Flow Foundation disclosed a Dec. 27 protocol-level exploit in which an attacker abused a flaw in Flow’s Cadence runtime to duplicate tokens. The post Flow DetailsFlow Foundation disclosed a Dec. 27 protocol-level exploit in which an attacker abused a flaw in Flow’s Cadence runtime to duplicate tokens. The post Flow Details

Flow Details $3.9M Token Duplication Exploit, Network Halted Within Hours

2026/01/07 14:23
3분 읽기
이 콘텐츠에 대한 의견이나 우려 사항이 있으시면 crypto.news@mexc.com으로 연락주시기 바랍니다
  • A protocol exploit in the Flow blockchain’s Cadence runtime on December 27 allowed an attacker to create $3.9 million in counterfeit tokens.
  • Network validators halted the chain within six hours and froze most fraudulent assets on exchanges before they could be liquidated.
  • Flow has patched the vulnerability and destroyed the counterfeit tokens via a governance-approved recovery plan, with 99% of accounts remaining unaffected.

The Flow blockchain contained a Dec. 27 protocol exploit that let an attacker create counterfeit tokens by abusing a flaw in the network’s Cadence runtime, leading to about US$3.9 million (AU$5.9 million) in confirmed losses before the incident was stopped, the Flow Foundation said Tuesday in a technical post-mortem.

The Foundation said the attacker did not break into wallets or drain existing balances. Instead, the bug allowed some assets to be duplicated in a way that bypassed normal supply controls, effectively creating extra tokens that should not have existed. 

The risk was that counterfeit tokens could be sold into real markets before being detected.

Read more: Surviving 2026: Aussie Analysts on How to Filter Financial Noise and Master the Final Cycle

How the Flow Incident Went Down

Crypto News Australia reported last week that Flow started rebuilding its network after the team realized an exploit on Saturday. It started with suspicious exchange activity tied to a large FLOW token deposit and rapid withdrawals.

Flow said validators coordinated a halt within six hours of the first malicious transaction and switched the network into a read-only mode to block “exit paths” while the team investigated. The Foundation said exchange partners also froze most of the counterfeit assets before they could be liquidated. 

Two days later, Flow restarted under an “isolated recovery” plan designed to keep valid transaction history intact while enabling a governance-approved process to recover and permanently destroy the counterfeit tokens.

Most accounts were not affected operationally. Flow said more than 99% of accounts retained full access during and after recovery, while a small number of accounts that interacted with the counterfeit tokens were temporarily restricted as a precaution.

The Foundation said it has patched the vulnerability, added stricter runtime checks, and expanded regression testing. It also said it is working with forensic partners and law enforcement, and plans to strengthen monitoring and bug-bounty programs as part of broader security hardening.

The flow token is down 53% since its launch in early December, currently trading at US$0.1012 (AU$0.15), as per CoinGecko data.

Related: Analysts Say Bitcoin Finds Its Footing as 2026 Opens, Eyes Turn to ETF Flow

The post Flow Details $3.9M Token Duplication Exploit, Network Halted Within Hours appeared first on Crypto News Australia.

시장 기회
플로우 로고
플로우 가격(FLOW)
$0.0313
$0.0313$0.0313
-1.19%
USD
플로우 (FLOW) 실시간 가격 차트
면책 조항: 본 사이트에 재게시된 글들은 공개 플랫폼에서 가져온 것으로 정보 제공 목적으로만 제공됩니다. 이는 반드시 MEXC의 견해를 반영하는 것은 아닙니다. 모든 권리는 원저자에게 있습니다. 제3자의 권리를 침해하는 콘텐츠가 있다고 판단될 경우, crypto.news@mexc.com으로 연락하여 삭제 요청을 해주시기 바랍니다. MEXC는 콘텐츠의 정확성, 완전성 또는 시의적절성에 대해 어떠한 보증도 하지 않으며, 제공된 정보에 기반하여 취해진 어떠한 조치에 대해서도 책임을 지지 않습니다. 본 콘텐츠는 금융, 법률 또는 기타 전문적인 조언을 구성하지 않으며, MEXC의 추천이나 보증으로 간주되어서는 안 됩니다.

USD1 Genesis: 0 Fees + 12% APR

USD1 Genesis: 0 Fees + 12% APRUSD1 Genesis: 0 Fees + 12% APR

New users: stake for up to 600% APR. Limited time!