Post

挖矿的小羊
挖矿的小羊
Show original
40亿枚ONE被凭空铸造后,Harmony决定回滚——但真正的问题不是币价 8月12日,你醒来,打开行情软件。 Harmony ONE,跌了40%。 你以为看错了。 再刷新——最低0.0005735美元,历史新低。 发生了什么? 有人利用“空区块”漏洞,未经授权铸造了约40亿枚ONE。 相当于总供应量的26%。 其中28亿枚已经被转移到交易所。 攻击者正在卖。市场正在崩。你在亏钱。 40亿枚凭空出现的代币,把你的持仓稀释了四分之一。 这不是黑客“偷币”。这是直接从协议层面,凭空创造新代币。 然后你看到了项目方的公告。 “正在与交易所合作冻结资金”。 “正在开发补丁”。 “正在评估链上回滚方案”。 三个“正在”,没有一个“已完成”。 而你的ONE,还在跌。 更让人头皮发麻的是——Harmony的totalSupply查询接口最初根本没显示这40亿枚新增代币。 什么意思? 连系统自己都不知道自己被增发了。 8月13日,Harmony宣布:回滚方案已启动,漏洞修复已激活。 但事情没那么简单。 回滚意味着什么? 意味着把整条链的状态重置到攻击发生之前的那个区块。 攻击者铸造的40亿枚ONE会被抹掉。你的持仓会恢复到攻击前的数量。 但代价是什么? 回滚点之后发生的所有正常交易——也可能被一并抹去。 有人刚在DEX上完成了一笔swap。有人刚给LP加了池子。有人刚完成了一笔转账。 这些交易如果被回滚,谁来赔? 这不是Harmony第一次出事了。 2022年6月,Harmony的Horizon跨链桥被黑客盗走约1亿美元。 美国联邦调查局后来把这次攻击归咎于朝鲜的拉撒路集团。 那次是跨链桥被攻破。 这次是链本身被攻破。 从“桥不安全”到“链不安全”——信任崩塌的速度,比币价跌得还快。 现在的问题是: 如果你持有ONE,你会怎么做? 继续持有,赌回滚成功、币价反弹? 及时止损,认亏离场? 还是等官方最终处理结果? 我的答案是——别只看币价。看“信任”怎么重建。 什么样的处理方式最能重建市场信任? 第一,回滚必须执行,且执行必须透明。 攻击前的区块、攻击后的区块、回滚的目标区块——全部公开可查。让每个人都能验证自己的资产是否被正确恢复。 第二,漏洞的根本原因必须披露,不能糊弄。 2023年Harmony出过另一个通胀漏洞——质押逻辑缺陷导致1.46亿枚ONE被错误生成,最后靠紧急硬分叉解决。 那次规模小得多。 这次是40亿枚,是上次的27倍。 如果两次漏洞是同一种类型——那说明上次根本没修好。 项目方必须说清楚:这个漏洞是怎么产生的?为什么上次没发现?这次怎么保证不再发生? 第三,赔偿方案必须明确。 回滚会伤害无辜用户。不回滚会稀释所有持有者。 无论选哪条路,都有人受损。 项目方需要拿出具体的补偿方案——不是发个公告说“我们很遗憾”,而是真金白银地承担责任。 说句扎心的: 在币圈,安全事件不可怕。可怕的是项目方处理安全事件的方式。 2022年Harmony被盗1亿美元,最后追回了多少?没人说得清。 2023年质押漏洞,紧急硬分叉解决了,但信任修复了吗? 这次如果还是“发个公告、打个补丁、然后等热度过去”——那ONE这个币,就真的只剩“历史”了。 最后问你一个问题—— 如果回滚成功,你的ONE回来了。但下次呢? 下次漏洞出现的时候,你还会相信“正在处理”这四个字吗? 币价可以修复。信任不可以。 信任一旦断裂,修复它的成本,永远比修复代码高。 $BTC $ETH $ONE #Harmony推进链上回滚,铸币漏洞修复已激活
挖矿的小羊
挖矿的小羊
400 million turned into 3 trillion, Harmony is rolling back — this time, I stand for “immutability” If the coins in your hand were diluted by 26% overnight, would you support a rollback? Don’t rush to answer. Let me ask you another question — If you just completed a normal transaction after the attack happened, and now the project team says they want to roll back to the state before the attack, and your transaction will be canceled — would you still support the rollback? Think carefully before answering. Because Harmony’s users are now standing at this crossroads. On August 12, Harmony experienced a shocking incident. The attacker exploited the “empty block” vulnerability to mint about 4 billion ONE tokens without authorization, accounting for about 26% of the total supply at that time. About 2.8 billion of these were quickly transferred to major exchanges. ONE’s price once plummeted nearly 40%. But the most surreal thing happened the next day. On August 13, Harmony announced — the number of abnormally minted ONE tokens had exceeded 3 trillion, involving 6 abnormal blocks. 3 trillion. You read that right. From 4 billion to 3 trillion, a difference of 750 times. The total supply of ONE before the attack was only about 15 billion. What does 3 trillion mean? It’s equivalent to creating 200 times the entire Harmony out of thin air. Although most of it hasn’t been dumped yet, the “totalSupply” endpoint couldn’t even reflect the new amount in real time. The project team doesn’t even know how many coins they have. Now Harmony’s choice is: rollback. Rollback means simply — restoring the entire chain to a block before the attack happened, and all transactions after the attack will be invalidated. Harmony said it is advancing the rollback plan and has reached consensus with validators and exchanges on the specific path. The vulnerability fix has been activated, and the full list of attacker wallets will be announced soon. Sounds reasonable, right? But here’s the problem — Every normal transaction that happened after the rollback point will be erased. You just completed a swap on a DEX, gone. You just received a transfer, gone. You just staked ONE, also gone. To punish one bad actor, you have to sacrifice the transaction history of all the good people. Is this the “decentralization” you want? What’s more ironic — this is not the first time Harmony has had issues. In 2022, the Horizon Bridge was hacked and $100 million was stolen, linked to North Korea’s Lazarus Group. In 2023, there was another abnormal minting issue related to staking. Now, in 2026, the third time. One project, three major incidents in three years. This time, well-known on-chain investigator ZachXBT directly refused to assist Harmony and called on other researchers not to help for free either. His reason is straightforward: after the 2022 bridge hack, researchers who helped track funds contributed a lot of work but received no payment. When even white hats don’t want to help you, think about what kind of reputation you have in this industry. So back to the original question — Do you support the rollback? My answer is: no. Not because I sympathize with the hacker. Because “immutability” is the last line of defense for blockchain. Today Harmony can roll back because of 3 trillion tokens, tomorrow any project can roll back because “we feel something’s wrong.” Then what are we even playing at? On-chain data immutability — if this rule is broken, it’s scarier than a hacker minting 3 trillion tokens. A hacker minting tokens loses money. Breaking the rules loses trust. And trust is the only valuable thing in this industry. I know some will say: “What about my coins being diluted? Isn’t my money worthless?” I understand. But the solution shouldn’t be tearing down the whole building to find a cockroach. Better approaches are: hard forks, compensation plans, stronger audits. After the 2022 bridge hack, Harmony once proposed a hard fork to mint additional ONE tokens to compensate victims. The same method, again? Better think about how to avoid a fourth time. $BTC $ETH $ONE #Harmony推进链上回滚,铸币漏洞修复已激活

Disclaimer: OKX Orbit content is provided for informational purposes only. Learn more

Replies

No comments yet. Be the first to reply!