The post Flow Details December Exploit that Led to $3.9M in Counterfeit Token Losses appeared on BitcoinEthereumNews.com. The Flow Foundation on Tuesday publishedThe post Flow Details December Exploit that Led to $3.9M in Counterfeit Token Losses appeared on BitcoinEthereumNews.com. The Flow Foundation on Tuesday published

Flow Details December Exploit that Led to $3.9M in Counterfeit Token Losses

The Flow Foundation on Tuesday published a technical post mortem detailing a protocol-level exploit that occurred on Dec. 27, when an attacker was able to counterfeit tokens on the network, resulting in about $3.9 million in confirmed losses before the exploit was contained.

According to the report, the attacker exploited a flaw in Flow’s Cadence runtime that allowed certain assets to be duplicated rather than minted, bypassing supply controls without accessing or draining existing user balances. Validators coordinated a network halt within six hours of the first malicious transaction, while exchange partners froze most counterfeit assets before they could be sold.

Flow said the temporary halt placed the network into a read-only mode to sever exit paths and prevent further duplication while the issue was investigated. Operations resumed two days later under an “isolated recovery” plan that preserved legitimate transaction history and authorized the recovery and permanent destruction of counterfeit assets through a governance-approved process.

Source: Flow Blockchain

The Flow Foundation, which supports the Flow network, said no existing user balances were compromised, as the exploit duplicated assets rather than removing funds from accounts. A limited number of accounts that interacted with counterfeit tokens were temporarily restricted as a precaution, while more than 99% of accounts retained full access during and after the recovery.

While the attacker generated a large volume of counterfeit tokens onchain, Flow said the vast majority were contained or frozen before liquidation.

The Foundation said it has since patched the underlying vulnerability, added stricter runtime checks and expanded regression testing to prevent similar exploits. It also is working with forensic partners and law enforcement and plans to strengthen monitoring and bug-bounty programs as part of broader security hardening.

Related: NFTs shifted to utility and culture as price faded in 2025

Flow’s post-NFT downturn

Dapper Labs, the creators of the non-fungible token project CryptoKitties, announced the development of Flow in September 2019 as a new layer-1 blockchain designed to address scalability challenges facing consumer applications such as games and digital collectibles. 

Early success with NBA Top Shot, an NFT platform for trading officially licensed NBA video highlights, helped bring mainstream attention to the Flow blockchain in 2020 and 2021. Against this backdrop, the network’s FLOW token surged past $40 in 2021, according to data from CoinGecko.

Flow’s momentum carried into 2022, where the project raised about $725 million from investors, including Andreessen Horowitz (a16z) and Union Square Ventures, to support ecosystem development.

As activity across the NFT market cooled in the years that followed, the FLOW token also lost momentum and has since fallen outside the top 300 cryptocurrencies by market capitalization.

The decline accelerated following the Dec. 27 hack, when FLOW plunged by around 40% over five hours.

The token later slid to a low of $0.075 on Friday before beginning to recover. It was trading near $0.10 at the time of writing, up about 16% over the past 24 hours, according to Cointelegraph data.

Source: CoinGecko

Magazine: Big questions: Would Bitcoin survive a 10-year power outage?

Source: https://cointelegraph.com/news/flow-details-december-exploit-3-9m-counterfeit-token-losses?utm_source=rss_feed&utm_medium=feed&utm_campaign=rss_partner_inbound

Market Opportunity
FLOW Logo
FLOW Price(FLOW)
$0.04604
$0.04604$0.04604
+2.37%
USD
FLOW (FLOW) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Propel to Report Q4 and Full Year 2025 Financial Results and Announces Dividend Increase

Propel to Report Q4 and Full Year 2025 Financial Results and Announces Dividend Increase

TORONTO, Feb. 10, 2026 /CNW/ – Propel Holdings Inc. (“Propel”) (TSX: PRL), the fintech facilitating access to credit for underserved consumers, announced today
Share
AI Journal2026/02/11 09:15
UK crypto holders brace for FCA’s expanded regulatory reach

UK crypto holders brace for FCA’s expanded regulatory reach

The post UK crypto holders brace for FCA’s expanded regulatory reach appeared on BitcoinEthereumNews.com. British crypto holders may soon face a very different landscape as the Financial Conduct Authority (FCA) moves to expand its regulatory reach in the industry. A new consultation paper outlines how the watchdog intends to apply its rulebook to crypto firms, shaping everything from asset safeguarding to trading platform operation. According to the financial regulator, these proposals would translate into clearer protections for retail investors and stricter oversight of crypto firms. UK FCA plans Until now, UK crypto users mostly encountered the FCA through rules on promotions and anti-money laundering checks. The consultation paper goes much further. It proposes direct oversight of stablecoin issuers, custodians, and crypto-asset trading platforms (CATPs). For investors, that means the wallets, exchanges, and coins they rely on could soon be subject to the same governance and resilience standards as traditional financial institutions. The regulator has also clarified that firms need official authorization before serving customers. This condition should, in theory, reduce the risk of sudden platform failures or unclear accountability. David Geale, the FCA’s executive director of payments and digital finance, said the proposals are designed to strike a balance between innovation and protection. He explained: “We want to develop a sustainable and competitive crypto sector – balancing innovation, market integrity and trust.” Geale noted that while the rules will not eliminate investment risks, they will create consistent standards, helping consumers understand what to expect from registered firms. Why does this matter for crypto holders? The UK regulatory framework shift would provide safer custody of assets, better disclosure of risks, and clearer recourse if something goes wrong. However, the regulator was also frank in its submission, arguing that no rulebook can eliminate the volatility or inherent risks of holding digital assets. Instead, the focus is on ensuring that when consumers choose to invest, they do…
Share
BitcoinEthereumNews2025/09/17 23:52
The Inner Circle acknowledges Catherine B. Murphy as a Pinnacle Professional Member Inner Circle of Excellence

The Inner Circle acknowledges Catherine B. Murphy as a Pinnacle Professional Member Inner Circle of Excellence

PUNTA CANA, Fla., Feb. 10, 2026 /PRNewswire/ — Prominently featured in The Inner Circle, Catherine B. Murphy is acknowledged as a Pinnacle Professional Member Inner
Share
AI Journal2026/02/11 09:45