The post Flow Details December Exploit that Led to $3.9M in Counterfeit Token Losses appeared on BitcoinEthereumNews.com. The Flow Foundation on Tuesday publishedThe post Flow Details December Exploit that Led to $3.9M in Counterfeit Token Losses appeared on BitcoinEthereumNews.com. The Flow Foundation on Tuesday published

Flow Details December Exploit that Led to $3.9M in Counterfeit Token Losses

2026/01/07 15:13
3분 읽기
이 콘텐츠에 대한 의견이나 우려 사항이 있으시면 crypto.news@mexc.com으로 연락주시기 바랍니다

The Flow Foundation on Tuesday published a technical post mortem detailing a protocol-level exploit that occurred on Dec. 27, when an attacker was able to counterfeit tokens on the network, resulting in about $3.9 million in confirmed losses before the exploit was contained.

According to the report, the attacker exploited a flaw in Flow’s Cadence runtime that allowed certain assets to be duplicated rather than minted, bypassing supply controls without accessing or draining existing user balances. Validators coordinated a network halt within six hours of the first malicious transaction, while exchange partners froze most counterfeit assets before they could be sold.

Flow said the temporary halt placed the network into a read-only mode to sever exit paths and prevent further duplication while the issue was investigated. Operations resumed two days later under an “isolated recovery” plan that preserved legitimate transaction history and authorized the recovery and permanent destruction of counterfeit assets through a governance-approved process.

Source: Flow Blockchain

The Flow Foundation, which supports the Flow network, said no existing user balances were compromised, as the exploit duplicated assets rather than removing funds from accounts. A limited number of accounts that interacted with counterfeit tokens were temporarily restricted as a precaution, while more than 99% of accounts retained full access during and after the recovery.

While the attacker generated a large volume of counterfeit tokens onchain, Flow said the vast majority were contained or frozen before liquidation.

The Foundation said it has since patched the underlying vulnerability, added stricter runtime checks and expanded regression testing to prevent similar exploits. It also is working with forensic partners and law enforcement and plans to strengthen monitoring and bug-bounty programs as part of broader security hardening.

Related: NFTs shifted to utility and culture as price faded in 2025

Flow’s post-NFT downturn

Dapper Labs, the creators of the non-fungible token project CryptoKitties, announced the development of Flow in September 2019 as a new layer-1 blockchain designed to address scalability challenges facing consumer applications such as games and digital collectibles. 

Early success with NBA Top Shot, an NFT platform for trading officially licensed NBA video highlights, helped bring mainstream attention to the Flow blockchain in 2020 and 2021. Against this backdrop, the network’s FLOW token surged past $40 in 2021, according to data from CoinGecko.

Flow’s momentum carried into 2022, where the project raised about $725 million from investors, including Andreessen Horowitz (a16z) and Union Square Ventures, to support ecosystem development.

As activity across the NFT market cooled in the years that followed, the FLOW token also lost momentum and has since fallen outside the top 300 cryptocurrencies by market capitalization.

The decline accelerated following the Dec. 27 hack, when FLOW plunged by around 40% over five hours.

The token later slid to a low of $0.075 on Friday before beginning to recover. It was trading near $0.10 at the time of writing, up about 16% over the past 24 hours, according to Cointelegraph data.

Source: CoinGecko

Magazine: Big questions: Would Bitcoin survive a 10-year power outage?

Source: https://cointelegraph.com/news/flow-details-december-exploit-3-9m-counterfeit-token-losses?utm_source=rss_feed&utm_medium=feed&utm_campaign=rss_partner_inbound

시장 기회
플로우 로고
플로우 가격(FLOW)
$0.03129
$0.03129$0.03129
-1.23%
USD
플로우 (FLOW) 실시간 가격 차트
면책 조항: 본 사이트에 재게시된 글들은 공개 플랫폼에서 가져온 것으로 정보 제공 목적으로만 제공됩니다. 이는 반드시 MEXC의 견해를 반영하는 것은 아닙니다. 모든 권리는 원저자에게 있습니다. 제3자의 권리를 침해하는 콘텐츠가 있다고 판단될 경우, crypto.news@mexc.com으로 연락하여 삭제 요청을 해주시기 바랍니다. MEXC는 콘텐츠의 정확성, 완전성 또는 시의적절성에 대해 어떠한 보증도 하지 않으며, 제공된 정보에 기반하여 취해진 어떠한 조치에 대해서도 책임을 지지 않습니다. 본 콘텐츠는 금융, 법률 또는 기타 전문적인 조언을 구성하지 않으며, MEXC의 추천이나 보증으로 간주되어서는 안 됩니다.

USD1 Genesis: 0 Fees + 12% APR

USD1 Genesis: 0 Fees + 12% APRUSD1 Genesis: 0 Fees + 12% APR

New users: stake for up to 600% APR. Limited time!