Skip to content
Flow Network Neutralizes $3.9M Exploit After Sophisticated Token Counterfeiting Attack

Flow Network Neutralizes $3.9M Exploit After Sophisticated Token Counterfeiting Attack

Castlecrypto.Gg • February 1, 2026

Flow disclosed that an attacker exploited a low-level vulnerability in its Cadence execution environment on December 27, 2025, enabling the duplication of fungible tokens rather than unauthorized minting or wallet access.

Crucially, no legitimate user balances were drained or modified. Instead, the attacker counterfeited assets by duplicating existing token objects, allowing a portion to be bridged off-network before containment measures were activated. The confirmed economic damage amounted to approximately $3.9 million, reflecting only the assets successfully settled outside the Flow ecosystem.

According to Flow’s technical post-mortem , the exploit required significant sophistication. The attacker deployed more than 40 malicious smart contracts and chained together three distinct weaknesses in the Cadence runtime.

At the core was a type-confusion flaw that allowed protected, non-copyable resource objects to masquerade as standard data structures. This bypassed runtime safeguards designed to enforce asset linearity, enabling token duplication without triggering supply invariant checks.

The vulnerability did not stem from the Fungible Token standard itself, but from execution-layer validation gaps – a distinction the Flow team emphasized repeatedly in its disclosure.

Once anomalous cross-environment transfers were detected, Flow validators coordinated a network-wide halt, cutting off exit routes within hours of the first malicious transaction. The network entered a controlled read-only state while forensic analysis and remediation began.

Most counterfeit assets were either isolated onchain or frozen at centralized exchanges due to abnormal deposit patterns and internal AML controls. Major exchanges cooperated quickly, with several returning frozen assets for destruction.

Flow confirmed that more than 98% of counterfeit tokens never entered active circulation.

Rather than reverting the blockchain to a prior state, Flow opted for an Isolated Recovery Plan. This approach preserved all legitimate transaction history while surgically neutralizing counterfeit assets through validator-approved governance actions.

Temporary restrictions were placed on just over 1,000 accounts, representing less than 0.01% of total network accounts. Most restrictions were lifted within 24 hours following verification that no counterfeit assets remained.

The network fully resumed normal operations on December 29, with transaction history intact and bridges gradually re-enabled after independent stability checks.

Flow has since rolled out comprehensive fixes addressing every stage of the exploit chain. These include stricter static type validation during contract initialization, extended runtime checks for built-in types, and mandatory type matching during contract deployment.

The exploit pattern has been integrated into Flow’s regression test suite, and additional static analysis tooling has been deployed to detect similar attack vectors early. The foundation also committed to expanding its bug bounty program to reflect the network’s growing total value.

More News: Trust Wallet Issues Security Alert for Browser Extension Users

For more information on stablecoin adoption and blockchain innovation globally, keep checking Castlecrypto News.

Extracted Entities

Platforms (2)