Blockchain Sleuth ZachXBT Refuses to Help Hacked Harmony Project for Free

cryptonews.ruОпубліковано о 2026-08-12Востаннє оновлено о 2026-08-12

Анотація

Blockchain investigator ZachXBT has publicly refused to offer free assistance to the Harmony project following a recent hack where an attacker minted approximately 4 billion new ONE tokens, representing about 26% of the total supply. ZachXBT cited Harmony's failure to reward volunteers who helped track hackers after the $100 million Harmony Bridge exploit by North Korean actors in June 2022. Despite the volunteers' help leading to asset freezes and law enforcement seizures, Harmony only offered verbal thanks. In a tweet, ZachXBT stated he would not be investigating the new incident and believes no one should assist Harmony for free. He emphasized that without proper bug bounty and reward programs, security researchers lack incentive to help, making blockchains more vulnerable. The investigator recently identified an American woman, Tiffany Milanovich, as being involved in a separate $5 million crypto theft through phishing schemes.

ZachXBT's statements came shortly after an attack on Harmony, during which the malicious actor minted approximately 4 billion new tokens of the project, ONE. This represents about 26% of the total coin supply. ZachXBT explained that he would not take on the case because the project had previously failed to reward those who helped track the hackers that attacked the Harmony Bridge in 2022.

In June 2022, North Korean hackers breached the Harmony Bridge, stealing $100 million in cryptocurrency. A group of white hat hackers and other voluntary helpers assisted the project in tracking and freezing the stolen assets; however, Harmony never paid a bounty to the dedicated volunteers. ZachXBT claims that Harmony's creators merely expressed gratitude for the help by writing, "Good job."

I will not be tracking this incident and think no one should assist them for free.

Harmony took advantage of people who assisted during the $100M Harmony Bridge exploit by DPRK in 2022 and rewarded $0 for significant freezes which lead to LE seizures and simply said “good job”

— ZachXBT (@zachxbt) August 12, 2026

By refusing to provide assistance to the project, respected crypto industry researcher ZachXBT aimed to promote the idea that developers should properly incentivize security experts and ethical hackers who help investigate incidents and recover stolen funds. Without bounty programs, skilled professionals will not want to spend time and resources identifying vulnerabilities, making blockchains potentially more susceptible to attacks.

Recently, ZachXBT managed to identify an American woman named Tiffany Milanovich, naming her as involved in the theft of $5 million in cryptocurrency. The woman impersonated a customer support representative for crypto services, distributing phishing links to users and then publicly bragging about the stolen assets.

end-content

Пов'язані питання

QWho is ZachXBT and what was his response to the recent Harmony hack?

AZachXBT is a blockchain investigator who refused to provide free assistance to the Harmony project after it was hacked. He explained his refusal by citing Harmony's failure to reward volunteers who helped track down hackers in a previous $100 million exploit.

QWhat happened in the most recent Harmony exploit mentioned in the article?

AIn the recent Harmony exploit, an attacker minted approximately 4 billion new ONE tokens, which represents about 26% of the total coin supply.

QWhy did ZachXBT cite Harmony's past actions as a reason for not helping now?

AZachXBT cited that during the June 2022 Harmony Bridge hack by North Korean hackers, volunteers, including white-hat hackers, helped trace and freeze stolen assets. However, Harmony never paid a reward for this significant assistance and only offered verbal thanks, saying 'good job'.

QWhat broader point was ZachXBT trying to make by refusing to help Harmony?

AZachXBT was trying to promote the idea that developers must properly incentivize security experts and ethical hackers who help investigate incidents and recover stolen funds. Without bug bounty or reward programs, qualified specialists may not invest time, making blockchains more vulnerable.

QWhat other recent case did ZachXBT help expose, according to the article?

AAccording to the article, ZachXBT recently identified an American woman named Tiffany Milanovich, accusing her of being involved in stealing $5 million in cryptocurrency by impersonating crypto service support staff and distributing phishing links.

