Flow Security Incident Review: Type Confusion Vulnerability in Cadence Identified as Key Factor

By: theblockbeats.news|2026/03/30 03:22:41
0
Share
copy

BlockBeats News, January 7th, Folw released an attack event retrospective report, stating that the attacker exploited a Flow Network vulnerability to mint fake tokens, stealing approximately $3.9 million through a bridging attack. This attack did not access or leak any existing user balances. The attack duplicated assets but did not touch legitimately held assets, with the majority of the fake assets either stored on-chain before liquidation or frozen by exchange partners. Network validators have approved a decentralized governance action authorizing the permanent destruction of all fake assets. The network resumed operation on December 29th, is currently running smoothly, and all transaction history has been preserved.

The attacker sequentially deployed over 40 malicious smart contracts, leveraging a three-stage attack chain: 1) bypassing attachment import verification; 2) circumventing defense checks of built-in types; 3) exploiting a contract initializer semantic vulnerability. The root cause was a type confusion vulnerability in the Cadence runtime (v1.8.8), which has now been patched (v1.8.9 and higher versions). This vulnerability allowed the attacker to disguise protected assets (which should not be duplicable) as standard data structures (which are duplicable), bypassing runtime security checks and enabling token minting.

In addition to moving assets out of Flow, the attacker also attempted to deposit fake FLOW on several centralized exchanges, but due to the abnormal transaction volume and internal anti-money laundering protocols, multiple exchanges froze the deposit upon receipt. Approximately 50% of the fake FLOW deposits have been returned and destroyed by cooperating exchanges (such as OKX, Gate, MEXC), while the foundation continues to actively coordinate with other exchange platforms.

-- Price

--

You may also like

Champion's Final Bow: FC Barcelona vs Real Betis – Celebrate the Title with a Home Finale

FC Barcelona are champions! After beating Real Madrid to clinch the 2025-26 LALIGA title, Barça return home to face Real Betis on May 17. A victory party at Spotify Camp Nou awaits. Full preview inside.

Best Oil Trading Platform for Crypto Users in 2026

Looking for the best oil trading platform for crypto users? Trade crude oil, gold, forex, and US stock futures directly with USDT on WEEX TradFi with 0% trading fees and no broker account required.

5 Futures Trading Strategies Smart Traders Use to Cut Crypto Fees and Boost Futures Returns

Most futures traders focus on entries and exits but ignore the fees quietly killing profits. Learn 5 futures trading strategies to cut costs and improve returns in 2026.

What Is TradFi? How Crypto Traders Can Now Access Crude Oil, Gold, and Global Markets

What is TradFi in crypto? Learn how crypto traders can now trade crude oil, gold, stocks, and global markets directly with USDT on WEEX TradFi with 0 fee trading and a $150,000 bonus pool.

How WEEX Bridges Crypto and Football: A Deep Look at the LALIGA Partnership Inside the WEEX App

WEEX is not just a LALIGA sponsor. It’s a true partner. From iPhone Dynamic Island to LALIGA-themed app icons and smart posters, see how WEEX brings football passion into every trade — and builds a real bridge between crypto and sports.

FC Barcelona vs Real Madrid Preview: El Clásico – Can Barça Clinch the Title at Spotify Camp Nou?

FC Barcelona vs Real Madrid El Clásico match preview for May 11, 2026. Barça need just 1 point to win LALIGA. Can Madrid delay the trophy? Full preview inside.

Contents

Popular coins

Latest Crypto News

Read more
iconiconiconiconiconiconicon
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:bd@weex.com
VIP Program:support@weex.com