Flow Security Incident Review: Type Confusion Vulnerability in Cadence Identified as Key Factor
BlockBeats News, January 7th, Folw released an attack event retrospective report, stating that the attacker exploited a Flow Network vulnerability to mint fake tokens, stealing approximately $3.9 million through a bridging attack. This attack did not access or leak any existing user balances. The attack duplicated assets but did not touch legitimately held assets, with the majority of the fake assets either stored on-chain before liquidation or frozen by exchange partners. Network validators have approved a decentralized governance action authorizing the permanent destruction of all fake assets. The network resumed operation on December 29th, is currently running smoothly, and all transaction history has been preserved.
The attacker sequentially deployed over 40 malicious smart contracts, leveraging a three-stage attack chain: 1) bypassing attachment import verification; 2) circumventing defense checks of built-in types; 3) exploiting a contract initializer semantic vulnerability. The root cause was a type confusion vulnerability in the Cadence runtime (v1.8.8), which has now been patched (v1.8.9 and higher versions). This vulnerability allowed the attacker to disguise protected assets (which should not be duplicable) as standard data structures (which are duplicable), bypassing runtime security checks and enabling token minting.
In addition to moving assets out of Flow, the attacker also attempted to deposit fake FLOW on several centralized exchanges, but due to the abnormal transaction volume and internal anti-money laundering protocols, multiple exchanges froze the deposit upon receipt. Approximately 50% of the fake FLOW deposits have been returned and destroyed by cooperating exchanges (such as OKX, Gate, MEXC), while the foundation continues to actively coordinate with other exchange platforms.
You may also like

Aave Founder: What Is the Secret of the DeFi Lending Market?
The Trader's Playbook: 7 Market Cycle Lessons From LALIGA’s 90 Minutes
What do LALIGA matches teach about crypto markets? Learn how consolidation, breakouts, and late-cycle volatility shape disciplined trading decisions.
How Smart Money Tracker Survived Live AI Trading at WEEX AI Hackathon
Discover how WEEX AI Trading Hackathon tested strategies with real capital—no simulations. See how Smart Money Tracker survived flash crashes and leveraged 18x in live markets.
80% Win Rate to 40% Drawdown: An AI Trader's Brutal Recalibration at WEEX AI Wars
Dive into the technical blueprint of an AI trading system built on LLaMA reasoning and multi-agent execution. See how Quantum Quaser uses confidence thresholds & volatility filters at WEEX AI Wars, and learn the key to unlocking 95% win rate trades.
AI Trading Strategy Explained: How a Beginner Tiana Reached the WEEX AI Trading Hackathon Finals
Can AI trading really outperform human emotion? In this exclusive WEEX Hackathon finalist interview, discover how behavioral signal strategies, SOL trend setups, and disciplined AI execution secured a spot in the finals.

When AI Takes Over the 'Shopping Journey,' How Much Time Does PayPal Have Left?

Bloomberg: Aid Turkey Freeze $1 Billion Assets, Tether Remakes Compliance Boundary

Polymarket vs. Kalshi: The Full Meme War Timeline

Consensus Check: What Consensus Was Born at the 2026 First Conference?

Resigned in Less Than a Year of Taking Office, Why Did Yet Another Key Figure at the Ethereum Foundation Depart?

Russian-Ukrainian War Prediction Market Analysis Report

Ethereum Foundation Executive Director Resigns, Coinbase Rating Downgrade: What's the Overseas Crypto Community Talking About Today?

Who's at the CFTC Table? A Rebalancing of American Fintech Discourse
AI Trading vs Human Crypto Traders: $10,000 Live Trading Battle Results in Munich, Germany (WEEX Hackathon 2026)
Discover how AI trading outperformed human traders in WEEX's live Munich showdown. Learn 3 key strategies from the battle and why AI is changing crypto trading.
Elon Musk's X Money vs. Crypto's Synthetic Dollars: Who Wins the Future of Money?
How do Synthetic Dollars work? This guide explains their strategies, benefits over traditional stablecoins like USDT, and risks every crypto trader must know.

The Israeli military is hunting a mole on Polymarket

Q4 $667M Net Loss: Coinbase Earnings Report Foreshadows Challenging 2026 for Crypto Industry?

BlackRock Buying UNI, What's the Catch?
Aave Founder: What Is the Secret of the DeFi Lending Market?
The Trader's Playbook: 7 Market Cycle Lessons From LALIGA’s 90 Minutes
What do LALIGA matches teach about crypto markets? Learn how consolidation, breakouts, and late-cycle volatility shape disciplined trading decisions.
How Smart Money Tracker Survived Live AI Trading at WEEX AI Hackathon
Discover how WEEX AI Trading Hackathon tested strategies with real capital—no simulations. See how Smart Money Tracker survived flash crashes and leveraged 18x in live markets.
80% Win Rate to 40% Drawdown: An AI Trader's Brutal Recalibration at WEEX AI Wars
Dive into the technical blueprint of an AI trading system built on LLaMA reasoning and multi-agent execution. See how Quantum Quaser uses confidence thresholds & volatility filters at WEEX AI Wars, and learn the key to unlocking 95% win rate trades.
AI Trading Strategy Explained: How a Beginner Tiana Reached the WEEX AI Trading Hackathon Finals
Can AI trading really outperform human emotion? In this exclusive WEEX Hackathon finalist interview, discover how behavioral signal strategies, SOL trend setups, and disciplined AI execution secured a spot in the finals.