Пов'язані матеріали

1confirmation: Reverse Entrepreneurship, the Next Web3 Blockbuster Might Come from a Once-Failed Track

**Title: Reverse Entrepreneurship: The Next Web3 Blockbuster May Come from Previously Failed Tracks** This article argues that the next major consumer crypto application is likely to emerge from a concept that failed five years ago, now benefiting from matured infrastructure and better timing. It examines several such "failed" tracks that hold renewed potential: 1. **Internet-Native Assets:** Beyond simply tokenizing tweets or creating digital collectibles, there's an opportunity to create a genuinely new, crypto-native asset class that captures cultural moments and online phenomena, as opposed to merely tokenizing real-world assets (RWA). 2. **X-to-Earn:** While unsustainable token emission models doomed early projects like STEPN, the core premise that most people will first *earn* crypto, not buy it, remains valid. The future challenge is designing what is earned and why users would hold it long-term. 3. **The Metaverse:** Past failures like Decentraland stemmed from trying to replicate the physical world online. The opportunity lies not in abandoning shared online social spaces, but in reimagining their form beyond real-world analogs. 4. **DAOs:** DAOs have underdelivered by overcomplicating governance. The fundamental, unmet user need is simpler: enabling groups of internet strangers to pool funds and collectively achieve goals (e.g., buying assets, funding projects) that are impossible individually. 5. **Personal Value Tokenization:** Numerous attempts (Friend.tech, BitClout) to create markets around individuals have failed. The enduring demand for "person-as-asset" trading (seen in meme coins, prediction markets) suggests the direction isn't wrong, but the execution has been flawed, often lacking creator consent or a less commodified model. The conclusion is that true innovation will come from revisiting these past ideas with new insights, rather than crowding into currently popular trends.

marsbit12 хв тому

1confirmation: Reverse Entrepreneurship, the Next Web3 Blockbuster Might Come from a Once-Failed Track

marsbit12 хв тому

Liang Wenfeng Launches Surprise Attack on Musk: DeepSeek V4 Pro vs. Grok 4.6, First Tests Are Spectacular

**DeepSeek V4 Pro vs. Grok 4.6: A Benchmark and Real-World Showdown** In a dramatic AI clash, DeepSeek V4 Pro and Elon Musk's Grok 4.6 launched head-to-head, targeting long-task capabilities like tool calling and code validation. **Benchmark Performance:** DeepSeek V4 Pro excelled in Agent tests, topping CyberGym (83.3) and AutomationBench (31.8), surpassing models like Fable 5 and Claude Opus 4.8. It closed the gap on Terminal-Bench 2.1 (87.9) and saw massive gains in DeepSWE (software engineering). Grok 4.6 matched GPT-5.6 in overall ability (61 index), outperformed it in coding (CursorBench 69.9%), and led in three knowledge-work evaluations, including legal tasks (Harvey LAB, 15.8%). **Pricing Disruption:** DeepSeek's standout feature is its radically low cost: $0.87 per million output tokens—roughly 1/7th of Grok 4.6 ($6) and a tiny fraction of rivals like Fable 5 ($50). **Real-World Tests:** In practical challenges, both models demonstrated impressive skill. DeepSeek V4 Pro built a 3D interactive Earth, websites, 60 design styles, and a polished Flappy Bird clone (costing only $0.019 vs. Grok's $0.03 for a simpler version). Head-to-head comparisons were tight: Grok 4.6 won on some design aesthetics, while DeepSeek often delivered higher visual detail and completeness. However, in complex tasks like generating a Three.js cherry blossom tree, V4 Pro lagged behind GPT-5.6 Sol and Claude Opus 5. **Conclusion:** The simultaneous release signals a shift: high-end AI capability is becoming dramatically more affordable. DeepSeek V4 Pro and Grok 4.6 now compete directly with top-tier models from OpenAI and Anthropic, promising to democratize powerful AI tools and fuel an application explosion. The race continues, with Grok 4.7 and counter-moves from incumbents already anticipated.

marsbit26 хв тому

Liang Wenfeng Launches Surprise Attack on Musk: DeepSeek V4 Pro vs. Grok 4.6, First Tests Are Spectacular

marsbit26 хв тому

Торгівля

Спот
活动图片