The post Flow exploit post mortem reveals protocol-level flaw behind $3.9m loss appeared on BitcoinEthereumNews.com. A post-mortem report of the Dec. 27 exploitThe post Flow exploit post mortem reveals protocol-level flaw behind $3.9m loss appeared on BitcoinEthereumNews.com. A post-mortem report of the Dec. 27 exploit

Flow exploit post mortem reveals protocol-level flaw behind $3.9m loss

A post-mortem report of the Dec. 27 exploit of the Flow blockchain has detailed a protocol-level exploit that allowed the attacker to duplicate fungible tokens and drain approximately $3.9 million in value.

Summary

  • Flow exploiter duplicated tokens via a Cadence runtime exploit.
  • Over 1 billion counterfeit FLOW tokens were sent to exchanges, with nearly half recovered and destroyed by cooperating platforms.
  • FLOW token is up 14% in the past 24 hours as the network has become fully operational.

“The attack demonstrated significant technical sophistication. The attacker deployed over 40 malicious smart contracts in a coordinated sequence,” the report published by the Flow Foundation said.

Attackers managed to exploit a major flaw in the Cadence execution layer (v1.8.8) that allowed the attacker to disguise a protected asset, which should be non-copyable, as a standard data structure that can be copied.

In simple terms, the attacker was able to duplicate rather than mint tokens, which is also why existing user balances were not directly affected.

However, Flow validators were able to initiate a network halt within six hours of the first malicious transaction, and the funds already sent to centralized exchanges were frozen by exchange partners.

“1.094 billion counterfeit FLOW was deposited by the attacker across multiple centralized exchanges. Of this, 484,434,923 FLOW has already been returned by cooperative exchange partners OKX, Gate.io, and MEXC and destroyed,” the report added.

Meanwhile, Flow has taken steps to isolate 98.7% of the remaining counterfeit supply, which is now pending destruction.

As the Foundation continues working with additional exchange partners to recover the remaining assets, it has enabled a protocol-level backstop by restricting all attacker-linked deposit addresses at the execution layer. This has been done so that the counterfeit tokens cannot be withdrawn, bridged, or transferred until they are returned for destruction.

According to the foundation, the vulnerability has been patched, and the Flow network is fully operational.

Developers opted for an “isolated recovery” plan instead of the full-chain rollback it initially sought. As previously reported by crypto.news, this was done to preserve legitimate transaction history and allow for the destruction of counterfeit assets through a governance-approved process.

FLOW, the blockchain’s native token, has managed to stage a rebound since the recovery plan was completed and the Foundation subsequently released the post-mortem.

After plunging around 40% over five hours following the hack on Dec. 27, FLOW continued sliding to a low of $0.075 on Jan. 2 before beginning to recover as the network became operational. 

In the past 24 hours, the token has rallied over 14% and was trading at $0.1015 when writing.

Source: https://crypto.news/flow-exploit-post-mortem-reveals-protocol-level-flaw-behind-3-9m-loss/

Market Opportunity
FLOW Logo
FLOW Price(FLOW)
$0.0964
$0.0964$0.0964
+2.40%
USD
FLOW (FLOW) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Crypto News: Donald Trump-Aligned Fed Governor To Speed Up Fed Rate Cuts?

Crypto News: Donald Trump-Aligned Fed Governor To Speed Up Fed Rate Cuts?

The post Crypto News: Donald Trump-Aligned Fed Governor To Speed Up Fed Rate Cuts? appeared on BitcoinEthereumNews.com. In recent crypto news, Stephen Miran swore in as the latest Federal Reserve governor on September 16, 2025, slipping into the board’s last open spot right before the Federal Open Market Committee kicks off its two-day rate discussion. Traders are betting heavily on a 25-basis-point trim, which would bring the federal funds rate down to 4.00%-4.25%, based on CME FedWatch Tool figures from September 15, 2025. Miran, who’s been Trump’s top economic advisor and a supporter of his trade ideas, joins a seven-member board where just three governors come from Democratic picks, according to the Fed’s records updated that same day. Crypto News: Miran’s Background and Quick Path to Confirmation The Senate greenlit Miran on September 15, 2025, with a tight 48-47 vote, following his nomination on September 2, 2025, as per a recent crypto news update. His stint runs only until January 31, 2026, stepping in for Adriana D. Kugler, who stepped down in August 2025 for reasons not made public. Miran earned his economics Ph.D. from Harvard and worked at the Treasury back in Trump’s first go-around. Afterward, he moved to Hudson Bay Capital Management as an economist, then looped back to the White House in December 2024 to head the Council of Economic Advisers. There, he helped craft Trump’s “reciprocal tariffs” approach, aimed at fixing trade gaps with China and the EU. He wouldn’t quit his White House gig, which irked Senator Elizabeth Warren at the September 7, 2025, confirmation hearings. That limited time frame means Miran gets to cast a vote straight away at the FOMC session starting September 16, 2025. The full board now features Chair Jerome H. Powell (Trump pick, term ends 2026), Vice Chair Philip N. Jefferson (Biden, to 2036), and folks like Lisa D. Cook (Biden, to 2028) and Michael S. Barr…
Share
BitcoinEthereumNews2025/09/18 03:14
OKX launches RIVERUSDT perpetual contracts

OKX launches RIVERUSDT perpetual contracts

PANews reported on January 9th that OKX will officially launch RIVERUSDT perpetual contracts on its website, app, and API at 15:00 (UTC+8) on January 9th, 2026.
Share
PANews2026/01/09 15:15
Two Decades of Brand Evolution: Global Top Brands Witness Transformation and Perseverance of Consumer Electronics Industry

Two Decades of Brand Evolution: Global Top Brands Witness Transformation and Perseverance of Consumer Electronics Industry

LAS VEGAS, Jan. 9, 2026 /PRNewswire/ — The Global Top Brands Award Ceremony and International Consumer Electronics Industry Leaders’ Summit were held in Las Vegas
Share
AI Journal2026/01/09 15:15