The post Flow Details December Exploit that Led to $3.9M in Counterfeit Token Losses appeared on BitcoinEthereumNews.com. The Flow Foundation on Tuesday publishedThe post Flow Details December Exploit that Led to $3.9M in Counterfeit Token Losses appeared on BitcoinEthereumNews.com. The Flow Foundation on Tuesday published

Flow Details December Exploit that Led to $3.9M in Counterfeit Token Losses

3 min read

The Flow Foundation on Tuesday published a technical post mortem detailing a protocol-level exploit that occurred on Dec. 27, when an attacker was able to counterfeit tokens on the network, resulting in about $3.9 million in confirmed losses before the exploit was contained.

According to the report, the attacker exploited a flaw in Flow’s Cadence runtime that allowed certain assets to be duplicated rather than minted, bypassing supply controls without accessing or draining existing user balances. Validators coordinated a network halt within six hours of the first malicious transaction, while exchange partners froze most counterfeit assets before they could be sold.

Flow said the temporary halt placed the network into a read-only mode to sever exit paths and prevent further duplication while the issue was investigated. Operations resumed two days later under an “isolated recovery” plan that preserved legitimate transaction history and authorized the recovery and permanent destruction of counterfeit assets through a governance-approved process.

Source: Flow Blockchain

The Flow Foundation, which supports the Flow network, said no existing user balances were compromised, as the exploit duplicated assets rather than removing funds from accounts. A limited number of accounts that interacted with counterfeit tokens were temporarily restricted as a precaution, while more than 99% of accounts retained full access during and after the recovery.

While the attacker generated a large volume of counterfeit tokens onchain, Flow said the vast majority were contained or frozen before liquidation.

The Foundation said it has since patched the underlying vulnerability, added stricter runtime checks and expanded regression testing to prevent similar exploits. It also is working with forensic partners and law enforcement and plans to strengthen monitoring and bug-bounty programs as part of broader security hardening.

Related: NFTs shifted to utility and culture as price faded in 2025

Flow’s post-NFT downturn

Dapper Labs, the creators of the non-fungible token project CryptoKitties, announced the development of Flow in September 2019 as a new layer-1 blockchain designed to address scalability challenges facing consumer applications such as games and digital collectibles. 

Early success with NBA Top Shot, an NFT platform for trading officially licensed NBA video highlights, helped bring mainstream attention to the Flow blockchain in 2020 and 2021. Against this backdrop, the network’s FLOW token surged past $40 in 2021, according to data from CoinGecko.

Flow’s momentum carried into 2022, where the project raised about $725 million from investors, including Andreessen Horowitz (a16z) and Union Square Ventures, to support ecosystem development.

As activity across the NFT market cooled in the years that followed, the FLOW token also lost momentum and has since fallen outside the top 300 cryptocurrencies by market capitalization.

The decline accelerated following the Dec. 27 hack, when FLOW plunged by around 40% over five hours.

The token later slid to a low of $0.075 on Friday before beginning to recover. It was trading near $0.10 at the time of writing, up about 16% over the past 24 hours, according to Cointelegraph data.

Source: CoinGecko

Magazine: Big questions: Would Bitcoin survive a 10-year power outage?

Source: https://cointelegraph.com/news/flow-details-december-exploit-3-9m-counterfeit-token-losses?utm_source=rss_feed&utm_medium=feed&utm_campaign=rss_partner_inbound

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Trump roasts Mike Johnson for saying grace at prayer event: 'Excuse me, it's lunch!'

Trump roasts Mike Johnson for saying grace at prayer event: 'Excuse me, it's lunch!'

President Donald Trump in a speech at this year's National Prayer Breakfast roasted House Speaker Mike Johnson (R-LA) for saying grace at meals.The 79-year-old
Share
Rawstory2026/02/05 23:11
Where Can You Turn $1,000 Into $5,000 This Week? Experts Point Towards Remittix As The Best Option

Where Can You Turn $1,000 Into $5,000 This Week? Experts Point Towards Remittix As The Best Option

Cryptocurrency markets are again showing that opportunities can emerge when fundamentals, timing and demand intersect. Amid sideways price action in many major
Share
Techbullion2026/02/05 23:13
UK Looks to US to Adopt More Crypto-Friendly Approach

UK Looks to US to Adopt More Crypto-Friendly Approach

The post UK Looks to US to Adopt More Crypto-Friendly Approach appeared on BitcoinEthereumNews.com. The UK and US are reportedly preparing to deepen cooperation on digital assets, with Britain looking to copy the Trump administration’s crypto-friendly stance in a bid to boost innovation.  UK Chancellor Rachel Reeves and US Treasury Secretary Scott Bessent discussed on Tuesday how the two nations could strengthen their coordination on crypto, the Financial Times reported on Tuesday, citing people familiar with the matter.  The discussions also involved representatives from crypto companies, including Coinbase, Circle Internet Group and Ripple, with executives from the Bank of America, Barclays and Citi also attending, according to the report. The agreement was made “last-minute” after crypto advocacy groups urged the UK government on Thursday to adopt a more open stance toward the industry, claiming its cautious approach to the sector has left the country lagging in innovation and policy.  Source: Rachel Reeves Deal to include stablecoins, look to unlock adoption Any deal between the countries is likely to include stablecoins, the Financial Times reported, an area of crypto that US President Donald Trump made a policy priority and in which his family has significant business interests. The Financial Times reported on Monday that UK crypto advocacy groups also slammed the Bank of England’s proposal to limit individual stablecoin holdings to between 10,000 British pounds ($13,650) and 20,000 pounds ($27,300), claiming it would be difficult and expensive to implement. UK banks appear to have slowed adoption too, with around 40% of 2,000 recently surveyed crypto investors saying that their banks had either blocked or delayed a payment to a crypto provider.  Many of these actions have been linked to concerns over volatility, fraud and scams. The UK has made some progress on crypto regulation recently, proposing a framework in May that would see crypto exchanges, dealers, and agents treated similarly to traditional finance firms, with…
Share
BitcoinEthereumNews2025/09/18 02:21