Flow hack — December 2025
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | December 27, 2025 |
| Target type | Blockchain or validator set |
| Loss | $3,900,000Price at time of incident |
| Method | Contract logic errorA type-confusion vulnerability in the Cadence runtime. Malformed transaction arguments smuggled invalid fields past attachment import validation; resources were hidden inside built-in types such as PublicKey that lacked deep validation; and a mismatch between static and dynamic types during contract deployment allowed resources to be copied. The result was counterfeit fungible tokens minted outside the supply. |
| Chains | Other, Ethereum |
| Outcome | Partially recovered |
What happened
Flow, a layer-1 blockchain, was attacked across 26 and 27 December 2025 through a type-confusion vulnerability in its Cadence runtime (v1.8.8). Flow's own technical post-mortem describes a three-stage chain: malformed transaction arguments smuggled invalid fields past attachment import validation; resources were hidden inside built-in types such as PublicKey, which were not deeply validated; and a mismatch between static argument types and contract initializer parameters allowed resources to be copied — statically treating a value as a struct while dynamically executing it as a resource. Starting at 23:25 PST on 26 December the attacker deployed more than 40 malicious contracts in a coordinated sequence and used them to counterfeit 87,960,930,222 units of FLOW along with twelve other fungible tokens.
Counterfeit tokens were sent to exchange deposit accounts and swapped on decentralised exchanges. Validators halted the network at 05:23 PST on 27 December, roughly six hours after the first malicious deployment.
Flow puts the realised loss at approximately $3.9 million, meaning the portion successfully bridged off-network through Celer, deBridge and Stargate and then laundered via THORChain and Chainflip. Its forensic table records 99.25% of the counterfeit FLOW as accounted for; the post-mortem's summary section states 98.7% of counterfeit assets were isolated onchain or frozen by exchanges. 484,434,923 FLOW were recovered and destroyed with the cooperation of OKX, Gate.io and MEXC. Of roughly 47.9 million counterfeit FLOW swapped on decentralised exchanges, the 11.3 million swapped on IncrementFi was recovered by the Community Governance Council, while the 36.6 million swapped on KittyPunch left the network via bridges and forms part of the $3.9 million realised loss.
Flow initially proposed rolling the chain back. Ecosystem partners objected; deBridge co-founder Alex Smirnov said his team received "zero communication or coordination" from Flow before the plan was proposed and warned of unresolved liabilities for users who had bridged assets during the window. Flow abandoned the rollback on 29 December and restarted from the last sealed block instead, temporarily restricting 1,060 accounts for forensic review; full operational restoration followed on 2 January 2026. FLOW fell more than 40% intraday, from about $0.17 to a low of $0.079.
Sources
- Flow FoundationPrimary · retrieved 2026-08-01
- CoinDeskSecondary · retrieved 2026-08-01
- The BlockSecondary · retrieved 2026-08-01
- The BlockSecondary · retrieved 2026-08-01
Official post-mortem: https://flow.com/post/dec-27-technical-post-mortem
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Flow hack — December 2025", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/flow-blockchainhttps://itokenly.com/hacks/flow-blockchainPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.