Flow Foundation disclosed a Dec. 27 protocol-level exploit in which an attacker abused a flaw in Flow’s Cadence runtime to duplicate tokens. The post Flow DetailsFlow Foundation disclosed a Dec. 27 protocol-level exploit in which an attacker abused a flaw in Flow’s Cadence runtime to duplicate tokens. The post Flow Details

Flow Details $3.9M Token Duplication Exploit, Network Halted Within Hours

  • A protocol exploit in the Flow blockchain’s Cadence runtime on December 27 allowed an attacker to create $3.9 million in counterfeit tokens.
  • Network validators halted the chain within six hours and froze most fraudulent assets on exchanges before they could be liquidated.
  • Flow has patched the vulnerability and destroyed the counterfeit tokens via a governance-approved recovery plan, with 99% of accounts remaining unaffected.

The Flow blockchain contained a Dec. 27 protocol exploit that let an attacker create counterfeit tokens by abusing a flaw in the network’s Cadence runtime, leading to about US$3.9 million (AU$5.9 million) in confirmed losses before the incident was stopped, the Flow Foundation said Tuesday in a technical post-mortem.

The Foundation said the attacker did not break into wallets or drain existing balances. Instead, the bug allowed some assets to be duplicated in a way that bypassed normal supply controls, effectively creating extra tokens that should not have existed. 

The risk was that counterfeit tokens could be sold into real markets before being detected.

Read more: Surviving 2026: Aussie Analysts on How to Filter Financial Noise and Master the Final Cycle

How the Flow Incident Went Down

Crypto News Australia reported last week that Flow started rebuilding its network after the team realized an exploit on Saturday. It started with suspicious exchange activity tied to a large FLOW token deposit and rapid withdrawals.

Flow said validators coordinated a halt within six hours of the first malicious transaction and switched the network into a read-only mode to block “exit paths” while the team investigated. The Foundation said exchange partners also froze most of the counterfeit assets before they could be liquidated. 

Two days later, Flow restarted under an “isolated recovery” plan designed to keep valid transaction history intact while enabling a governance-approved process to recover and permanently destroy the counterfeit tokens.

Most accounts were not affected operationally. Flow said more than 99% of accounts retained full access during and after recovery, while a small number of accounts that interacted with the counterfeit tokens were temporarily restricted as a precaution.

The Foundation said it has patched the vulnerability, added stricter runtime checks, and expanded regression testing. It also said it is working with forensic partners and law enforcement, and plans to strengthen monitoring and bug-bounty programs as part of broader security hardening.

The flow token is down 53% since its launch in early December, currently trading at US$0.1012 (AU$0.15), as per CoinGecko data.

Related: Analysts Say Bitcoin Finds Its Footing as 2026 Opens, Eyes Turn to ETF Flow

The post Flow Details $3.9M Token Duplication Exploit, Network Halted Within Hours appeared first on Crypto News Australia.

Market Opportunity
FLOW Logo
FLOW Price(FLOW)
$0.09359
$0.09359$0.09359
-3.79%
USD
FLOW (FLOW) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

‘One Battle After Another’ Becomes One Of This Decade’s Best-Reviewed Movies

‘One Battle After Another’ Becomes One Of This Decade’s Best-Reviewed Movies

The post ‘One Battle After Another’ Becomes One Of This Decade’s Best-Reviewed Movies appeared on BitcoinEthereumNews.com. Topline Critics have hailed Paul Thomas Anderson’s “One Battle After Another,” starring Leonardo DiCaprio, as a “masterpiece,” indicating potential Academy Awards success as it boasts near-perfect scores on review aggregators Metacritic and Rotten Tomatoes based on early reviews. Leonardo DiCaprio stars in “One Battle After Another,” which opens in theaters next week. (Photo by Jeff Spicer/Getty Images for Warner Bros. Pictures) Getty Images for Warner Bros. Pictures Key Facts “One Battle After Another” boasts a nearly perfect 97 out of a possible 100 on Metacritic based on its first 31 reviews, making it the highest-rated movie of this decade on Metacritic’s best movies of all time list. The movie also has a 96% score on Rotten Tomatoes based on the first 56 reviews, with only two reviews considered “rotten,” or negative. The Associated Press hailed the movie as “an American masterpiece,” noting the movie touches on topical political themes and depicts a society where “gun violence, white power and immigrant deportations recur in an ongoing dance, both farcical and tragic.” The movie stars DiCaprio as an ex-revolutionary who reunites with former accomplices to rescue his 16-year-old daughter when she goes missing, and Anderson has said the movie was inspired by the 1990 novel, “Vineland.” Most critics have described the movie as an action thriller with notable chase scenes, which jumps in time from DiCaprio’s character’s early days with fictional revolutionary group, the French 75, to about 15 years later, when he is pursued by foe and military leader Captain Steven Lockjaw, played by Sean Penn. The Warner Bros.-produced film was made on a big budget, estimated to be between $130 million and $175 million, and co-stars Penn, Benicio del Toro, Regina Hall and Teyana Taylor. When Will ‘one Battle After Another’ Open In Theaters And Streaming? The move opens in…
Share
BitcoinEthereumNews2025/09/18 07:35
Vitalik: The crypto industry needs to address three major issues to develop better decentralized stablecoins.

Vitalik: The crypto industry needs to address three major issues to develop better decentralized stablecoins.

PANews reported on January 11 that Vitalik Buterin stated that the crypto industry currently needs better decentralized stablecoins, and three issues remain to
Share
PANews2026/01/11 15:47
Yingda Securities: The RMB exchange rate is likely to appreciate steadily in 2026.

Yingda Securities: The RMB exchange rate is likely to appreciate steadily in 2026.

PANews reported on January 11 that, according to Zhitong Finance, the 2026 China Chief Economist Forum Annual Meeting was held in Shanghai from January 10-11, with
Share
PANews2026/01/11 15:51