Flow Security Incident Review: Type Confusion Vulnerability in Cadence Identified as Key Factor
BlockBeats News, January 7th, Folw released an attack event retrospective report, stating that the attacker exploited a Flow Network vulnerability to mint fake tokens, stealing approximately $3.9 million through a bridging attack. This attack did not access or leak any existing user balances. The attack duplicated assets but did not touch legitimately held assets, with the majority of the fake assets either stored on-chain before liquidation or frozen by exchange partners. Network validators have approved a decentralized governance action authorizing the permanent destruction of all fake assets. The network resumed operation on December 29th, is currently running smoothly, and all transaction history has been preserved.
The attacker sequentially deployed over 40 malicious smart contracts, leveraging a three-stage attack chain: 1) bypassing attachment import verification; 2) circumventing defense checks of built-in types; 3) exploiting a contract initializer semantic vulnerability. The root cause was a type confusion vulnerability in the Cadence runtime (v1.8.8), which has now been patched (v1.8.9 and higher versions). This vulnerability allowed the attacker to disguise protected assets (which should not be duplicable) as standard data structures (which are duplicable), bypassing runtime security checks and enabling token minting.
In addition to moving assets out of Flow, the attacker also attempted to deposit fake FLOW on several centralized exchanges, but due to the abnormal transaction volume and internal anti-money laundering protocols, multiple exchanges froze the deposit upon receipt. Approximately 50% of the fake FLOW deposits have been returned and destroyed by cooperating exchanges (such as OKX, Gate, MEXC), while the foundation continues to actively coordinate with other exchange platforms.
You may also like

Champion's Final Bow: FC Barcelona vs Real Betis – Celebrate the Title with a Home Finale

Best Oil Trading Platform for Crypto Users in 2026
5 Futures Trading Strategies Smart Traders Use to Cut Crypto Fees and Boost Futures Returns

What Is TradFi? How Crypto Traders Can Now Access Crude Oil, Gold, and Global Markets

How WEEX Bridges Crypto and Football: A Deep Look at the LALIGA Partnership Inside the WEEX App
WEEX is not just a LALIGA sponsor. It’s a true partner. From iPhone Dynamic Island to LALIGA-themed app icons and smart posters, see how WEEX brings football passion into every trade — and builds a real bridge between crypto and sports.

FC Barcelona vs Real Madrid Preview: El Clásico – Can Barça Clinch the Title at Spotify Camp Nou?
FC Barcelona vs Real Madrid El Clásico match preview for May 11, 2026. Barça need just 1 point to win LALIGA. Can Madrid delay the trophy? Full preview inside.

At the Stripe conference, I saw the future of the AI economy

Miners welcome a new life

Seven Important Judgments by Claude Code's Founder at the Sequoia Conference

The payment moment of AI agents: Who will become the Stripe of the machine economy?

Morning Report | MoonPay acquires Solana's execution layer DFlow; Strategy releases Q1 financial report; Manta Network announces the termination of Manta staking program

Rented Tracks: What is this wave of stablecoin FX hot money really paying for?

Dialogue Velocity Eric: What is the stablecoin track that the CFO really wants?

Strategy should have said that selling coins is not ruled out

How MegaETH Achieved a TVL of 700m Within a Week of TGE? Analyzing the Packaging Strategy

Futures Trading Hours: Trade Cryptocurrency 24/7 and Earn Back Up to 45% in Trading Fees
Learn futures trading hours and the best time to trade crypto futures. Discover 24/7 market insights, peak trading sessions, and how to earn back up to 45% in fees.

Why is a16z Crypto raising another $2.2 billion to heavily invest in Web3?

Polymarket Underlying Algorithm Explained
Champion's Final Bow: FC Barcelona vs Real Betis – Celebrate the Title with a Home Finale
Best Oil Trading Platform for Crypto Users in 2026
5 Futures Trading Strategies Smart Traders Use to Cut Crypto Fees and Boost Futures Returns
What Is TradFi? How Crypto Traders Can Now Access Crude Oil, Gold, and Global Markets
How WEEX Bridges Crypto and Football: A Deep Look at the LALIGA Partnership Inside the WEEX App
WEEX is not just a LALIGA sponsor. It’s a true partner. From iPhone Dynamic Island to LALIGA-themed app icons and smart posters, see how WEEX brings football passion into every trade — and builds a real bridge between crypto and sports.
FC Barcelona vs Real Madrid Preview: El Clásico – Can Barça Clinch the Title at Spotify Camp Nou?
FC Barcelona vs Real Madrid El Clásico match preview for May 11, 2026. Barça need just 1 point to win LALIGA. Can Madrid delay the trophy? Full preview inside.
