Flow Details $3.9M Exploit After Cadence Flaw Allowed Token Duplication

image

Source: DefiPlanet Original Title: Flow details $3.9M exploit after Cadence flaw allowed token duplication Original Link:

Quick Breakdown

  • A Cadence runtime flaw allowed token duplication, leading to $3.9M in confirmed losses.
  • No user balances were drained; most counterfeit assets were frozen before liquidation.
  • Flow has patched the issue and rolled out tighter security and monitoring measures.

Technical Details

The Flow Foundation released a technical post-mortem explaining a protocol-level exploit that allowed an attacker to counterfeit tokens on the network, causing an estimated $3.9 million in losses before the incident was contained.

The exploit, which occurred on December 27, stemmed from a flaw in Flow’s Cadence runtime that allowed certain assets to be duplicated instead of properly minted. This bypassed supply controls but did not involve draining or accessing existing user balances.

Validators identified the malicious activity and coordinated a network halt within six hours of the first exploit transaction. During the pause, the blockchain was placed in a read-only state to prevent further asset duplication, while major exchange partners froze most counterfeit tokens before they could be sold.

Flow said normal operations resumed two days later following an “isolated recovery” process that preserved legitimate transaction history and enabled the recovery and permanent destruction of fake assets through governance approval.

The Foundation stressed that no user funds were stolen, as the exploit involved duplication rather than removal of assets. A small number of accounts that interacted with counterfeit tokens were temporarily restricted, while more than 99% of users retained full access throughout the recovery.

Security Patch and Future Measures

While the attacker created a large volume of counterfeit tokens onchain, Flow said most were contained or frozen before liquidation could occur.

The underlying vulnerability has since been patched, with the Foundation introducing stricter runtime checks, expanded regression testing, and enhanced monitoring tools. Flow is also working with forensic specialists and law enforcement, while committing to stronger bug-bounty and security hardening programs going forward.

Market Context

Flow was launched by Dapper Labs in 2019 to support consumer-focused blockchain applications, gaining early traction through NBA Top Shot, which helped push the FLOW token above $40 during the 2021 NFT boom.

The project raised roughly $725 million in 2022 from investors, including Andreessen Horowitz and Union Square Ventures, but momentum slowed as NFT activity declined. FLOW has since dropped outside the top 300 cryptocurrencies by market cap.

FLOW-1,19%
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
0/400
No comments
  • Pin

Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate App
Community
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)