Flow Foundation Confirms $3.9 Million Exploit Due to Execution Layer Flaw

Flow Foundation Confirms $3.9 Million Exploit Due to Execution Layer Flaw

Flow's January 7 update confirms attackers exploited a Cadence runtime bug to forge and bridge tokens off-chain, with no user balances compromised and most assets neutralized.

FLOW

Fact Check
The statement is assessed as "likely_true" with high confidence based on consistent and mutually reinforcing evidence from multiple credible sources. All three key components of the statement are well-supported:1. **Confirmation by Flow Foundation:** Several high-authority sources directly attribute the confirmation to the Flow Foundation. The official status update from Kraken, a major exchange partner, explicitly states that "the Flow Foundation has confirmed a security exploit." Similarly, reputable news outlets like The Block and Incrypted report that the Flow Foundation confirmed the exploit and the associated losses. LiveBitcoinNews also directly states, "According to Flow Foundation, the exploit was on the execution layer."2. **Exploit Amount (~$3.9 Million):** The figure of approximately $3.9 million is consistently cited across a majority of the sources, including The Block, ForkLog, Incrypted, and LiveBitcoinNews.3. **Cause (Flaw in Execution Layer):** The technical cause is also widely corroborated. Kraken's status update is a key piece of evidence, specifying the exploit affected "Flow's execution layer." This detail is independently reported by news outlets ForkLog, Incrypted, AInvest, and others.There are no contradictions in the provided evidence. While the most authoritative source—the Flow Blockchain's own X account—does not list all the specific details, the consistent reporting from a major partner (Kraken) and multiple reputable news agencies that directly attribute these details to the Flow Foundation provides a very strong basis for the statement's truthfulness.
Summary

On January 7, Flow disclosed that a $3.9 million exploit was carried out by attackers leveraging a Cadence runtime vulnerability to forge tokens and bridge them off-chain. No user balances were accessed or leaked, and recovery efforts froze or destroyed most forged assets. The network bug was patched in version 1.8.9, eliminating the vulnerability. This updated report refines earlier accounts of the December 27, 2025 incident, highlighting that while the attack involved large-scale token creation, effective containment prevented further user impact.

Terms & Concepts
  • Execution layer flaw: A vulnerability in the blockchain’s transaction and smart contract execution component that can enable unauthorized token actions.
  • Cadence VM: Flow’s virtual machine that executes Cadence smart contracts and processes transaction logic.