What happened
Harmony's Horizon Bridge lost about $100 million on June 23, 2022. Harmony's own incident summary described a coordinated attack on its internal infrastructure rather than a smart contract flaw, beginning with a phishing scheme that tricked at least one software developer into installing malicious software. The FBI confirmed in January 2023 that Lazarus Group and APT38 were responsible, after tracing laundering activity through Railgun.
How the deception worked
Harmony stated the attackers 'employed a phishing scheme to trick at least one software developer to install malicious software on their laptop.' That access let them read internal chat threads to learn how the bridge was operated and reach non-public bridge infrastructure code, then obtain backdoor access to one or more servers. Because the Horizon Bridge used a multisignature scheme requiring only two of five signatures, compromising the operational hosts holding those keys was enough to authorise transfers. On June 23 the attackers moved fourteen bridged asset types out in a series of transactions. Harmony emphasised the bridge contracts themselves were never exploited.
AI involvement · No AI reported
No AI involvement was reported.
The control that would have caught it· our reading, not a claim from the sources
Raising the signature threshold and isolating signing keys on dedicated hardware away from developer workstations would have meant that phishing one laptop could not produce a valid bridge withdrawal.
Sources (2)
- Summary of the Harmony Horizon Bridge IncidentHarmony·medium.comOpen ↗
- FBI: North Korean hackers stole $100 million in Harmony crypto hackBleepingComputer·bleepingcomputer.comOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.