In short
- Concord confirmed an exploit after an analyst reported that an attacker minted about 4 billion ONE, roughly 26% of the provision.
- Round 97% of these tokens have already reached exchanges, on-chain analyst Juiceberg mentioned.
- ONE was buying and selling at about $0.00077, down 37% on the day, after Concord shipped a patch to cease additional minting.
Layer-1 blockchain Concord has confirmed it was exploited after an attacker minted roughly 4 billion ONE tokens with out authorisation, sending the token down 37% to about $0.00077, per CoinGecko knowledge.
On-chain analyst Juiceberg flagged the mint early Wednesday, placing it at near 4 billion tokens, or about 26% of the provision, and saying the tokens had been created by means of empty blocks. Round 2.8 billion had been funnelled onto exchanges as the value fell.
In a follow-up tweet, the analyst mentioned the attacker had roughly 115 million ONE left to promote on-chain, about 2.9% of the overall minted. “The overwhelming majority (~97%) is already on exchanges,” Juiceberg wrote, and had both been offered or was sitting in deposit wallets.
Concord responded in a tweet that it was “working with our crew and applicable exchanges to cease and freeze the funds,” including that it was making ready a patch and weighing rollback choices. In a second publish it named 4 wallets, every listed in each Concord and hex codecs, and requested exchanges to dam something traced to them.
We’re working with our crew and applicable exchanges to cease and freeze the funds.
We’re engaged on a patch and rollback choices.
Will replace when we now have new info. https://t.co/XB0nCwTAyN
— Concord 💙 (@harmonyprotocol) August 12, 2026
Simply over two hours after that first assertion it paused its bridge, then launched a patch a minute later, telling validators to improve to a construct it mentioned prevents any additional minting. Coping with the tokens already created would take one other replace, it mentioned. 5 hours had handed since Juiceberg’s first publish.
The mission has not disclosed the vulnerability, confirmed what number of tokens had been created, or mentioned how a lot reached exchanges. One oddity Juiceberg famous is that Concord’s totalSupply endpoint didn’t mirror the brand new tokens, and worth trackers nonetheless record circulating provide at about 14.87 billion.
Rolling again the chain
A rollback would return the community to a state earlier than the exploit and proceed from there, erasing what adopted from the accepted historical past. That cuts each methods, since transactions made by odd customers after the assault would go together with it.
Concord has been right here earlier than, with hackers draining about $100 million from its Horizon cross-chain bridge in June 2022, in an assault the FBI later attributed to North Korea’s Lazarus Group.
The mission’s first proposal to the 2022 hack was to reimburse victims in ONE, which might have meant minting billions of recent tokens on prime of the circulating provide and hard-forking the chain to permit it. The plan drew sufficient criticism that the crew changed it with one funded from its treasury. 4 years on, an attacker has minted a comparable quantity with out asking.
ONE now carries a market capitalisation of about $11.5 million, rating it exterior the highest 1,000 tokens. It final traded close to its October 2021 file of $0.38 greater than 4 years in the past, and is down greater than 99% from that degree.
Each day Debrief E-newsletter
Begin each day with the highest information tales proper now, plus authentic options, a podcast, movies and extra.

