Blockchain Sleuth ZachXBT Refuses to Help Hacked Harmony Project for Free

cryptonews.ruPublished on 2026-08-12Last updated on 2026-08-12

Abstract

Blockchain investigator ZachXBT has publicly refused to offer free assistance to the Harmony project following a recent hack where an attacker minted approximately 4 billion new ONE tokens, representing about 26% of the total supply. ZachXBT cited Harmony's failure to reward volunteers who helped track hackers after the $100 million Harmony Bridge exploit by North Korean actors in June 2022. Despite the volunteers' help leading to asset freezes and law enforcement seizures, Harmony only offered verbal thanks. In a tweet, ZachXBT stated he would not be investigating the new incident and believes no one should assist Harmony for free. He emphasized that without proper bug bounty and reward programs, security researchers lack incentive to help, making blockchains more vulnerable. The investigator recently identified an American woman, Tiffany Milanovich, as being involved in a separate $5 million crypto theft through phishing schemes.

ZachXBT's statements came shortly after an attack on Harmony, during which the malicious actor minted approximately 4 billion new tokens of the project, ONE. This represents about 26% of the total coin supply. ZachXBT explained that he would not take on the case because the project had previously failed to reward those who helped track the hackers that attacked the Harmony Bridge in 2022.

In June 2022, North Korean hackers breached the Harmony Bridge, stealing $100 million in cryptocurrency. A group of white hat hackers and other voluntary helpers assisted the project in tracking and freezing the stolen assets; however, Harmony never paid a bounty to the dedicated volunteers. ZachXBT claims that Harmony's creators merely expressed gratitude for the help by writing, "Good job."

I will not be tracking this incident and think no one should assist them for free.

Harmony took advantage of people who assisted during the $100M Harmony Bridge exploit by DPRK in 2022 and rewarded $0 for significant freezes which lead to LE seizures and simply said “good job”

— ZachXBT (@zachxbt) August 12, 2026

By refusing to provide assistance to the project, respected crypto industry researcher ZachXBT aimed to promote the idea that developers should properly incentivize security experts and ethical hackers who help investigate incidents and recover stolen funds. Without bounty programs, skilled professionals will not want to spend time and resources identifying vulnerabilities, making blockchains potentially more susceptible to attacks.

Recently, ZachXBT managed to identify an American woman named Tiffany Milanovich, naming her as involved in the theft of $5 million in cryptocurrency. The woman impersonated a customer support representative for crypto services, distributing phishing links to users and then publicly bragging about the stolen assets.

end-content

Related Questions

QWho is ZachXBT and what was his response to the recent Harmony hack?

AZachXBT is a blockchain investigator who refused to provide free assistance to the Harmony project after it was hacked. He explained his refusal by citing Harmony's failure to reward volunteers who helped track down hackers in a previous $100 million exploit.

QWhat happened in the most recent Harmony exploit mentioned in the article?

AIn the recent Harmony exploit, an attacker minted approximately 4 billion new ONE tokens, which represents about 26% of the total coin supply.

QWhy did ZachXBT cite Harmony's past actions as a reason for not helping now?

AZachXBT cited that during the June 2022 Harmony Bridge hack by North Korean hackers, volunteers, including white-hat hackers, helped trace and freeze stolen assets. However, Harmony never paid a reward for this significant assistance and only offered verbal thanks, saying 'good job'.

QWhat broader point was ZachXBT trying to make by refusing to help Harmony?

AZachXBT was trying to promote the idea that developers must properly incentivize security experts and ethical hackers who help investigate incidents and recover stolen funds. Without bug bounty or reward programs, qualified specialists may not invest time, making blockchains more vulnerable.

QWhat other recent case did ZachXBT help expose, according to the article?

AAccording to the article, ZachXBT recently identified an American woman named Tiffany Milanovich, accusing her of being involved in stealing $5 million in cryptocurrency by impersonating crypto service support staff and distributing phishing links.

Related Reads

Bitwise Closes 8 ETFs and Cuts Staff by 14%, but Continues to Launch New Products

Bloomberg reported on August 12 that cryptocurrency asset management firm Bitwise has laid off approximately 14% of its staff, reducing headcount from around 180 to about 155 employees. CEO Hunter Horsley stated the adjusted team remains the largest in the company's eight-year history and expressed confidence in long-term growth, though current personnel and product configurations are tightening. Prior to the layoffs, Bitwise disclosed a significant drop in client assets from over $15 billion in early February to $11 billion by April 1st, a decrease of at least $4 billion. The company did not specify the contributions of price changes, fund flows, or changes in reporting scope to this decline. In a related product restructuring, Bitwise decided to liquidate eight ETFs between April and June. This included the Web3 ETF, a BTC/ETH/Treasuries rotation strategy ETF, and six options income ETFs tied to assets like Coinbase and Ethereum. These moves reduce the number of products requiring ongoing operational support. Despite these cuts, Bitwise continues to launch new products. Recent offerings include an Avalanche ETP with staking in Europe, the Hyperliquid ETF, and the takeover of Superstate's $267+ million Crypto Carry Fund, entering the tokenized fund management space. The company now manages 70 investment products for over 5,500 advisory teams and works with more than 20 banks and broker-dealers. The simultaneous staff reduction and product portfolio shift—away from thematic Web3 and single-asset options strategies towards direct crypto exposure, staking, and tokenized funds—indicates a strategic realignment. The operational burden on the smaller remaining team will depend heavily on the complexity of the revised product lineup. Bitwise has not disclosed the specific reasons for the layoffs, the affected departments, severance details, or any one-time costs associated with the job cuts.

marsbit8m ago

Bitwise Closes 8 ETFs and Cuts Staff by 14%, but Continues to Launch New Products

marsbit8m ago

CoreWeave: The Inflection Point Has Arrived. Has the 'Hard-Working Underdog' Finally Turned Profitable?

