Flow network suffers Cadence virtual machine vulnerability attack: 87.9 billion FLOW forged, 98.7% of illegal assets already frozen

【BitPush】The Flow network experienced a serious security incident on December 27, 2025. Attackers exploited a type confusion vulnerability in the Cadence virtual machine to construct a complex “three-part vulnerability chain” to break through the resource linear guarantee mechanism, ultimately achieving illegal copying by disguising resource objects as structures. The scope of this attack was quite broad—the attackers created a total of 87.96 billion FLOW tokens and various other assets.

How severe was the economic loss? Approximately $3.9 million was directly evaporated, and funds flowed to other networks through cross-chain bridges such as Celer and deBridge. Among them, 1.094 billion FLOW tokens were transferred to centralized exchanges, which should have been the riskiest part. Fortunately, Flow’s validator team responded quickly and immediately shut down the network. They also worked closely with leading exchanges like OKX, Gate.io, and MEXC to freeze illegal assets on-chain and on exchanges. The final result was: 98.7% of the illegal assets were successfully frozen, and about 484 million FLOW tokens were destroyed.

The network was restarted on December 29 through an “Isolation Recovery Plan,” deploying patches that included parameter validation, runtime checks, and contract deployment logic. This incident also serves as a reminder that even well-known public chains need to continuously strengthen their security defenses.

FLOW-3,26%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 7
  • Repost
  • Share
Comment
0/400
JustHodlItvip
· 01-08 09:56
87.9 billion FLOW created out of thin air? That's so outrageous. Are virtual machine vulnerabilities this wild?
View OriginalReply0
WagmiAnonvip
· 01-08 06:35
87.9 billion FLOW created out of thin air, how outrageous is that... Are virtual machine vulnerabilities really that deadly?
View OriginalReply0
ForkTonguevip
· 01-07 20:04
87.9 billion FLOW tokens created out of thin air? That's really outrageous. The virtual machine vulnerability directly turned it into a printing press... Fortunately, the team responded quickly and shut it down, or else it would have been a bloodbath.
View OriginalReply0
GameFiCriticvip
· 01-06 17:18
87.9 billion fake FLOW, I knew it was doomed as soon as this data came out... But wait, validators reacted so quickly? Direct shutdown + exchange collaboration? This move is impressive, at least it shows the governance system can still save the situation. The key issue is the vulnerability in the Cadence virtual machine layer... Blockchain security has taken another hit. When can we finally get it solidly right?
View OriginalReply0
RugPullAlertBotvip
· 01-06 17:08
Another virtual machine vulnerability... This time Flow was directly exploited for 87.9 billion tokens. I really can't take it anymore. That's why I always emphasize the importance of project teams' emergency response. Fortunately, exchanges responded quickly; otherwise, this could have blown up sky-high. Low-level bugs like type confusion are really hard to prevent. Cadence needs to thoroughly review its code. 3.9 million was lost directly. Luckily, most of it was frozen. One more second of delay, and it might have been gone entirely. Flow's validators really came through this time, shutting down quickly... If it were another chain, they would have already run away.
View OriginalReply0
MidsommarWalletvip
· 01-06 17:02
87.9 billion FLOW appeared out of nowhere. How crazy is that? What's going on with the Cadence virtual machine...
View OriginalReply0
ResearchChadButBrokevip
· 01-06 16:55
87.9 billion FLOW appeared out of nowhere, this is just outrageous... Is it really that easy to exploit a virtual machine vulnerability?
View OriginalReply0
  • Pin

Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate App
Community
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)