Loading...
[Flow Reviews Security Incident and Fixes Cadence Type Confusion Vulnerability] Flow released a report reviewing the attack incident, where attackers exploited a vulnerability in the Flow network to forge tokens and stole approximately $3.9 million through bridging. The attack did not compromise existing user balances, and most of the forged assets have been stored on-chain or frozen by exchanges. Network validators approved the destruction of all forged assets, and the network resumed operations on December 29, 2025. The attackers deployed over 40 malicious contracts, leveraging a type confusion vulnerability in the Cadence runtime (v1.8.8) to forge tokens. This vulnerability has been fixed (v1.8.9 and later versions). Approximately 50% of the forged FLOW deposits have been returned and destroyed by exchanges such as OKX, Gate, and MEXC. The foundation is continuing its investigation in collaboration with blockchain forensics partners and law enforcement agencies.