Flow halts after a $3.9m exploit, ditches a full rollback plan and opts for targeted token burns to preserve user activity and restore trust. Flow blockchain’s Flow halts after a $3.9m exploit, ditches a full rollback plan and opts for targeted token burns to preserve user activity and restore trust. Flow blockchain’s

Flow faces rollback backlash after $3.9m exploit hits execution layer

2025/12/29 18:35
3분 읽기
이 콘텐츠에 대한 의견이나 우려 사항이 있으시면 crypto.news@mexc.com으로 연락주시기 바랍니다

Flow halts after a $3.9m exploit, ditches a full rollback plan and opts for targeted token burns to preserve user activity and restore trust.

Summary
  • An attacker exploited Flow’s execution layer for about $3.9m via cross-chain bridges before validators halted the network and sought freezes from issuers and exchanges.​
  • A proposed rollback to a pre-attack checkpoint drew criticism from bridge operators and lawyers, who warned of doubled balances, unbacked assets and trust damage.​
  • Flow’s revised plan scraps a global rollback, targets fraudulent mints, phases the restart and restricts flagged accounts while preserving legitimate user activity.

Flow blockchain’s proposal to reverse transactions following a $3.9 million exploit triggered opposition from ecosystem partners, prompting the network’s foundation to revise its remediation approach.

Flow crypto moves along with cross-chain bridges

An attacker exploited a vulnerability in Flow’s (FLOW) execution layer on Dec. 27, extracting approximately $3.9 million in assets through multiple cross-chain bridges before validators halted the chain, according to Flow Foundation. The foundation and forensic partner FindLabs stated that existing user balances were not accessed and that the exploit was contained, with freeze requests sent to major exchanges and stablecoin issuers.

The attacker’s Ethereum wallet was identified, and investigators reported tracking laundering attempts through Thorchain and Chainflip.

Flow core developers proposed a rollback to a checkpoint prior to the exploit, which would erase all transactions submitted during a several-hour window and require users and infrastructure providers to resubmit activity. The Foundation stated the rollback would neutralize unauthorized minting and restore the ledger.

Alex Smirnov, founder of cross-chain bridge deBridge, said he learned of the rollback decision after its public announcement. Smirnov warned that reverting the chain could create doubled balances for users who bridged assets out during the rollback window, while leaving others who bridged in facing losses with no clear reimbursement plan. He called on Flow validators to halt transaction validation until the Foundation clarified resolution of these cases and how custodians such as LayerZero, the primary USDC custodian on Flow, would handle affected transfers.

Flowscan data showed the network stalled at a fixed block height for an extended period. The FLOW token declined following the exploit and rollback announcement, and some centralized exchanges temporarily suspended transactions, according to market data.

DefiLlama data showed Flow’s total value locked dropped after the incident before partially rebounding within 24 hours.

Gabriel Shapiro, general counsel at Delphi Labs, stated the approach risked pushing losses onto bridges and issuers by creating unbacked assets. Smirnov argued that financial damage from a rollback could exceed the original exploit. Chain rollbacks remain rare in cryptocurrency networks due to concerns about reversing confirmed transactions and questions regarding decentralization.

On Dec. 29, Flow Foundation announced a revised remediation plan developed in consultation with bridge operators, exchanges, and validators. The updated approach abandoned a global rollback and instead focused on isolating and destroying fraudulently minted tokens while preserving legitimate user activity. Dapper Labs, which launched Flow, said it reviewed and supported the revised plan and that no Dapper Labs user balances or assets were impacted.

Under the new plan, the network would restart in phases, temporarily restricting accounts identified through forensic analysis as recipients of illicit tokens. Validators approved a software upgrade enabling the targeted remediation, and the network returned online in a read-only testing mode ahead of a phased restoration. The Foundation stated the majority of accounts would remain unaffected, with ongoing updates promised as normal operations gradually resume.

시장 기회
플로우 로고
플로우 가격(FLOW)
$0.03122
$0.03122$0.03122
-0.06%
USD
플로우 (FLOW) 실시간 가격 차트
면책 조항: 본 사이트에 재게시된 글들은 공개 플랫폼에서 가져온 것으로 정보 제공 목적으로만 제공됩니다. 이는 반드시 MEXC의 견해를 반영하는 것은 아닙니다. 모든 권리는 원저자에게 있습니다. 제3자의 권리를 침해하는 콘텐츠가 있다고 판단될 경우, crypto.news@mexc.com으로 연락하여 삭제 요청을 해주시기 바랍니다. MEXC는 콘텐츠의 정확성, 완전성 또는 시의적절성에 대해 어떠한 보증도 하지 않으며, 제공된 정보에 기반하여 취해진 어떠한 조치에 대해서도 책임을 지지 않습니다. 본 콘텐츠는 금융, 법률 또는 기타 전문적인 조언을 구성하지 않으며, MEXC의 추천이나 보증으로 간주되어서는 안 됩니다.

USD1 Genesis: 0 Fees + 12% APR

USD1 Genesis: 0 Fees + 12% APRUSD1 Genesis: 0 Fees + 12% APR

New users: stake for up to 600% APR. Limited time!