Horizon by Harmony Hack

REPORTED LOSS $100M
Critical Access Control

What happened

Harmony’s Horizon bridge lost about $100 million on 23 June 2022. Harmony reported that attackers obtained enough validator private keys to authorize withdrawals from the Ethereum side of the bridge.

Technical Root Cause

The incident was a validator-key compromise rather than a demonstrated bridge-contract bug. Harmony said encrypted keys were accessed and decrypted; the FBI later attributed the theft to Lazarus Group.

Case & protocol details

Classification Bridge
Protocol Type Exploit/Access control
Affected asset / contract ONE
Official Website www.harmony.one/
Protocol Twitter/X @harmonyprotocol

How it happened

  1. Attackers first obtained and decrypted enough validator private keys to control bridge signing.
  2. They then authorized transfers of bridged assets from the Ethereum side to an external account.
  3. Harmony halted the bridge and moved to stronger multisig controls; the FBI later attributed the theft to Lazarus Group.

Funds Recovery

1.4%

Recovered

$1.4M

Net Loss

$98,600,000

Post-Incident Timeline

  • 2023-02-14

    Crypto exchanges Binance and Huobi today froze accounts containing approximately $1.4 million in crypto assets originating from the June 2022 hack of Harmony’s Horizon Bridge.

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.