Two Compromised Keys, One $100 Million Bridge: Inside the Harmony Horizon Hack
Harmony's cross-chain bridge lost $100 million in an exploit that ranks among the largest bridge hacks on record, making it the third bridge to enter the top-ten leaderboard and the second in a row attributed to compromised private keys rather than a smart contract flaw.
Harmony did not confirm the breach publicly until more than 14 hours after the attacker's first transactions went out, finally acknowledging the theft on Twitter.

That delay raises an uncomfortable question: was nine figures of user funds really being protected by control of just two signatures? (Credit to researchers RugDocIO and BeosinAlert for early analysis.)
The Horizon bridge's security rested on a 2-of-5 multisignature wallet. Per research shared publicly, two of the five authorized signing addresses had been compromised:
0xf845A7ee8477AD1FB4446651E548901a2635A915
0x812d8622C6F3c45959439e7ede3C580dA06f8f25
Exactly how the intruder gained control of these two addresses is still unconfirmed. One theory circulating is that the associated private keys were stored as plaintext on hot wallets. If that's accurate, breaching the servers hosting those wallets would have been enough to authorize any transaction the attacker wanted — including a $100 million withdrawal from the bridge.
Exploiter address: 0x0d043128146654c7683fbf30ac98d7b2285ded00
Harmony ETH Bridge: 0xf9fb1c508ff49f78b60d3a96dea99fa5d7f3a8a6
Harmony ERC20 Bridge: 0x2dCCDB493827E15a5dC8f8b72147E6c4A5620857
Harmony BUSD Bridge: 0xfd53b1b4af84d59b20bf2c20ca89a6beeaa2c628
The withdrawals began at 11:06 UTC. The attacker moved 13,100 ETH out of the ETH Bridge and 5.5 million BUSD out of the BUSD Bridge, in addition to draining a range of other ERC20 tokens from the ERC20 Bridge.
Those assets were forwarded to two secondary addresses — address 2 and address 3 — converted into ETH, and consolidated back into the attacker's primary wallet, where the funds have stayed. Separately, on BNB Chain, the attacker withdrew 5,000 BNB and 640,000 BUSD, both of which remain parked in the same address on BscScan.
PeckShield published a graphic mapping the complete movement of the stolen funds.

Following the incident, Harmony raised the multisig's signer threshold to four — a fix that came only after the damage was done.
This exploit follows the same script as the Ronin bridge hack, where five of nine validator keys were compromised, an operation widely linked to the spear-phishing campaigns attributed to the Lazarus Group. Given that groups like this are known to persistently target crypto projects, it's striking that an entire network's official bridge could still be emptied by compromising just two addresses.
The warning signs weren't only visible in hindsight, either. Back in early April, Twitter user @_apedev specifically flagged the fragile state of the Harmony bridge's security setup — a warning that went unheeded.
It leaves an open question of how the team overlooked, and then continued to ignore, such weak protection around nine figures of user funds. Harmony had already struggled to build a strong user base before this hack, and coming at a time when broader market sentiment was near all-time lows, the breach raises real doubts about whether the network can recover.
Get new scam files the moment we publish them — usually 2–3 emails a week.