CoreWeave, an AI cloud unicorn, released its Q2 2026 earnings on August 12, with shares rising about 15% post-announcement. While overall performance did not significantly exceed expectations, key positive trends emerged. Revenue reached approximately $2.58 billion, up 112% year-over-year, though slightly below the high end of prior guidance. A major highlight was the acceleration in computing power deployment, with Active Power increasing by a record 500 Mw to 1,500 Mw, far surpassing market forecasts and signaling faster future revenue growth. Capital expenditures also hit a new high of $9.4 billion. Importantly, profitability showed signs of inflection. "True" gross margin (after deducting cost of revenue and Tech & Infrastructure expenses) rose to 7.3%, up 3 percentage points from the previous quarter. As revenue scales, depreciation and operating expenses are being diluted. Adjusted operating profit margin improved significantly to 5% from 1% last quarter. The company's guidance points to continued acceleration, with Q3 revenue growth expected at 158% and margins continuing to climb. Management raised full-year 2026 guidance, projecting Q4 revenue growth of around 194% and an adjusted operating margin of approximately 14.6%, suggesting a rapid path toward its 25%-30% long-term target. Recent developments, including a 25% price increase for its services and the launch of higher-margin Managed Inference offerings, support the improving profitability narrative. While long-term competitive challenges remain for new cloud providers, CoreWeave's near-term trajectory of accelerating growth and expanding margins presents a high-risk, high-reward opportunity, especially amid renewed market optimism for cloud stocks.

marsbit45m ago

CoreWeave: The Inflection Point Has Arrived. Has the 'Hard-Working Underdog' Finally Turned Profitable?

marsbit45m ago

Uncovering the Secret Reasoning Chains of Claude Opus for $720: A Leak via Haiku, with GPT and Gemini Also Affected

Researchers discovered a method to extract hidden reasoning traces, or "Chain of Thought" (CoT), from major proprietary large language models (LLMs) like Anthropic's Claude Opus 4.8, OpenAI's GPT-5.6 Sol, and Google's Gemini 3.1 Pro. The attack exploits a design flaw in how these models handle encrypted reasoning "blobs." These blobs, which contain a model's internal reasoning steps, are encrypted and sent to the client for storage between conversation turns to save server costs. The researchers found these blobs were encrypted with a global key, allowing them to be reused across different sessions, users, and, crucially, different models from the same company. By taking an encrypted reasoning blob generated by a powerful "flagship" model and feeding it to a smaller, less capable model from the same family (e.g., feeding Claude Opus's blob to Claude Haiku), the researchers could prompt the smaller model to divulge the hidden CoT. This bypassed the need to crack the encryption directly. The implications are significant: 1) Competitors could potentially distill high-value reasoning data at low cost (estimated at ~$720 for 10,000 traces). 2) Sensitive information like API keys, passwords, and personal emails, which models might process internally but not output, could be leaked. The team found such leaks in 4.9% of analyzed public agent logs. 3) Models might internally analyze dangerous queries (e.g., car theft methods) before refusing to answer, but this dangerous analysis could be extracted from the CoT. 4) Malicious instructions could potentially be hidden within a reasoning blob to influence a model's future behavior. While the vulnerability was responsibly disclosed and patched by the affected companies, the research highlights a fundamental tension between the convenience of portable reasoning states and security. The paper also notes preliminary tests found no clear evidence that open-source models like DeepSeek had been distilled from the extracted CoTs.

marsbit51m ago

Uncovering the Secret Reasoning Chains of Claude Opus for $720: A Leak via Haiku, with GPT and Gemini Also Affected

marsbit51m ago

1confirmation: Reverse Entrepreneurship, the Next Web3 Blockbuster Might Come from a Once-Failed Track

**Title: Reverse Entrepreneurship: The Next Web3 Blockbuster May Come from Previously Failed Tracks** This article argues that the next major consumer crypto application is likely to emerge from a concept that failed five years ago, now benefiting from matured infrastructure and better timing. It examines several such "failed" tracks that hold renewed potential: 1. **Internet-Native Assets:** Beyond simply tokenizing tweets or creating digital collectibles, there's an opportunity to create a genuinely new, crypto-native asset class that captures cultural moments and online phenomena, as opposed to merely tokenizing real-world assets (RWA). 2. **X-to-Earn:** While unsustainable token emission models doomed early projects like STEPN, the core premise that most people will first *earn* crypto, not buy it, remains valid. The future challenge is designing what is earned and why users would hold it long-term. 3. **The Metaverse:** Past failures like Decentraland stemmed from trying to replicate the physical world online. The opportunity lies not in abandoning shared online social spaces, but in reimagining their form beyond real-world analogs. 4. **DAOs:** DAOs have underdelivered by overcomplicating governance. The fundamental, unmet user need is simpler: enabling groups of internet strangers to pool funds and collectively achieve goals (e.g., buying assets, funding projects) that are impossible individually. 5. **Personal Value Tokenization:** Numerous attempts (Friend.tech, BitClout) to create markets around individuals have failed. The enduring demand for "person-as-asset" trading (seen in meme coins, prediction markets) suggests the direction isn't wrong, but the execution has been flawed, often lacking creator consent or a less commodified model. The conclusion is that true innovation will come from revisiting these past ideas with new insights, rather than crowding into currently popular trends.

marsbit1h ago

1confirmation: Reverse Entrepreneurship, the Next Web3 Blockbuster Might Come from a Once-Failed Track

marsbit1h ago

Trading

Spot
活动图片