Harmony’s Horizon Bridge Hack
2022-07-14 • Harmony One •
https://medium.com/harmony-one/harmonys-horizon-bridge-hack-1e8d283b6d66
Harmony's rolling incident update documents the June 23, 2022 Horizon Bridge hack, in which approximately $100 million was stolen through 11 unauthorized transactions from the Ethereum side of the bridge. The incident response found no evidence of smart-contract or Harmony consensus-layer compromise; instead, Harmony reported that private keys used to sign transactions were compromised and decrypted despite being stored with passphrase and key-management protections. The attacker swapped assets including BUSD, USDC, ETH, and WBTC into ETH, and later began moving funds through Tornado Cash while Harmony worked with the FBI, Chainalysis, AnChainAI, exchanges, and the community. Harmony increased the bridge controls from a 2-of-4 to a 4-of-5 multisig, offered a $10 million return/information bounty, and developed recovery plans for roughly 50,000 affected wallets.