed the incident separately and corroborated the forged mint and the main findings from the fund-flow analysis, according to the network.

Harmony has dealt with a major cross-chain security incident before. Its Horizon Bridge lost about $100 million in June 2022 after private keys controlling the bridge were compromised. The project subsequently worked with exchanges, law enforcement, and blockchain analytics firms to identify the attacker, while raising its hacker bounty to $10 million.

Funds from that attack continued moving months later. In January 2023, on-chain investigators tracked stolen ETH through hundreds of addresses, while Binance and Huobi froze accounts linked to the movement and recovered 124 BTC.

For the current incident, Harmony said it is working with exchanges and bridges to assess the effect of discarding post-checkpoint activity and determine how affected parties can be handled. The team said all blocks after the checkpoints would be removed under the proposed recovery, including regular transactions that were unrelated to the forged mint.