Flow Network Exploit Post-mortem
On December 27, 2025, an attacker exploited a vulnerability in the Flow network to counterfeit tokens, extracting approximately $3.9 million USD across bridges. No existing user balances were accessed or compromised. The attack duplicated assets but did not touch legitimate holdings, with the vast majority of counterfeit assets being contained onchain or frozen by exchange partners before they could be liquidated. Network validators have ratified a decentralized governance action authorizing the permanent destruction of 100% of counterfeit assets. The network resumed operations on December 29th and is operating as expected with full transaction history preserved.
The attack demonstrated significant technical sophistication. The attacker deployed over 40 malicious smart contracts in a coordinated sequence, exploiting a three-part attack chain. The root cause was a type confusion vulnerability in the Cadence runtime (v1.8.8), now patched (v1.8.9 and later). The flaw allowed the attacker to disguise a protected asset (which should be non-copyable) as a standard data structure (which can be copied), bypassing the runtime's safety checks and enabling token counterfeiting.
Full technical details of the vulnerability, exploit mechanism, forensic analysis, and remediation architecture are found on the latest Flow post in the below link:
🔗 https://x.com/flow_blockchain/status/2008612688755130840
Post #488
3.02K