Concord’s ONE token plunged sharply on Aug. 12 after the Layer-1 blockchain suffered a suspected exploit that reportedly allowed an attacker to mint roughly 4 billion ONE with out authorization.
The newly created tokens characterize about 26% of the roughly 15 billion ONE that have been circulating earlier than the incident, elevating issues a couple of sudden improve in provide and triggering heavy promoting strain. Harmony confirmed the safety incident and mentioned it was engaged on an emergency patch whereas evaluating rollback choices.

Concord Exploited in Unauthorized Mint of 4 Billion ONE (Supply: X)
Billions of ONE Reportedly Minted
On-chain analyst Juiceberg reported that roughly 4 billion ONE have been created by way of empty blocks on the Concord community. If confirmed, the issuance could be equal to greater than one-quarter of the token’s beforehand circulating provide.
Concord has not independently confirmed the 4 billion determine or disclosed the vulnerability that enabled the unauthorized mint. As a substitute, the venture mentioned it was working to stop additional token creation and decide the best way to deal with the tokens that had already been generated.
The incident turned extra severe as massive quantities of the newly minted ONE have been reportedly transferred to cryptocurrency exchanges. Juiceberg estimated that round 2.8 billion ONE reached exchanges, whereas roughly 115 million remained accessible on the market on-chain at one level. Concord has not confirmed these figures, so they continue to be analyst estimates.
If the estimates are correct, the fast motion of tokens to exchanges may make restoration considerably tougher. Funds that stay identifiable can doubtlessly be frozen, whereas tokens which have already been bought or transferred to different wallets could also be more durable to hint and recuperate.
Concord Strikes to Comprise the Assault
Concord mentioned it recognized 4 pockets addresses linked to the incident and requested cryptocurrency exchanges to dam and freeze funds originating from them.
The venture additionally paused its token bridge and instructed community operators to put in an emergency software program replace meant to stop additional unauthorized minting. Concord mentioned it was engaged on a patch and contemplating rollback choices.
A rollback would contain returning the blockchain to a state earlier than the exploit and successfully eradicating subsequent transactions from the accepted chain historical past. Such a transfer may doubtlessly get rid of unauthorized tokens that stay on the community, however it will additionally threat reversing professional transactions made in the course of the affected interval.
That creates a tough alternative for Concord. Whereas a rollback may be an efficient emergency response, blockchain immutability is a elementary precept of decentralized networks. Reversing transactions may due to this fact create extra controversy amongst customers and builders.
Concord has not but introduced whether or not it’ll proceed with a rollback or recognized the particular block vary that might be affected.

4 pockets addresses have been linked to the incident
ONE Value Drops Sharply
The suspected exploit instantly despatched ONE decrease as merchants reacted to the potential improve in provide.
In accordance with the supply materials, ONE fell greater than 39% at one level to roughly $0.000747. The sharp decline highlights the market’s sensitivity to unauthorized token issuance, notably when the reported quantity is massive in contrast with the present provide.
The potential affect goes past the tokens allegedly managed by the attacker. Even when a portion of the newly created ONE may be frozen, uncertainty over the ultimate provide can weigh on investor confidence and improve volatility.
The shortage of an official provide reconciliation additionally leaves an necessary query unanswered: precisely what number of ONE have been created?
Till Concord publishes a definitive determine, the reported 4 billion determine needs to be handled as an on-chain analyst estimate somewhat than a confirmed last whole.

Concord (ONE) Value Efficiency (Supply: CoinMarketCap)
Concord Has Confronted Unauthorized Minting Earlier than
This isn’t the primary incident involving unintended ONE creation.
In 2023, a vulnerability in Concord’s staking logic resulted in roughly 146.3 million ONE being minted throughout 74 delegator addresses. In accordance with Concord’s technical report, the problem concerned undelegation data that weren’t correctly cleared after validator fee adjustments. Some matured undelegations consequently acquired repeated payouts throughout a number of epochs, creating tokens outdoors the meant issuance course of.
Concord responded with an emergency laborious fork and deployed a repair at block 51,118,080.
The venture has additionally skilled a serious safety breach involving its Horizon Bridge. In June 2022, attackers stole roughly $100 million value of cryptocurrency after compromising personal keys controlling the bridge. The FBI later attributed the assault to North Korea-linked Lazarus Group actors.
The most recent incident is totally different from the Horizon Bridge hack as a result of the reported harm entails the creation of latest ONE instantly on Concord’s Layer-1 community somewhat than the theft of property held by a bridge.
What Occurs Subsequent?
Concord now faces a number of crucial questions: what vulnerability enabled the unauthorized mint, what number of ONE have been truly created, what number of stay underneath the attacker’s management and the way a lot can exchanges efficiently freeze?
The choice over a possible rollback might be equally necessary. Reverting the chain may assist get rid of unauthorized transactions, but it surely may additionally have an effect on professional customers and additional problem confidence within the community’s transaction finality.
For Concord, the precedence is to cease any extra unauthorized issuance, determine the basis trigger and set up an correct accounting of the affected tokens. Cooperation from cryptocurrency exchanges will even be essential if massive portions of the newly minted ONE have already entered centralized buying and selling platforms.
As of Aug. 12, Concord had confirmed the safety incident however had not publicly confirmed the reported 4 billion ONE determine or disclosed the underlying vulnerability. The venture mentioned it will present additional updates as its investigation and response progress.
The incident leaves Concord dealing with one other main check of its safety infrastructure and its capability to revive confidence after an unauthorized growth of its token provide.





