Harmony Horizon Bridge 2022 exploit
In June 2022, Harmony's Horizon Bridge was exploited for roughly $100 million. Later public statements and FBI material linked the theft to Lazarus Group actors, while recovery and reimbursement details remain incomplete in this seed record.
Incident facts
- Incident title
- Harmony Horizon Bridge 2022 exploit
- Bridge
- Harmony Horizon Bridge
- Incident date
- 2022-06-24
- Incident type
- Exploit
- Major incident
- Yes
- Affected chains
- Harmony, Ethereum, BNB Chain
- Affected assets
- ETH, USDC, USDT, WBTC, BNB, ONE
- Attack category
- Validator Key Compromise
- Reported loss
- $100 million
- Amount confidence
- Medium
- Loss amount basis
- Public Reports And Official/Security Summaries
- Recovery
- Partial Recovery
- Reimbursement
- In Progress
- Restart
- Not Reopened
- Current outcome
- Dead After Incident
- Postmortem
- Partial
- Resolution
- Unresolved
- Last reviewed
- 2026-06-15
- Last verified
- 2026-06-15
Amount and valuation
Reported as roughly $100 million in public coverage.
Public reports commonly cite approximately $100 million; exact asset-level composition requires later source-specific expansion.
about $100 millionabout $100 million
Used as the display loss amount in this seed record.
Why this remains unresolved
- Recovery and buyback activity remains ongoing and does not establish full reimbursement.
- The final recovered amount and completion date remain unknown.
Timeline events
Harmony Horizon Bridge exploit disclosed2022-06-24
Harmony disclosed that Horizon Bridge had been exploited for roughly $100 million in assets.
FBI attribution to Lazarus Group reported2023-01-23
The FBI publicly attributed the Horizon Bridge theft to Lazarus Group and APT38 actors associated with North Korea.
Harmony documented treasury-led recovery activity2023-03
Harmony reported using treasury funds to recover and burn depegged assets while community recovery work continued.
Harmony Horizon included in bridge-hack research context2025-01-06
Later cross-chain bridge hack surveys use Harmony Horizon as a major reference case for bridge exploit classification and attribution context.
Used for context only, not as a primary incident source.
Additional Harmony recovery partner proposed2025-06-17
A community proposal described continued buyback-and-burn recovery work and sought recognition as an additional recovery partner.
Evidence of continuing recovery activity, not full reimbursement.
Evidence records
- Hackers steal $100 million from Harmony's Horizon bridgeCNBC · Tier 2 · High reliability · secondary · 2022-06-24Claim scope: Incident Case
Used for initial public loss framing of the Horizon Bridge exploit.
- FBI Confirms Lazarus Group Cyber Actors Responsible for Harmony's Horizon Bridge Currency TheftFederal Bureau of Investigation · Tier 1 · High reliability · primary · 2023-01-23Claim scope: Incident Case
Government source used for Lazarus/APT38 attribution context.
- U.S. FBI says North Korean hackers stole $100 million from Harmony BridgeReuters · Tier 2 · High reliability · secondary · 2023-01-24Claim scope: Amount
Used as secondary reporting for amount and attribution context.
- SoK: A Review of Cross-Chain Bridge Hacks in 2023arXiv · Tier 2 · Medium reliability · secondary · 2025-01-06Claim scope: Incident Case
Research context for bridge-hack classification and Harmony Horizon as a reference case.
- Summary of the Horizon Bridge IncidentHarmony · Tier 1 · High reliability · primary · 2022-08-24Claim scope: Incident Case
Official incident and response summary.
- State of Harmony Q1 2023Harmony · Tier 1 · High reliability · primary · 2023-03-31Claim scope: Recovery
Official update describing treasury-funded recovery and burn activity.
- Proposal: UtilityDAO — Recovery Partner for Harmony ProtocolHarmony Community Forum · Tier 2 · Medium reliability · secondary · 2025-06-17Claim scope: Recovery
Evidence that community recovery work remained active in 2025.
Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.
Known unknowns
- The total amount repurchased, burned, or returned remains incomplete.
- The recovery program requires later outcome review.
Help maintain incident aftermath records
Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.
Report a correction
Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.